Trojan remains after 3 formats?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Phydron, Oct 3, 2012.

  1. Phydron

    Phydron Private E-2

    I have a desk top Gigabyte DQ6, core 2 Duo, 3.6GHz, 4GB, that has a major
    trojan problem. This bug was originally identified as HEUR.BackDoor.Win64.
    Generic, then TDSSKiller said it wasTROJ_SPNR.OBD112. I have reformatted
    twice on another computer, using /u suffix, removed the BIOS battery, tried
    a new HDD and I can't understand how this thing can survive all that.
    When I first get the OS installed, it begins to screw up, it reboots half way through installing any other software, flashes 'Windows Installer' on the
    screen at random times, takes 45 sec. to two minutes for each keystroke
    or mouse click, in the processes box it creates two of each program.
    All this is before connecting to the net, then it really screws up, including
    redirecting explorer to a Facebook address.

    Here are the logs that were requested, it won't let me copy the MG logs.

    Thanks for any help you can give.
     
  2. Phydron

    Phydron Private E-2

    I guess the files didn't make it. I'll try again, sorry.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. Please attach the log from running MGTools.exe --- C:\MGLogs.zip
     
  4. Phydron

    Phydron Private E-2

    I'll try again, this bug stopped me from saving MGToools yesterday.
     
  5. Phydron

    Phydron Private E-2

    Thanks for the quick reply.
    I finally wrestled the MGTools log out of this thing.
    It's just as bad as ever and when the internet connects, it really gets bad.

    Thanks again, Norm
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I do not find any malware in any of your logs. I suggest that you post in the software forum for additional assistance. Your logs are clean.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware. You can uninstall RogueKiller and HitManPro.
    2. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0
     
  7. Phydron

    Phydron Private E-2

    Thanks anyway, I guarantee there is still malware of some type on this machine.
    I'll keep working on it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    When you do a format, are you creating new partitions as well?
     
  9. Phydron

    Phydron Private E-2

    I formatted in control panel using the /u suffix, removed the BIOS battery and installed a
    fresh copy of Vista from a legal disk. One time, I used a disk that had never been on this
    PC. It begins screwing up as soon as I start adding other programs, then when it connects
    to the internet it really gets bad. I have a whole litany of problems it causes if you need
    them.

    Thanks again for your time and efforts.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since I couldn't find any evidence of malware in your logs, you should probably post in the software forum for additional assistance.

    We can do one other thing:

    Please download ComboFix to your desktop. Turn off any AV software you have before you run it. Attach the log when finished. Do not do anything while it is running or it may stall the program.
     
  11. Phydron

    Phydron Private E-2

    On my last format I used a new HDD that had never been on this computer.
    I removed the BIOS battery for 5 mins., replaced the video card on the off
    chance that this bug was hiding there. It was suggested that my modem might
    be at fault so I replaced that, although no other computers on the modem
    have problems. I reinstalled Vista from a retail disk and have a full page of
    problems it still has.

    I wonder if it's possible for this virus to have taken up residence in the chip
    set or CPU or other flash memory. I haven't used SD cards or any other
    I/O device that could have transferred it. I think I've proven it's not on
    the HDD. Is it possibe that it could still be in the BIOS. Obviously I'm
    stumped.

    Thanks again,

    Norm
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't run Combo from your desktop as instructed.
     
  13. Phydron

    Phydron Private E-2

    I'll have to reformat to be able to load it.
     
  14. Phydron

    Phydron Private E-2

    I managed to save the file before it was deleted.
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That didn't find anything. I can only suggest that you post in the software forum for additional assistance. This does not appear to be a malware issue.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds