Trojan Horse and Downloader Virus Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Ophie, Nov 15, 2006.

  1. Ophie

    Ophie Private E-2

    Hi there,

    I have done all of the READ AND RUN ME FIRST and am attaching all of the log files.

    Basically, I have virus and a Trojan Horse that will not be removed, I have tried everything.

    They also keep disabling my Windows auto-updater and my Norton Internet Security. The services that get shut down with every boot are Symantec LL Core and Windows Automatic Updater.

    Several of the virus scans have said that they've deleted both Downloader and the Trojan but when I reboot into normal mode they're back again.

    Any help would be much appreciated, I've been at this for three days and am at my wit's end.

    Thanks,

    Ophie
     

    Attached Files:

  2. Ophie

    Ophie Private E-2

    The rest of the attachments...

    Here are the last two scanner logs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: The rest of the attachments...

    Welcome to Majorgeeks!

    You did not follow all of the directions in step 2 of the READ ME. You did not enable viewing extensions for know file types. Because of this (since you could not see the extension), you renamed hijackthis.exe to analyse.exe.exe instead of analyse.exe
    This is not a big deal but you need to correct this.

    Uninstall the below software which should have been uninstalled in step 0 of the READ ME!
    Need2Find Bar
    Viewpoint Manager (Remove Only)


    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: (no name) - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)
    O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - (no file)
    O4 - HKLM\..\Run: [.nvsvc] C:\WINDOWS\system\smss.exe /w
    O8 - Extra context menu item: &Search - http://kb.bar.need2find.com/KB/menusearch.html?p=KB
    O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} (Sinstaller Class) - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system\smss.exe
    c:\windows\browserxtras\pn\remove.exe
    c:\windows\ss3unstl.exe
    C:\WINDOWS\system32\spool\drivers\setup.exe
    c:\windows\browserxtras <--- the whole folder
    c:\program files\Need2Find <--- the whole folder
    c:\program files\RXToolBar <--- the whole folder
    c:\windows\cdmxtras <--- the whole folder

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Tanya\Local Settings\Temp

    Now attach the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT

    Make sure you tell me how things are working now!

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
    Last edited: Nov 16, 2006
  4. Ophie

    Ophie Private E-2

    Thank you so much for this. I apologize I must have misunderstood a couple of the steps, I've been at it for 3 days and its all a blur now. I will do these steps as soon as I get home from work. Only one question. Before I found you guys I tried to followed the removal instructions at Symantec (which didn't work) and they had me disable System Restore already. Should I just leave it disabled or should I enable and disable and re-enable?

    Thanks again,

    Ophie
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since it is already disabled, just leave it that way now until we have all malware removed.
     
  6. Ophie

    Ophie Private E-2

    I don't see a "Need2Find" Bar in my Add/Remove Programs. Would it have another name? Or be located somewhere else?

    Thanks.
     
  7. Ophie

    Ophie Private E-2

    OH MY GOD! Everything seems to be running perfectly. My NIS is working, live update and Windows Auto Updater both booted automatically. I don't believe it. THANK YOU SO MUCH CHASLANG. I admit, I had given up hope after the Symantec people couldn't help me. The new files are attached as requested. I'm dumbfounded. Geekagenius!

    Should I turn on System Restore?

    A ZILLION THANKS.

    Ophie
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It shows in the log from ShowNew. Let's use the below to see if we can remove it.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new log from ShowNew.
     
  9. Ophie

    Ophie Private E-2

    Here is the new log. Did that work?
    I can't tell anymore because everything seems to be working great.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! It is still there in your log! Try installing and using the below to uninstall Need2Find Bar

    Your Uninstaller! 2006
     
  11. Ophie

    Ophie Private E-2

    Your Uninstaller did not detect it either.:confused:
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  13. Ophie

    Ophie Private E-2

    Unkeys file attached!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay try this version of registry patch. They did not name the registry key like the application was named.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now attach a new log from ShowNew.
     
  15. Ophie

    Ophie Private E-2

    How bout now?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log is clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    4. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    7. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  17. Ophie

    Ophie Private E-2

    Well that's it, I've done all the steps. The only thing I'm wrestling with is deciding to ditching Norton Internet Security over AVG but mostly because I paid for the thing - even though I recognize its such a hog. Grrrr.

    I can't reiterate enough how much Chaslang and the Geeks rock. I thought I'd never get rid of the problems. Now they're not only gone, but I've learned a TON about how to prevent and handle theses messes in the future. THANKS SO MUCH!

    Ophie
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! All internet security suites are big hogs! But Norton even without the suite is a hog.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds