Trojan Virus on Computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by bjparrish04, Feb 4, 2012.

  1. bjparrish04

    bjparrish04 Private E-2

    Good morning,

    I am new to this site and am having a few issues with a trojan virus on my Wife's computer. I know my way around a computer a little bit and have followed the tutorial to complete the steps necessary for someone to help me. Attached are the logs as requested. I appreciate any and all help that you can give me. Please let me know if I can do anything else to help you, help me.

    Thank you in advance!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You skipped Malwarebytes that was requested in the READ & RUN ME. Please run it now and fix what it finds. Then reboot immediately. After reboot, attach the log from Malwarebytes.
     
  3. bjparrish04

    bjparrish04 Private E-2

    Sorry about that.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log shows you took no action! Is this correct or did you just forget to fix before you saved the log?

    Continue with the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=ZUGO&form=ZGAPHP
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

    After clicking Fix, exit HJT.


    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).



    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Feb 4, 2012
  5. bjparrish04

    bjparrish04 Private E-2

    Thank you for all of your help so far.

    What I didn't do last time was save the log after I fixed the errors. I saved the log and then fixed them. Sorry about that it's been a long day.

    I have attached the requested log files, one issue that did result was immediately after completing the MGtools, a popup window showed up with the intent of malicious malware was detected named C:\WINDOWSNIRCMD.EXE. I am currently running my AVG to see if there is anything amiss and if there is still anything lingering around in the system.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not malware. It is very well known valid tool and it is used by ComboFix. Per our instructions, you should have uninstalled AVG before running ComboFix the very first time. AVG gets in the way of proper removal of malware. And in addition even if you had not uninstalled AVG, my last instructions stated to disable your AV before running ComboFix you may not have done this based on the log from ComboFix. The fix did not work properly either based on your logs and this may be the result of still having AVG installed. I still see the files we were trying to remove including C:\Windows\svchost.exe. You need to uninstall AVG and run the fix again.

    Now all the above being said, you did not tell me how things are working now.
     
    Last edited: Feb 4, 2012
  7. bjparrish04

    bjparrish04 Private E-2

    Good afternoon,

    The computer speed improved a bit last night after some of the malware was removed. But Malware still found the 2 trojans and I now was getting redirected when I would search with Google. When I first started, I thought.I had disabled AVG, according to the logs, that was not the case. I completely uninstalled AVG from this point and tried to continue. I then went back when I received your message to look for anything with avg, since I kept receiving an error that two sets of avg security was still being found by combo fix. I ran another log as instructed to pull into combofix and the computer crashed and is unable to restore in any manner that I try. Even a system restore to 16 January is not working. The.module says it encountered an error and cannot finish. What did I do wrong now?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure.


    What does this mean? Does this mean you just ran ComboFix or did you try running the fix exactly as instructed with the CFScript.txt file? Did you run ComboFix more than once? None of the information in the fix would cause your computer not to boot. If however your computer crashed or you shut it down while the fix was running, this could cause problems with your registry or file system.

    What exactly happens when you boot up your computer?

    Does it boot in safe mode if normal mode does not work?

    So you are saying that you tried to perform a System Restore but it fails to complete properly?
     
  9. bjparrish04

    bjparrish04 Private E-2

    Sorry it has been a couple days, I have been away with work and the computer was not with me.

    I ran Combofix with cfscript.txt after I completed the other steps to get to that point. I did not shut the computer down while the script was running. It shut down in the middle of the script being run on Combofix.

    I am not given an option to boot in safe mode.

    The computer now will not boot Windows, it says there is an error starting Windows and asks if I want to do 2 separate options
    1. Launch Startup repair (Recommended)
    2. Start Windows normally

    When I try to start normally, it starts to load Windows, and with the blink of a blue screen, immediately reverts back to the Windows failed to load screen

    When I choose Launch startup repair, is says that Windows is loading files, and the startup repair screen starts. Within 3 minutes Startup.Repair says that it cannot repair this computer automatically and prompts me to complete 1 of 2 more actions.
    1. Send information about this problem (recommended)
    2. Don't send
    Upon choosing either action, it states that Windows cannot be repaired and click finish to shut down the computer.

    When I view the diagnostic and repair details, all sections are marked as completed successfully, but the areas that are marked as a "root cause found"
    1. Internal State Check-Startup repair has tried several times but still cannot determine the cause of the problem.
    2. Bug checkanalysis-Unknown bugcheck:bugcheck 109, and then it lists the parameters.

    However, it also gives me the choice to View Advanced system repair options. The options are as follows:
    Startup repair-I already know this function is not working
    System Restore-I've tried restoring to 3 different time periods and none will complete the process before sayingthat it cannot be restored to an earlier point in time
    System Image recovery- I have not created a system Image recovery disk
    Windows Memory Diagnostic-I won't lie, I don't know what I am doing with this
    Command prompt-Same as above, not educated enough to begin this process
    Recovery management- I would like to exhaust all other options before resorting to this.

    I hope I have answered all of your questions efficiently, please let me know what other info you need.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can boot your PC into the System Recovery Environment ( how to do this is explained down below. We will also need a flash drive with another tool loaded on it which we will use while in the System Recovery Environment.

    Please download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Now plug the flashdrive into the infected PC.

    Use one of the two options below to boot into the System Recovery Environment.


    Option 1: Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
    Option 2: Enter System Recovery Options by using Windows installation disc:
    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    After getting into the System Recovery Options menu you will see the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • Windows notepad should open
      • Under File menu select Open.
      • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type type e:\frst64 and press Enter
      • Note: Replace letter e with the drive letter of your flash drive.
    • The FSRT will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply
     
  11. bjparrish04

    bjparrish04 Private E-2

    Good Evening, attached is the requested log from the instructions that you gave me. Please let me know what you think.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system



    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    Now attempt to boot normally. Let me know what happens.
     

    Attached Files:

  13. bjparrish04

    bjparrish04 Private E-2

    Phew, Well Thank you.

    The computer booted successfully after running fixlist. Just to be sure there weren't errors elsewhere, I tried to open a couple of programs. They all opened correctly except for Firefox. Firefox states that it has crashed and needs to be restarted. Upon trying to do so, it gives me the same error message that it has crashed. I then tried to use IE to gain access to the internet and when the browser opens it tells me that that IE cannot display the webpage. No big deal here, if I have to reload them, I have to reload them. I just wanted you to know these were the only areas that I was experiencing issues when I rebooted. I would try to restart but I would rather wait for further instruction.

    I have attached fixlog as well as the message that I received when Windows finally booted successfully after running the fixlist.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Also tell me how the PC is running. Any malware problems?
     
  15. bjparrish04

    bjparrish04 Private E-2

    Attached is the newest MGTools log file.

    I had to re-download MG Tools, i had data logs from previously on my C:/ drive but not the executable program.

    The computer seems to be running a bit quicker, but i didn't notice the speed was really being slowed or becoming such a huge issue before, obviously there was an underlying problem. The main problem was AVG kept populating errors and finding a virus. Should I go back and clean out the caches again?
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then if you are not having any current malware problems, before you run any additional scans with AVG, complete the below final instructions to remove artifacts from the cleaning procedure.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  17. bjparrish04

    bjparrish04 Private E-2

    So I am apparently a liar.

    I am still having the same issues as before. There is still a virus lurking around in the system. I think I am going to have to go back and start from the very beginning. I have attached the most recent log from MalwareBytes. I'm not sure if this will help or not, If I have to start over from the read and run me, I will.
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay please download the current version of MGtools and attach a new log so we can get started again. I see the C:\Windows\svchost.exe problem has returned.
     
  19. bjparrish04

    bjparrish04 Private E-2

    Yes, it is. Attached is the MGlog. Please let me know if you want me to add anything else.
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay download and save the current version of combofix.exeto your Desktop. Overwrite any old version. DO NOT run it yet. Just save it.



    Now we need to use ComboFix to remove a bunch of malware files.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.


    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • the TDSSkiller log
    • the MBRcheck log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  21. bjparrish04

    bjparrish04 Private E-2

    Attached are the requested logs. But you will see an issue with AVG in the txt file.

    When Combofix begins to run, it states that there are AVG scanners still in operation. I have uninstalled AVG via the uninstall programs module within the PC as well as trying to use a third party client. I have rebooted after each of these methods. I have also searched for ANYTHING with the keyword of AVG. I don't know how there are still active scanners for AVG. I have searched for other methods online, but to no avail have been successful with finding another procedure to ensure the deleting everything involved I guess....

    Is there something underlying that contains AVG data that is causing this error?

    The PC is running as normal, no speed issues, and the only time a Virus is detected is through an Antivirus program. So I can't detect any other issues other than the txt documents that state there is actually there.
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    AVG still shows as running because it does not properly uninstall everything it puts on your PC. There are entries in the registry in security center that ComboFix is seeing.

    Some of the items we had ComboFix remove were removed, but many were not. Let's try another tool and see if we can get all of these removed.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    See the download links under this icon http://www.majorgeeks.com/images/dll.gif
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot look for all of the above files we had Avenger attempt to delete. If you still see them, delete them yourself. Make sure that you only delete the exact file names being listed. Do not delete anything else. If unsure, then leave it alone.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  23. bjparrish04

    bjparrish04 Private E-2

    I ran the avenger as instructed, but still do not see the log file, nor did a popup come on the screen upon reboot. I have gone through every file and deleted them accordingly.

    After I emptied the Recycle bin, I attempted to run Avenger again and still the same issue, no log file at C:\avenger.txt. After searching for it, nothing. the only avenger that is found is the zip file and .exe. I ran the MGlog.bat file and it is attached.

    Am I doing something incorrectly or not giving it enough time to configure the data for the log file for avenger?

    By the way, the computer is blazing fast again, seems like I am getting somewhere at least. Funny how you can get accustomed to a lag in timing and then realize normalcy when it returns.
     

    Attached Files:

  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Probably not. There may just be something about your computer that causes an incompatibility with Avenger. It happens! Sometimes we see the same with ComboFix. There are cases were malware is the cause, but I don't think that is why here.

    There are two files you still need to delete. Delete the below and then empty the Recycle Bin
    C:\Windows\SysWow64\16526s596d9z.dll
    C:\Windows\SysWow64\97e3vir3558z.exe

    Then REBOOT immediately. After reboot, we need to make sure that nothing returns. Thus, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
     
  25. bjparrish04

    bjparrish04 Private E-2

    Ok, here is the most recent copy of MGlogs.zip.

    Question; When you asked me to search for that entire list of files, what is an easier way to search for all of them involved at the same time? I went line by line in the search bar. Surely you didn't do the same thing? Did you?
     

    Attached Files:

    Last edited: Feb 17, 2012
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Notice that my request did not use the word "search". ;) I said look. I would open up Windows Explorer and simply navigate to the C:\Windows\SysWOW64 folder and then scroll thru the file list in alpha order to LOOK for the files in the list. Much much faster and easier than using any form of search especially Windows Search. ;)

    It looks like they are all gone now. So let's move on to final instructions again if all is good.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  27. bjparrish04

    bjparrish04 Private E-2

    Ahhhh, I See.

    Well played Sir, Well played. I guess I didn't notice they were in chronological order.

    I finished the cleaning procedures, Everything seems in great order. PC is Fast, responsive and free and clear of Malware and underlying Viruses. I will let it run its course for a couple days and report back.

    Thank you for all of your patience, hard work and dedication to resolving all my issues and then some. You are truly a master at all you do.

    Thank you once again!
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds