Trojan Horse - Can't Get Rid of it - Help!

Discussion in 'Malware Help (A Specialist Will Reply)' started by BethieD, Dec 22, 2009.

  1. BethieD

    BethieD Private E-2

    Yesterday I started having problems with my computer. I noticed that my browser was being hijacked whenever I tried to click on results from google. Then it started locking up constantly and I noticed that my online backup wasn't working and hadn't backed up for the past four days. When I ran my AVG Virus scan, it showed that I had a trojan horse called downloader.small.61.

    I've been online and have tried to fix it myself (Adaware, SuperAntiSpyware, RKill, Maleware Bytes, CCleaner, Spybot Search and Destroy, etc.). I received results from one of them (not sure which now) that said I also had a trojan horse called Vundo.

    It seems like they are both gone, but my browser is still being hijacked and it's running really slow. And I still can't run my backup. I downloaded Hijack This and will post it below. I also downloaded Combofix but have not run it for fear of messing something up. I'm no computer expert by any stretch of the word. I have Windows XP and use both firefox and internet explore (I know...)

    If you need any further information, please let me know. Thanks in advance for any help offered!!


    Here is my Hijack Log:
     
    Last edited by a moderator: Dec 23, 2009
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please do this first:

    * Please download TDSSKiller to your Desktop
    * Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    * Click Start > Run and copy/paste the following bold command into Run box and hit Enter.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v

    * Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    * When done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents in your next reply.

    If you are still having issues, then please complete all the instructions here:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. BethieD

    BethieD Private E-2

    Thanks for the help, Tim. My problem is on my work computer, so after the holidays I will do exactly what you said and post my results. Thanks again!!
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I will be here.....sigh. :)
     
  5. BethieD

    BethieD Private E-2

    I ran the TDSSKiller, but it said that it didn't find any threats or infections. And I did the things that were listed in the Read & Run link (which I'd previously done last week). I'm not sure what took care of it, but my computer seems to be back on track. My google results aren't being hijacked anymore and I haven't noticed any kind of lag while working on my pc. So I think i'm good to go. Thanks so much for your help - keep your fingers crossed that this continues!!!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Without seeing any logs, it would be hard for me to make a judgment as to how clean you are. :(
     
  7. BethieD

    BethieD Private E-2

    Here is the log from TDSSKiller. Please let me know if you see anything crazy. My computer seems to be ok, but I'm still having a problem running my online backup and there is a little lag when I'm online. It's weird. Anyway, please let me know if you see anything that looks off. Thanks so much!!

    EDIT: Inline log removed and attached

    Note: Please also attach the other requested logs from running the READ & RUN ME FIRST. Malware Removal Guide.
     

    Attached Files:

    Last edited by a moderator: Dec 31, 2009
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please read this:
    HOW TO: Attach Items To Your Post

    That log was clean. But I still need the other requested logs:
    SAS
    MBAM
    ComboFix
    C:\MGLogs.zip --> from running the C:\MGTools.exe
     
  9. BethieD

    BethieD Private E-2

    Here are the logs. Thanks again for your help!!
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any issues in your logs. The only suggestions I have is that you uninstall ThreatFire ( if you haven't already) as well as Ad-Aware ( as it is useless these days).

    Unless you are still having any malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real-time protection. They are useful as backup scanners.They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore ato create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  11. BethieD

    BethieD Private E-2

    I think I've finally finished everything you suggested. My computer is acting normally again - no signs of any other problems. Thanks so much for all your time and help. I REALLY appreciate it!!!
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds