Trojan Woes

Discussion in 'Malware Help (A Specialist Will Reply)' started by Eppiox, Mar 1, 2009.

  1. Eppiox

    Eppiox Private E-2

    -Machine Xp sp3 build 2600 080814-1236
    P4 1gig ram

    -Introduction:major
    I have been fixing friends infected computers and damaged parts for many years now, however my auntie who downloaded and ran a Trojan from a file she downloaded in lime wire (i told her not to use it!:cry) informed her she needed to download X.file to view what she just downloaded.
    I have tried all my tricks to fix it but nothing worked.
    Things i normally try (and up until this point have worked);
    1. Avg (already installed, gave it a go but it would not start, it is uninstalled now.)
    2. Crap Cleaner
    3. RunViewer (Used up free trial)
    4. HijackThis
    5. Nod32 (picked up some things after the first, 2 hour scan, nothing on the next)
    6. A .exe file association repair registry entry file (worth a shot)
    7. Recovery Console (was going to reset windows policies, i still have not reset them yet)

    -Symptoms Before:major
    1. Her user profile seems to have been restricted, "folder options" was removed Processing Time egg kept appearing
    2. .exe files in the root of C:\
    3. Constant web redirecting to anti spyware programs (irony) ->webclicks
    4. Huge slow down in speed
    5. Some .exe programs fail to execute
    6. System Restore wont initiate.

    -Symptoms After :major
    1. i tried to repair, (i made a new user with administrator rights to gain more control and view hidden files.)
    2. Browser Hijacking still
    3. Some .exe programs fail to execute
    4. System restore still wont initiate.

    -Following the guide from this point on:major
    1. Mbam does not start.
    2. Spy bot does not start.
    3. SuperantiSpyware does not start.
    4. combofix does not start.
    5. Mgtools ran and made a log file.

    By not run i mean i double click on the exe, the time egg shows up for about 1 second then disappears.

    Made an sp3 cd (from from another pc, i might try from hers tommorow) and the Recovery Console still will not run. As soon as i click it it fails to get past the blinking dashing line.

    Latest javascript will not install returning the error "The system administrator has set policies to prevent this installation"-another reason for my self to try and reset policies (still need to try and do it)

    Any Help would be greatly appreciated (i want to cure this machine, i see formatting as been defeated, also my auntie requested if possible to back it up and with it being infected by an unknown trojan and my pc the only way to back her data up (single hard drive) i would be worried for my files also)

    I will be back in about 16 hours to reply :) (sorry if that is to far away, in between those 16 hours are a nights sleep:zzz and a 9 hours shift of work:p-doh)
    (attached is the only log file i could generate)
    Thanks in advance-Eppiox
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this:
    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

    * Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    * Then search for TDSSserv.sys
    * Let me know if you find this or not.
    * If you do find it, right click on it, and select Disable. Do not try to uninstall it.
    * Also if this is found and you disable it, then reboot and see if you can run the other scans that would not run.

    Now, Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\TEMP\UAC998b.tmp
    C:\a.exe
    C:\VirusTrojanBusting --> unless this is something you created.
    C:\WINDOWS\system32\ghu02
    C:\WINDOWS\system32\a.dll

    Now download and install:
    Java Runtime 6

    Now try to run the scans and get me the logs. Also, run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  3. Eppiox

    Eppiox Private E-2

    Thank you for helping and.
    Update:
    TDSServ.sys is not there.
    HJT successful
    Reg file successful

    C:\WINDOWS\TEMP\UAC998b.tmp (all temp was cleared out)
    C:\a.exe (is actually a renamed mBam install, renamed it from mb to see if it worked, also trojan was using this file name, thought it was worth a shot)
    C:\VirusTrojanBusting --> unless this is something you created. (it was, has other apps, dll monitors, process tree monitors (all useless in this case)
    C:\WINDOWS\system32\ghu02 (deleted
    C:\WINDOWS\system32\a.dll (deleted

    The java applet installed
    No other programs ran that already did not :(

    Mbam gives an error
    vbAcceleration SGrid II Controll
    Error "0"
    then another error
    Mbam error
    Error 440, automation error
    i see a lot of "missing .mui" in logs when ever i try to run these programs.
    I can now see the folder options menu in the original user account though :)
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system.......and there is very little even running in your logs.

    You could try doing an online scan :
    Using BitDefender Online Scan.

    But I doubt it will find anything.

    Was anything removed before we started this?
     
  5. Eppiox

    Eppiox Private E-2

    The original Trojan was deleted by my auntie along with lime wire, nod32 killed off about 60+ items and i had already run HJT and a few other apps to see what i could disable.

    I think the result might lie with windows policies :/ but i do not know how to reset them without the recovery console.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not knowing what was removed......I'm not sure what you need. If you are talking about permissions, then you can try doing this:

    Reset Registry and File Permissions

    The below is based on original info from http://support.microsoft.com/kb/949377

    Important: This task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:

    How to back up and restore the registry in Windows]

    1. Download and then installSubInACL (SubInACL.exe)file from Microsoft.
    2. Click Start, Run and enter notepad and click OK to bring up the Windows Notepad program.
    3. Copy and then paste the following text into Notepad.

    Code:
    cd /d "%ProgramFiles%\Windows Resource Kits\Tools" 
    subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f /grant=system=f
    subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f /grant=system=f
    subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f /grant=system=f
    subinacl /subdirectories %SystemDrive% /grant=administrators=f /grant=system=f
    subinacl /subdirectories %windir%\*.* /grant=administrators=f /grant=system=f
    secedit /configure /cfg %windir%\repair\secsetup.inf /db secsetup.sdb /verbose
    
    4. Save this Notepad file as Reset.cmd to your desktop. Be sure the Save as type is set to all files.
    5. Once you have save it properly, double-click the Reset.cmd file to run the script.

    * Note This script file may take a long time to run. Additionally, you have to run this script as an administrator.

    6. Now reboot your computer! You must do this before the above will take effect.
     
  7. Eppiox

    Eppiox Private E-2

    Hello TimW I finally fixed the machine.
    I tried to run the windows file but it returned "Administrator has disabled this option in policies "(cant remember exact wording) however i was in administrator in safe mode.

    I snooped around and found an AVG anti root kit. Found 13 items removed them and then the system seemed to be back to normal with hijacking still happening however.

    Ran the windows file, then the command you made and it seems fine.

    I had no idea what a root kit was until this morning.
    After reading if you are infected on the Kernel level via root kits you are never 100% sure of a clean system.

    As she does a lot of internet banking related things on her system i suggested a format and stronger virus prevention programs :) (just to be 100% sure and not 90%)

    Thanks for all your help! Perhaps a root kit scan should be the first step when someone says they cant get a few virus scanner programs to run if it not to great a risk.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know it is working.....:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds