Author Topic: Trojan and Malware gen threats with Avast popping up every 4 min  (Read 8190 times)

0 Members and 2 Guests are viewing this topic.

robinson0418

  • Guest
I need help to remove these threats completely. I ran malware bytes and avast that helped however am still getting avast popping up every 4-5 min with trojan and malware threats detected.  I have attached a copy of the malware bytes log for review.  I also included OTL log document and extras.  I have also included aswMBR. Thanks for your help!
Sam

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #1 on: August 29, 2012, 12:44:43 AM »
we also need OTL.txt

robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #2 on: August 29, 2012, 01:14:28 AM »
OK OTL now attached

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #3 on: August 29, 2012, 01:16:27 AM »
malware removers are notified. It may take hours before one arrive so be patient

robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #4 on: August 29, 2012, 09:37:18 AM »
here is OLT extras

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #5 on: August 29, 2012, 03:26:04 PM »
Hi you also have the babylon toolbar so I shall clear that as well

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Reg
[HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32]
""="%systemroot%\system32\wbem\wbemess.dll"
[-HKCU\Software\Classes\clsid\{12d0253a-7c96-815c-11e0-3034bbd97cc0}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS]
"DisplayName"="@%SystemRoot%\\system32\\qmgr.dll,-1000"
"ImagePath"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,\
  74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,73,\
  00,76,00,63,00,68,00,6f,00,73,00,74,00,2e,00,65,00,78,00,65,00,20,00,2d,00,\
  6b,00,20,00,6e,00,65,00,74,00,73,00,76,00,63,00,73,00,00,00
"Description"="@%SystemRoot%\\system32\\qmgr.dll,-1001"
"ObjectName"="LocalSystem"
"ErrorControl"=dword:00000001
"Start"=dword:00000002
"DelayedAutoStart"=dword:00000001
"Type"=dword:00000020
"DependOnService"=hex(7):52,00,70,00,63,00,53,00,73,00,00,00,45,00,76,00,65,00,\
  6e,00,74,00,53,00,79,00,73,00,74,00,65,00,6d,00,00,00,00,00
"ServiceSidType"=dword:00000001
"RequiredPrivileges"=hex(7):53,00,65,00,43,00,72,00,65,00,61,00,74,00,65,00,47,\
  00,6c,00,6f,00,62,00,61,00,6c,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,\
  67,00,65,00,00,00,53,00,65,00,49,00,6d,00,70,00,65,00,72,00,73,00,6f,00,6e,\
  00,61,00,74,00,65,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,\
  00,00,53,00,65,00,54,00,63,00,62,00,50,00,72,00,69,00,76,00,69,00,6c,00,65,\
  00,67,00,65,00,00,00,53,00,65,00,41,00,73,00,73,00,69,00,67,00,6e,00,50,00,\
  72,00,69,00,6d,00,61,00,72,00,79,00,54,00,6f,00,6b,00,65,00,6e,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,53,00,65,00,49,00,6e,00,\
  63,00,72,00,65,00,61,00,73,00,65,00,51,00,75,00,6f,00,74,00,61,00,50,00,72,\
  00,69,00,76,00,69,00,6c,00,65,00,67,00,65,00,00,00,00,00
"FailureActions"=hex:80,51,01,00,00,00,00,00,00,00,00,00,03,00,00,00,14,00,00,\
  00,01,00,00,00,60,ea,00,00,01,00,00,00,c0,d4,01,00,00,00,00,00,00,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
"ServiceDll"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,\
  00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,\
  71,00,6d,00,67,00,72,00,2e,00,64,00,6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Performance]
"Library"="bitsperf.dll"
"Open"="PerfMon_Open"
"Collect"="PerfMon_Collect"
"Close"="PerfMon_Close"
"InstallType"=dword:00000001
"PerfIniFile"="bitsctrs.ini"
"First Counter"=dword:000007d2
"Last Counter"=dword:000007e2
"First Help"=dword:000007d3
"Last Help"=dword:000007e3
"Object List"="2002"
"PerfMMFileName"="Global\\MMF_BITS_s"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Security]
"Security"=hex:01,00,14,80,90,00,00,00,a0,00,00,00,14,00,00,00,34,00,00,00,02,\
  00,20,00,01,00,00,00,02,c0,18,00,00,00,0c,00,01,02,00,00,00,00,00,05,20,00,\
  00,00,20,02,00,00,02,00,5c,00,04,00,00,00,00,02,14,00,ff,01,0f,00,01,01,00,\
  00,00,00,00,05,12,00,00,00,00,00,18,00,ff,01,0f,00,01,02,00,00,00,00,00,05,\
  20,00,00,00,20,02,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,04,\
  00,00,00,00,00,14,00,8d,01,02,00,01,01,00,00,00,00,00,05,06,00,00,00,01,02,\
  00,00,00,00,00,05,20,00,00,00,20,02,00,00,01,02,00,00,00,00,00,05,20,00,00,\
  00,20,02,00,00

:Files
C:\Windows\assembly\GAC_32\Desktop.ini
C:\Windows\assembly\GAC_64\Desktop.ini
C:\Windows\Installer\{b94f4e27-57ca-54c6-faaa-b0ab04add4e2}
C:\Users\Ghost\AppData\Local\{b94f4e27-57ca-54c6-faaa-b0ab04add4e2}
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt  /c
ipconfig /release /c
ipconfig /renew /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

FINALLY

Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete



Once done it will ask to reboot, allow this
On reboot a log will be produced please attach that

robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #6 on: August 29, 2012, 08:21:09 PM »
step 1 OTL log added

robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #7 on: August 29, 2012, 09:26:48 PM »
Part 2

robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #8 on: August 29, 2012, 09:29:14 PM »
Malware program is now getting alerts like every 3 minutes or so on to final part

robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #9 on: August 29, 2012, 09:43:02 PM »
Final Part

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #10 on: August 29, 2012, 09:57:05 PM »
Could you confirm that you are still getting alerts ..  And include a screenshot of the popup

msgorham37

  • Guest
I also have the same Trojan Rootkit as the others. PLEASE HELP!!!
« Reply #11 on: August 29, 2012, 10:27:17 PM »
I receive the same Avast! pop-up about every five minutes. I thought I had cornered the sucker and put it our of its misery but it seems to be more clever than I am.
I am not sure which logs to post so I am going to post the ones I have that are the most recent.
Please help me disinfect this trojan so I may go back to happy, safe surfing. Thank you!!

msgorham37

  • Guest
Reply with log from aswMBR.exe
« Reply #12 on: August 29, 2012, 10:45:35 PM »
Here is the log from the aswMBR.exe program.

robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #13 on: August 29, 2012, 10:57:54 PM »
I am still having problems now with malware pops included is screen capture of error


robinson0418

  • Guest
Re: Trojan and Malware gen threats with Avast popping up every 4 min
« Reply #14 on: August 29, 2012, 11:01:18 PM »
picture did not show up here is the screen capture