Author Topic: Trojan 80000000.@  (Read 5988 times)

0 Members and 1 Guest are viewing this topic.

Sterling Bronze

  • Guest
Trojan 80000000.@
« on: October 17, 2012, 11:36:18 PM »
Hello, i have been suffering from this problem for a day now where Avast is telling me that i have infected and i delete it but it reappears 5-10 minutes later.

The specific Codes are, 80000000.@, 00000004.@, 000000cb.@, 80000032.@

really hoping to get rid of this, thanks in advance!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37629
  • Not a avast user
Re: Trojan 80000000.@
« Reply #1 on: October 17, 2012, 11:39:16 PM »
follow guide and attach logs....not copy and paste.  http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR


when done a removal specialist will help you. it may take hours before one arrive so be patient

Sterling Bronze

  • Guest
Re: Trojan 80000000.@
« Reply #2 on: October 18, 2012, 01:13:03 AM »
Logs you requested are here
« Last Edit: October 18, 2012, 01:15:15 AM by Sterling Bronze »

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Trojan 80000000.@
« Reply #3 on: October 18, 2012, 01:21:57 AM »
Im on it  ;)

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Trojan 80000000.@
« Reply #4 on: October 18, 2012, 01:27:45 AM »
@Sterling Bronze
Hello and wellcome 8)

  • I will be working on your Malware issues this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • If you don't know or understand something, please don't hesitate to ask.
  • Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc...)
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • It is important that you reply to this thread. Do not start a new topic.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Absence of symptoms does not mean that everything is clear.
------------------------
  Step#1 
Code: [Select]
-> No action taken.
Re-run MBAM


  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember ( desktop for example ).
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


**********************

  Step#2 

Download TDSSKiller  and save it to your desktop

    Execute TDSSKiller.exe by doubleclicking on it.

  •     Press Start Scan

     
  •   If Suspicious object is detected, the default action will be Skip, click on Continue.
     
  •   If Malicious objects are found, select Cure.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.


************************
  Step#3 


> Download ComboFix from here and save it to your Desktop.
If you are unsure how ComboFix works please read this guide carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this or this Instruction.

How to disable avast:

  • Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
  • In the window that opens on the top right corner, click Settings.
  • In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.

  • Right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
  • In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.



************************
  Step#4 


> Check USB storage devices / removable drives


Download MCShield from one of the following links:

MyCity -  Official download link
Softpedija - Mirror download link

  • Double click MCShield-Setup to install the application.
  • Wait a few seconds to MCShield finish initial scan.
Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
  • Connect your USB storage devices to the computer one at a time. Scanning will be done automatically.
When all scanning is done, you need to attach a logreport that has made MCShield.

Start -> All Programs -> MCShield -> Logs

Attach here -> AllScans.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.



Sterling Bronze

  • Guest
Re: Trojan 80000000.@
« Reply #5 on: October 18, 2012, 03:52:31 AM »
here's the logs. the TDDSS one is too large even tho its in ansi format to upload.
Combo fix seemed to do the trick since after i rebooted everything back up (avast), i haven't been getting the pop ups for trojans.
didn't use MCshield since i haven't had usb hookups to it.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Trojan 80000000.@
« Reply #6 on: October 18, 2012, 04:05:28 AM »
Open notepad and copy/paste the text present inside the code box below:


Code: [Select]

DirLook::
c:\windows\SysWow64\{9A4521A4-FD3A-4725-9851-9B4A1369BA08}{641DB4BC-ED5E-460D-BCC1-0C0E82C1D712}
c:\windows\SysWow64\{36C7D2EC-06C2-4796-A89F-93AD16CB453C}{773EA457-729E-4870-B6F0-EA50D8D2DAEC}
c:\windows\SysWow64\{9A4521A4-FD3A-4725-9851-9B4A1369BA08}{47C5E9B3-E9BE-45C6-A88E-51C1A645394A}
c:\windows\SysWow64\{9A4521A4-FD3A-4725-9851-9B4A1369BA08}{FA4D38DE-735C-4D16-B032-457AA3C33725}

ClearJavaCache::

Folder::
c:\windows\Installer\{10860994-414b-41f0-9829-30ce2a4d7a99}

FileLook::
c:\windows\system32\services.exe



Save this as CFScript.txt



Close all browser windows and refering to the picture above.

Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:\ComboFix.txt )

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Trojan 80000000.@
« Reply #7 on: October 18, 2012, 04:08:48 AM »
Also, can you TDSSKiller log paste log here:

www.pastebin.com

Paste txt ( TDSSKiller log ) there and click on Submit.

Please just copy/paste here URL link so i may view TDSSKiller log  ;)

Sterling Bronze

  • Guest
Re: Trojan 80000000.@
« Reply #8 on: October 18, 2012, 04:12:54 AM »
http://pastebin.com/pjQR9WtV

Here's the TDSS killer log, i'll update you when combo fix is done

Sterling Bronze

  • Guest
Re: Trojan 80000000.@
« Reply #9 on: October 18, 2012, 04:54:03 AM »
and here's the combofix

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Trojan 80000000.@
« Reply #10 on: October 18, 2012, 12:09:33 PM »
Looks good. How's your computer running now?

Sterling Bronze

  • Guest
Re: Trojan 80000000.@
« Reply #11 on: October 18, 2012, 03:43:35 PM »
is running fine now today no avast pop-ups, you're help has been greatly appreciated! you're the man

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: Trojan 80000000.@
« Reply #12 on: October 18, 2012, 08:53:42 PM »
It is necessary to uninstall ComboFix :
  • Click Start (or ) then Run.


    On Windows7 or Vista you may use Start Search field if Run is not available.

  • In the line of text type in (Copy) the following:
Code: [Select]
ComboFix /Uninstall
    Note that there is a space between " ComboFix " and " /Uninstall " .

    • then click OK (or press Enter ).
    Wait for the uninstall process is complete.


    ------------------------------


    > Re-run OTL and click on CleanUp! button.

    You will be asked to reboot the machine to finish the cleanup process, choose Yes.
    After the reboot all the tools we used should be gone.
    Note: Some more recently created tools may not yet be removed by OTL. Feel free to manually delete any tools it leaves behind.