Trojans detected, looking for help

Discussion in 'Malware Help (A Specialist Will Reply)' started by opjpb, Feb 5, 2014.

  1. opjpb

    opjpb Private E-2

    Hello all,
    On the latest Avira system scan for this computer, the virus "BOO/Tdss.O" was detected. I followed an internet search to a windows forum post that recommended using Windows Defender Offline. I booted WDO up, which found another virus, "DOS/Aruleon.E," but did not find the BOO/Tdss.O. WDO was unable to remove the DOS/Aruleon.E, and Avira is still reporting the BOO/Tdss.O upon start up. Another internet search for the Aruleon virus brought me here, and I have followed the "Read & Run Me First" up to step 4 of removal, and am attaching the files I can. Unfortunately, the HitmanPro log is too big to upload here. I would deeply appreciate any help the community can offer.
    Thanks for your time and help in advance!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Rerun Hitman and have it remove all that it found. Reboot, rescan and attach the new log.
     
  3. opjpb

    opjpb Private E-2

    Okay, cleared, rebooted, and rescanned. Here is the new Hitman log.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me what issues you are having, if any.
     
  5. opjpb

    opjpb Private E-2

    I unfortunately don't have too many details, as this is my coworker's computer, but she has been complaining of popups, new tabs being opened and redirected in Firefox, and general slowness. I also noticed while scanning that the computer will constantly "tab out," in that it will act as if the active program has been switched, although no open windows will change. I have not personally seen any popups or redirects, but the initial Avira and Windows Defender Offline scans did remove some adware. Furthermore, Avira has not had any alerts for the BOO/Tdss.O virus since I let Hitman remove what it found, but I have not had a chance to run another full scan yet.
    Thank you for looking into this, and I hope some of this info helps. I will be keeping an eye on this thread over the weekend, but I won't be back in the office until Monday morning, so I won't be able to work on the computer until then.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Just let me know how things are running when you get back to it.
     
  7. opjpb

    opjpb Private E-2

    Okay, I have run full scans with Avira, Malwarebytes, and Windows Defender Offline, which have all been clean. I also reran the scans in the Read First sticky. Roguekiller had some flags in the registry, but all other scans were clear. I'm including the new logs in case you need to look them over. However, the "tabbing out" continues to be an issue. Is it possible that there is a missed virus causing this, or should I start looking at software/hardware issues?
    Thanks!
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I see that may be a problem is this:
    Code:
    [SHELLSPWN] HKLM\[...]\command :  ("C:\Program Files (x86)\Prezi\Prezi.exe" "%1") -> FOUND
    [SHELLSPWN] HKCR\[...]\command :  ("C:\Program Files (x86)\Prezi\Prezi.exe" "%1") -> FOUND
    Rerun RogueKiller and remove them. Then if you still have issues, I suggest you post in the software forum.
     
  9. opjpb

    opjpb Private E-2

    Okay, I'll take care of that and see how it goes. Thank you so much for your help!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. Let me know how things go.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds