Trojan infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by barnard83, Dec 29, 2007.

  1. barnard83

    barnard83 Private E-2

    I was given a laptop by my cousin and he seems to have downloaded a trojan infection. The laptop has been going incredibly slowly and although running the programs in your cleaning procedures has helped it still does not seem to be operating normally. There were lots of pop-ups appearing and messages saying that the desktop could not run the script required but these appear to have stopped now. I've attached the files requested except the AVG report as there was not one to save when I went to the 'Reports' screen, despite me following your notes.

    Can you help? Many thanks.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's fix an issue with PC Tools ThreatFire. It is not malware but it is not installed anymore or it is broken.

    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to ThreatFire
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {C89F8841-4856-4EB5-9BDE-99137B16E32B} - C:\WINDOWS\system32\wvwut.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.6.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime.cab
    O20 - Winlogon Notify: fccdawx - fccdawx.dll (file missing)
    O20 - Winlogon Notify: winorl32 - winorl32.dll (file missing)
    O20 - Winlogon Notify: wvwut - C:\WINDOWS\system32\wvwut.dll (file missing)

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. barnard83

    barnard83 Private E-2

    I ran everything you suggested and was successful with everything except the registry key removal, which it said it couldn't find, and had the reports ready.

    However, I've now lost the use of the keyboard and mouse on the infected laptop. A plug-in mouse works but nothing else so I can't log on to this posting and attach the reports. Is this because of anything we did or the trojan and what can I do to correct it? I've tried removing the keyboard driver and reinstalling it as well as searching for a new driver but nothing has worked yet.

    Once this is corrected I can attach the reports but in the meantime the laptop is still working very slowly.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How about an external keyboard?


    The only think I can think of is that it could some how be related to C:\WINDOWS\SYSTEM32\DRIVERS\TfKbMon.sys which was from Threatfire. It is supposedly some kind of keyboard monitor. The strange thing is that your PC did not show that Threatfire was installed. Just the service and that file were in your log. Did you or anyone else install this program? Did some one uninstall it? It is supposed to cleanup after itself. See this link:

    http://www.pctools.com/forum/showthread.php?t=49750

    Looks like someone else notice issues with a keyboard while trying to get Threatfire removed and it apparently Threatfire has uninstall issues.

    If the external keyboard works, we may be able to restore this file from the Avenger backup ZIP file as long as Avenger ran properly.

    Also note, I have read of several cases where Threatfire has cause significant slow downs on a PCs. Perhaps you are still somehow being impacted by once having it installed.
     
  5. barnard83

    barnard83 Private E-2

    Unfortunately I don't have an external keyboard so we can't go down that route.

    I installed Threatfire when I was first trying to tackle this problem and then I uninstalled before I ran all your processes as it said not to have more than one anti-virus etc in use.

    I looked in the Avenger file and there is an icon with TfkbMon.sys in there but I'm not sure how to go about restoring it, if indeed I can and should, or if that is possible without the use of a keyboard.

    Any advice would be much appreciated as this is beyond me! Many thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you can boot your PC to do some of the things you are have been saying then perhaps you can navigate to your C:\Windows\system32 folder. In this folder you will see a file named OSK.EXE double click it to run it. This is an on screen keyboard. You can use your mouse to select keys like you were typing on a keyboard. It will enter anything you click on (using your mouse) into the active window. Try using this to copy the C:\WINDOWS\SYSTEM32\DRIVERS\TfKbMon.sys file back from the Avenger backup.


    I'm still not sure if this is the problem or not but it is the only possible reason I can see that may be related.
     
  7. barnard83

    barnard83 Private E-2

    That's done the trick! The keyboard and mouse are both operating normally.

    Here are the MGlog and Avenger reports I produced before.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's great but I strongly recommend you contact PC Tools to determine why ThreatFire does not uninstall properly. You need to get that keyboard hook removed properly. Sooner or later something is going to detect it as a possibly keylogger or similar and delete it. And then you will be in trouble especially if no backup is made to restore from.

    You're logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  9. barnard83

    barnard83 Private E-2

    Thanks for all your help. I shall follow the instructions and set up a few rules for my cousin so he doesn't get anything again! I'll also follow some of your other advice to try and speed the laptop back up to normal again. At least I know it's ok to use now. Happy 2008!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds