Trojan problems

Discussion in 'Malware Help (A Specialist Will Reply)' started by jsortore, Sep 17, 2008.

  1. jsortore

    jsortore Private E-2

    Not sure how long this has been a problem, as I'm mostly unaffected. I noticed last week that all of my email to a certain domain was being bounced back to me, and after consulting with my provider, was directed to the CBL, which tells me that I am infected with a trojan. (Possibly multiple trojans?) The first message called it a Srizbi Bot, it was something else last night, and just now it is listed as Storm Bot. I ran the "Run me first" procedures two days ago and my logs are attached. I'm not much of a tech wiz myself, so thank you so much for any help you can offer!
     

    Attached Files:

  2. jsortore

    jsortore Private E-2

    Re: Trojan problems (logs continued)

    Here's the fourth log.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan problems (logs continued)

    Welcome to Major Geeks!

    Your logs do not show any malware problems. I do observe that your AVG7.5 antivirus program is not running properly. No processes for it appear to be running. I suggest that you uninstall it and then reboot. After reboot, you should reinstall version 8 from AVG AntiVirus Free Edition ( if you wish to keep AVG ) because support for AVG7 will soon be discontinued. Then after reinstalling the antivirus program, get any updates for it and then run a full system scan. Let me know if anything is found.

    Then run this Running GMER to detect rootkits and attach the requested log.

    Srizbi Bot and Stormbot are things that cause lots of outgoing spam. Has your ISP shutdown your ability to send email because they say you are spamming?
     
    Last edited: Sep 18, 2008
  4. jsortore

    jsortore Private E-2

    Thank you for your reply.
    I uninstalled AVG 7.5, rebooted, and installed AVG 8. After updating, I ran a scan and it didn't find anything.
    I've attached the log from GMER.
    Today when I checked, CBL listed the problem as the Not-yet-named (we call Gheg) bot.
    After I followed the "Read first" procedure, I unlisted my IP from CBL, but the listing came back right away.
    My email is working fine except for the messages bounced back from domains that check CBL. I've had no communications from my ISP.
    Thanks again!
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your GMER log is also clean. I suspect that somehow your IP address has gotten blacklisted and you will need to figure out how to correct this. Perhaps your ISP can help you with this.

    We could run additional scans if you want to check further but I tend to doubt we will find any problem. If your PC was spamming, your ISP would have notified you or shut you down already.
     
    Last edited: Sep 21, 2008
  6. jsortore

    jsortore Private E-2

    I'll check with my ISP. Thank you again for your help.
     
  7. jsortore

    jsortore Private E-2

    Just a follow-up to let you know that I'm closer to discovering a fix. The problem is apparently my wireless ISP, which uses dynamic IP addresses. (Which seems to explain why the CBL listed a different bot each time I checked.) I'm currently checking with my web hosting/email tech support to see if there's a way to configure my outgoing mail through Outlook to circumvent this problem.
    Thanks and best regards,
    --Jeremy
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Let us know what you finally figure out. It could prove useful to others in the future. ;)
     
  9. jsortore

    jsortore Private E-2

    Unfortunately, my email support people do not have a solution for the problem of blacklisted IP addresses due to my ISP using dynamic IPs. I will have to use my webmail application instead of Outlook to send email to domains that check the CBL. But at least I know it's not my computer that's infected. Thank you!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds