Virtu trojan

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bashy, Dec 7, 2008.

  1. Bashy

    Bashy Private E-2

    If someone could review my logs and tell me what I need to do next, I would very much appreciate it. I had trouble with the removal portion of Super Anti Spyware. I got a blue screen error when trying to do the removal.

    I did the READ ME FIRST and am attaching the logs.

    Thanks ever so much.

    Barbara
     

    Attached Files:

  2. Bashy

    Bashy Private E-2

    Malwarebytes log is attached
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Hello, Bashy

    While I'm looking over the logs you attached - Did you try these instructions
    from SUPERAntiSpyware - running & getting a log?
    dr.m
     
  4. Bashy

    Bashy Private E-2

    I did do this, although I wasn't sure I should since it's not crashing when it runs the scan, it's crashing when it goes to fix the problem, does that make sense? I did not, however, run a complete scan again AFTER I made the modifications.
     
  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, Bashy


    If you have not already done so, please disable the Guest account in User accounts.


    First, please disable any antivirus and/or antispyware programs you have installed so they will not block this fix. (Remember to enable them again when this steps are completed.) Print out these instructions or save them to a text file so as All Browser Windows must be CLOSED. *The fixes are specific to your problem and should only be used for issue(s) on this machine.


    Step 1:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Step 2:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Note: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.
    After clicking Fix, exit HJT.

    Step 3:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.



    Step 4:
    Run Ccleaner


    Step 5:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).


    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt


    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!


    Thanks!
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Bashy

    Please subsititute and use this CFscript.txt in Step 3: instead of the one I posted in my last reply! All instructions remain the same, other than this revision.

    Thanks!
    dr.m
     
  7. Bashy

    Bashy Private E-2

    Thank you for your help. Attached are the logs you requested. I did not have any problems running your instructions.
     

    Attached Files:

  8. Bashy

    Bashy Private E-2

    I am posting to advise of an error I have been receiving since doing the instructions left for me.


    Tool-NirCmd
    A0005111.exe
    c:\system Volume Information\._restore{43DE61f211)\Rp50\A0005111.exe

    Thanks so much for all your help. I greatly appreciate it. I have tried to "clean" and "quarantine" these items with McAfee.
     
  9. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    c:\system Volume Information\._restore{43DE61f211)\Rp50\A0005111.exe is a restore point that will be flushed when I give you the final clean-up steps. Please check via Control Panel > User Accounts and tell me if your Guest Account is (Disabled). That account is considered a security risk.

    Thanks!

    dr.m
     
  10. Bashy

    Bashy Private E-2

    Thanks for the quick response. Yes, the guest account is disabled. I did that earlier at the beginning of your instructions. I just double checked and it shows "off".

    Thanks again!

    Barbara
     
  11. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're Welcome, Barbara.

    Please un-install Java(TM) 6 Update 10 and use the following link to update.

    Sun Java Runtime Environment

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    Safe surfing!... and "Happy New Year!" http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  12. Bashy

    Bashy Private E-2

    Thanks so very much for all your help.
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    You're very welcome. :major
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds