Trojan infecting my system32. PLZ HELP.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lacertosus, Aug 10, 2008.

  1. Lacertosus

    Lacertosus Private E-2

    Hey there. I read some good reviews about this place and was wondering if anyone was able to help me. I recently had a copy of Dragon NaturallySpeaking (voice recognition software) in which required a serial number. Now, since I bought it second hand, I eventually found out the serial number was invalid as it told me so when installing.

    So eventually I went to www.seriall.com to get a fake serial number. I typed in Dragon NaturallySpeaking and clicked the top one. This then lead to a Trojan Horse in the ZIP file that it came with. I soon got rid of that. However, it spread to a Firefox Profile. I simply got rid of that and uninstalled/reinstalled Firefox to get a clean version.

    I turn on my computer today, and there's two more the moment I access back the internet. AVG tells me there's a Trojan Horse in these files:
    fccbYOGW.dll
    geBspMDT.dll

    I deleted the files, and so far nothing is unnatural or abnormal about how my computer works so I'm guessing they're not significant files.

    I reset all my Sygate (firewall) applications to "Ask before allowing access" which should then have all incoming/outgoing applications ask me for permission, allowing me to track down whats relevant and what isnt.

    I used Spybot search and destroy which tracked down 9 problems, they were all dealt with and fixed. I also noticed my Windows Firewall was turned off, so I turned that back on again, which should help a little.

    Is there anything you guys think I should do, or is there anything else that I need to do?

    I am pretty worried.

    Thank you in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes uninstall the software and crack that started the problem before your issues become even worse. Then move on to the below because it sounds like you have or had a Vundo infection.


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.



    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:
    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. Lacertosus

    Lacertosus Private E-2

    I installed Trojan Remover from www.download.com and it killed it.
    AVG couldnt pick up anything, and then after I did three scans with Trojan Remover, that couldnt pick up anything either.

    So, I'm guessing it's all fine?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I cannot answer that without seeing the logs from what I requested.
     
  5. Lacertosus

    Lacertosus Private E-2

    Here's the log for the Trojan Remover.
    I'll do the stages you suggested as well.
     

    Attached Files:

  6. Lacertosus

    Lacertosus Private E-2

    Oh, I also turned on my computer today, and it had spread to my Win333.exe so obviously Trojan Remover didnt work. AVG caught it though.

    (Sorry for double post)
     
  7. Lacertosus

    Lacertosus Private E-2

    I did the procedures you told me too. Here are the logs.

    Edit: For some reason it wont let me upload the third log. I tried in a new post, still didnt work. Should I copy it into a post?
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are four logs. You need to attach the logs from Malwarebytes and from MGtools. Just try again. Watch for non-obvious error messages in the Manage Attachments window.

    Obviously based on your logs from the tools in the READ & RUN ME, Trojan Remover did not remove your malware problems. The Trojan Remover logs are not useful as there is too much junk in there rather than just showing what problems were found and fixed. In fact, I did not notice anything fixed, so as stated, it missed a lot or malware.
     
    Last edited: Aug 14, 2008
  9. Lacertosus

    Lacertosus Private E-2

    It says: mbalog.txt:
    Your file of 268.8 KB bytes exceeds the forum's limit of 250.0 KB for this filetype.

    Do you want me to email it to you?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just put it into a ZIP file and attach it.

    Don't forget the MGlogs.zip file from MGtools.
     
  11. Lacertosus

    Lacertosus Private E-2

    There you go, all of them in one folder.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Most of your problems appear to have been removed now. However you need to uninstall the below as requested in step 1 of the READ & RUN ME. The first three are part of the reason for your Vundo infection and other infections.

    Messenger Plus! 3 & Sponsor
    Messenger Plus! Live & Sponsor (CiD)
    P2P Networking
    Viewpoint Media Player


    Then I suggest that you delete the below files if they still exist:
    C:\Documents and Settings\Elliot\Local Settings\Temp\A24211BA.TMP
    C:\Documents and Settings\Elliot\Local Settings\Temp\AAX16.tmp
    C:\Documents and Settings\Elliot\Local Settings\Temp\AAX30.tmp
    C:\Documents and Settings\Elliot\Local Settings\Temp\AAX31.tmp
    C:\Documents and Settings\Elliot\Local Settings\Temp\AAXC.tmp
    C:\Documents and Settings\Elliot\Local Settings\Temp\AAXF.tmp
    C:\Documents and Settings\Elliot\Local Settings\Temp\kx82F.tmp
    C:\Documents and Settings\Elliot\Local Settings\Temp\zza32.tmp

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds