Trojan Troubles

Discussion in 'Malware Help (A Specialist Will Reply)' started by KyleP, Apr 9, 2009.

  1. KyleP

    KyleP Private E-2

    A few days ago Norton began reporting an intrusion by Hacktool.Rootkit. Norton would then report the problem was resolved however the message would come up every 15 minutes or so. The next morning the computer would not connect to the internet. When I restarted the computer I recieved a blue screen of death for 1/2 second when I logged into Windows and then the computer would restart. Somehow I managed to get it to run again but I don't really know how (I was trying to boot in safe mode and I think I activated system restore but I'm not positive) . Since then Norton has continued to report various problems it has detected and resolved at a rate of about 1 every half an hour, from Hacktool.Rootkit to Trojan.Vundo to "Downloader". Also Firefox would get redirected when I clicked links from google searches.
    I came to your website and followed the steps for removing malware. Since then everything seems to be normal and Norton has stopped reporting problems. I have attached the logs from the programs I ran. Can someone please look at them to see if my system is still infected? After reading about Hacktool.Rootkit it seems to be a serious infection at a deep level and I want to be sure I rooted everything out. Please see my attached logs. Thank you very much for your help so far, the work you all do in this forum is great. :)
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, KyleP


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    *You need run MSconfig and put your PC into normal startup mode as requested in step 1 of the READ & RUN ME.

    I strongly recommend that you clean up your Desktop immediately leaving only links. Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least it can have an effect on your PCs performance.

    * Why didn't you have Malwarebytes fix what it detected?

    Step 1:
    Update the definitions for both SAS & MBAM and run them.. be sure to fix any malware that is found.

    Step 2:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 3:
    Now we need to use ComboFix to remove some malware.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    File::
    c:\windows\Llulexe.dat
    c:\windows\Thizozido.bin
    C:\Documents and Settings\Kyle Poole\oashdihasidhasuidhiasdhiashdiuasdhasd
    C:\edq51gen.exe
    
    Folder::
    c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    C:\Documents and Settings\Kyle Poole\Local Settings\Application Data\{7DA1C34B-EBDC-4829-A99E-37B397136379}
    
    Driver::
    amd64si
    ati64si
    port135sik
    securentm
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 4:
    Run Ccleaner

    Step 5:
    See the below link for running a rootkit scanner and attach its log.
    Using Sophos Anti-Rootkit

    Step 6:
    Go to this link MGTools and download the new version of MGtools....overwrite your previous MGtools.exe file with this one.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next replies - it will require two posts as there is a 4 attachment maximum per reply:
    • C:\MGlogs.zip
    • C:\combofix.txt
    • SASlog.txt
    • MBAMlog.txt
    • sarscan.log

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds