Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

trojan i think


  • This topic is locked This topic is locked
31 replies to this topic

#1 clintonholmes

clintonholmes

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 30 April 2013 - 03:08 PM

Thank you in advance for any help that can be provided.  I think I have a nasty trojan virus that I haven't been able to remove.  I've tried several programs over a period of time and none have solved the problem.  Microsoft security essentials removed some stuff but didn't completely fix the problem.  I've tried Kaspersky, ccleaner (which runs way slower that it should), malwarebytes just freezes before completing its scan.  I have glary utilities on the computer right now.  There have been others that I have downloaded (and can't remember) and deleted to try and avoid conflicts.
 
When downloading files I can't just run a download.  It says it doesn't work and asks me to retry.  I am able to save the file first, then run it.  Forgive me for not being able to be more descriptive as to what the problem is.  I am a novice on the computer.
 
Again, thank you in advance for you efforts.


Please let me know any other specifics you would like me to give.  I'd give you more but I barely know what I'm talking about.  Also, I'm not sure if I have a firewall enabled like you ask in the prep guide.  It has instructions for a different version of windows.  I have windows 7 and couldn't find appropriate instructions for it.

Attached Files


Edited by boopme, 30 April 2013 - 03:21 PM.


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 40,747 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:20 AM

Posted 04 May 2013 - 08:44 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===
Third party programs if not up to date can be the cause of infiltration an infection.

Please run this security check for my review.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===

Search and delete the AdWare, PUP (Potentially Unwanted Program) installed on your computer.

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete tab follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Rn].txt (n is a number).
===

Please download ComboFix from any of the links below, and save it to your desktop. For information regarding this download, please visit this web page: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Link 1
Link 2

IMPORTANT !!! Save ComboFix.exe to your Desktop

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Do not install any other programs until this if fixed.


How to : Disable Anti-virus and Firewall...
http://www.bleepingcomputer.com/forums/topic114351.html

Double click on ComboFix.exe and follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt
Note: Do not mouse click ComboFix's window while it's running. That may cause it to stall

Note: If you have difficulty properly disabling your protective programs, refer to this link --> http://www.bleepingcomputer.com/forums/topic114351.html

Note: If after running ComboFix you get this error message "Illegal operation attempted on a registry key that has been marked for deletion." when attempting to run a program all you need to do is restart the computer to reset the registry.
===

Please paste the logs in your next reply DO NOT ATTACH THEM.
Let me know what problem persists.

#3 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 04 May 2013 - 04:13 PM

 Results of screen317's Security Check version 0.99.63 
 Windows 7 Service Pack 1 x64 (UAC is enabled) 
 Internet Explorer 9 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Disabled! 
Kaspersky PURE 3.0  
 Antivirus up to date!  
`````````Anti-malware/Other Utilities Check:`````````
 Java™ 6 Update 25 
 Java version out of Date!
 Adobe Flash Player 11.6.602.180 
 Google Chrome 26.0.1410.64 
````````Process Check: objlist.exe by Laurent```````` 
 Norton ccSvcHst.exe
 Kaspersky Lab Kaspersky PURE 3.0 avp.exe 
 Kaspersky Lab Kaspersky PURE 3.0 klwtblfs.exe 
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C: 23% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
 

 

I am very busy this weekend.  I probably won't be able to get to the next step til monday.  Thanks again for the help.

 



#4 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 04 May 2013 - 04:34 PM

Copy and pasting doesn't seem to want to work but...

 

# AdwCleaner v2.300 - Logfile created 05/04/2013 at 16:21:15
# Updated 28/04/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Clint - CLINT-PC
# Boot Mode : Normal
# Running from : C:\Users\Clint\Downloads\adwcleaner.exe
# Option [Delete]

***** [Services] *****

***** [Files / Folders] *****

Folder Deleted : C:\Program Files (x86)\OApps

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Software\Freecause
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{443789B7-F39C-4B5C-9287-DA72D38F4FE6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Software

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16476

[OK] Registry is clean.

-\\ Google Chrome v26.0.1410.64

File : C:\Users\Clint\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [1700 octets] - [04/05/2013 16:21:15]

########## EOF - C:\AdwCleaner[S1].txt - [1760 octets] ##########

 

 

I have a trial version of kaspersky currently on my computer.  I am not impressed.  I am curious to know what you would recommend.  The cheaper the better.  I am currently underemployed.

 

Also...  I use my computer pretty much for only surfing the net and playing a computer game Civilization V.  I'd prefer anything else not of use be removed so if there is anything you want me to take off it, good with me.

 

Thanks as always for the help.  Combofix will have to wait til monday when I have more time to read up on the instructions.



#5 nasdaq

nasdaq

  • Malware Response Team
  • 40,747 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:20 AM

Posted 05 May 2013 - 07:34 AM

Secure your system by updating 3rd party programs.

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.

Be careful not to install malware posing as Java update!
Important read this blog.
http://blog.trendmicro.com/trendlabs-security-intelligence/malware-poses-as-an-update-for-java-0-day-fix/

Quoted from the page.
"In light of the recent events surrounding Java, users must seriously consider their use of Java. Do they really need it? If yes, make sure that users follow the steps we recommended and get the security update directly from the official oracle website." at:
http://www.oracle.com/technetwork/java/javase/downloads/index.html

How to disable Java in your browsers
http://www.infoworld.com/t/web-browsers/how-disable-java-in-your-browsers-210882

You can manually check your present version and update as recommended.
https://www.java.com/en/download/installed.jsp

If present remove the old version(s) of Java using the Add/Remove Programs applet.

Java 6 Update 25

Note
Java security update installs Ask Toolbar by default -- a single click in a multi-step installer.
http://www.benedelman.org/images/iac-jan13/ask-iac-011613-small.png
I suggest that your un-check the box "Install the Ask Toolbar" before proceeding.
===

Critical vulnerabilities have been identified in old version of Adobe Flash Player please get the latest version.

Summary: Adobe has released security updates for Adobe Flash Player 11.6.602.180 and earlier versions for Windows and Macintosh, Adobe Flash Player 11.2.202.275 and earlier versions for Linux, Adobe Flash Player 11.1.115.48 and earlier versions for Android 4.x, and Adobe Flash Player 11.1.111.44 and earlier versions for Android 3.x and 2.x. These updates address vulnerabilities that could cause a crash and potentially allow an attacker to take control of the affected system.

Get the latest Flash Player

On the top of the page you will be given an opportunity to download the version for your operating system.
Make sure you select appropriate version.

You will also have an option to install the Free! McAfee Security Scan Plus Un-check the box if you are NOT using McAfee's virus protection software.

For the users of Internet Explorer download version 11.
Flash Player 11 (64 bit)
Flash Player 11 (32 bit)
===


Total Fragmentation on Drive C: 23% Defragment your hard drive soon! (Do NOT defrag if SSD!)
If you hard disk is not a Solid State Disk, take care of this when you know you will not be using your computer for one or two hours.
===


I have a trial version of kaspersky currently on my computer. I am not impressed. I am curious to know what you would recommend. The cheaper the better

Kaspersky is good. If you cannot afford to keep it to date I suggest one of these free programs.
 

It is really dangerous to go online without an antivirus. Without one, you are extremely likely to get infected and the consequences could be even worse next time. All of the following are excellent free versions of commercial antiviruses. Be sure to only install one.
AVG.
If you install AVG it will install Chrome unless you deny it.
avast!.
AVAST will install the Google Chrome if not already installed. If you do not want to keep it just remove it using the Add/Remove Programs list.
AntiVir


If you decide to try one of these then make sure that Kaspersky is removed completely before installing a new one.

Remove Kaspersky Pure 3.
http://support.kaspersky.com/9501

I do not suggest you make a change to this program until we have a clean computer.
===


Waiting for you ComboFix report.

#6 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 07 May 2013 - 01:34 AM

I tried to run combofix.  It said it completed stages 1-4 and froze i think.  I let it run for over an hour the first time.  I restarted my computer and tried again.  This time I got a 2 error messages as the program started to run (stage 1 area).  They read... 

 

c:\program files\toshiba\tphm\tpchwmsg.exe

illegal operation attempted on a registry key that has been marked for deletion  and the same for

c:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe

 

Again the program said it completed stages 1-4.  This time I only let it run for about a half hour before closing it.

 

I went to java's website using your link.  But the download failed to work properly.  It just froze up instead.



#7 nasdaq

nasdaq

  • Malware Response Team
  • 40,747 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:20 AM

Posted 07 May 2013 - 08:39 AM

You have to restart the computer normally and run ComboFix again.
See the ComboFix instructions on post no. 2.
 

This time I got a 2 error messages as the program started to run (stage 1 area). They read...

c:\program files\toshiba\tphm\tpchwmsg.exe
illegal operation attempted on a registry key that has been marked for deletion and the same for
c:\program files\toshiba\toshiba hdd ssd alert\tossenotify.exe

Again the program said it completed stages 1-4. This time I only let it run for about a half hour before closing it.


p.s.
If ComboFix seems to stall, look at your computer time if it's running let it finish.
Stop it if the time does not change.

#8 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 07 May 2013 - 06:24 PM

  • How exactly am I suppose to know if its running correctly?  What time am I suppose to look at?  Its again only completed 4 stages and its been running for 4 hours when saying it usually only takes 10 minutes.

 

Note, I'm typing this from a different computer.  I've been running the program while disconnected from the internet, if it matters.

 

Also, In the second post, the "how to use combo fix" when I try to look at it, it just redirects me to this page.



#9 nasdaq

nasdaq

  • Malware Response Team
  • 40,747 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:20 AM

Posted 08 May 2013 - 06:44 AM

--RogueKiller--
  • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+


#10 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 08 May 2013 - 07:29 PM

RogueKiller V8.5.4 _x64_ [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Clint [Admin rights]
Mode : Remove -- Date : 05/08/2013 19:23:36
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\windows\system32\drivers\etc\hosts

 

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK5075GSX +++++
--- User ---
[MBR] 7f79cb000448030f522d37fdcf96dd4d
[BSP] 7baa029788e9cf5e28b7bc72b87ad807 : Windows Vista MBR Code
Partition table:
0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 460413 Mo
2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 945999872 | Size: 15026 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2]_D_05082013_02d1923.txt >>
RKreport[1]_S_05082013_02d1923.txt ; RKreport[2]_D_05082013_02d1923.txt



#11 nasdaq

nasdaq

  • Malware Response Team
  • 40,747 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:20 AM

Posted 09 May 2013 - 08:03 AM

Makes sure that Kaspersky is disable and run ComboFix one move time.

If it fails to run to completion try this one.

Download OTL to your desktop.
Double click on the icon to run it.
Make sure all other windows are closed and to let it run uninterrupted.

OTL_Main_Tutorial.gif
  • Select All Users.
  • Under the Custom Scan box paste this text in bold in
netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
winsock.*
/md5stop
CREATERESTOREPOINT


Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Post both logs DO NOT ATTACH THEM.

#12 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 09 May 2013 - 07:44 PM

I tried combofix again.  It did the same thing.  I quit it after about an hour.  Kaspersky was disabled each time I ran it.  OTL is running right now (I am typing this from a different computer).  Its taking forever.  Longer than it should be I think.  At the bottom it says...

 

Pattern search - Looking at file c:\users\clint\appdata\local\microsoft\windows\temporary internet files\content.ie5\hzqvp74v\... absurd number of files, especially if these are only suppose to be temporary internet files.

 

I was thinking I should maybe go in and delete these files manually.  Combofix and Otl don't seem to stall.  They just seem to want to run forever.  Right now the last file line is at admeld_fds_fc_ap_... 

 

The program has been running about an hour.  I'm going to give it another half hour but don't expect it to finish in that time.

 

Again thank you for trying to help.



#13 nasdaq

nasdaq

  • Malware Response Team
  • 40,747 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:04:20 AM

Posted 10 May 2013 - 06:34 AM

Delete all your Temporary Internet files with this tool.

Please download CCleaner (freeware) from [URL=http://www.piriform.com/ccleaner/features %5BB%5Dhere[/b].
Run the installer, and uncheck the option to install Yahoo toolbar (unless you want Yahoo toolbar).
Once installed, run CCleaner.

The following should be selected by default, if not, please select:
oqyhk8.gif

Then please click 30ijknb.gif and choose 5x3nu8.gif

Please uncheck 2wlsw11.gif

Then go back to 2jb4qyb.gif and click nf47ev.gif to run it.

If presented with an option to install 3rd party software, deny it.
===

Post a ComboFix or a OTL log for my review.

#14 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 10 May 2013 - 03:47 PM

I had CCleaner on that computer.  I've tried running it in the past but could not get it to finish anymore.  Again it runs, but wants to run forever.  It was running for about a half hour when I went to this (other computer), booted it up, ran CCleaner on this computer (took about 3 minutes), and came back here to post.  Its in running in that same temporary internet files folder and is only at ad... right now despite running for some time.  Its going to take all night to make it through the alphabet at this pace.



#15 clintonholmes

clintonholmes
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:04:20 AM

Posted 10 May 2013 - 04:29 PM

Still running.  At adsca...






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users