Author Topic: Somehow infected with trojan(s), please help! [FIXED - thank you!]  (Read 8537 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Hiya,
Basically, a few hours ago - it was brought to my attention that I had a potential trojan lurking on my PC. I was talking to my friend in a Skype call when my UAC informed me that Adobe Flash Player needed an update. I was skeptical about this because the publisher listed was not Adobe Systems Incorporated, it was unknown/unverified. When I selected 'No', the UAC window refused to disappear. It would keep popping up aggressively, expecting me to run the exe. I got a little panicky and restarted my PC before scanning everything with Malwarebytes.

It found and quarantined a trojan, and this is what it was from the logs:
http://puu.sh/cOIFc/29076dacbf.png

I was scared so I relayed this info to my friend and he advised me to get Avast because I've mostly been relying on MSE/Malwarebytes and haven't had too many problems. I did this and scanned again, and was greeted with another Trojan called BV:Agent-ANZ. I scanned and quarantined that, and allowed Avast to do the boot scan thing as well. Nothing untoward was picked up, as far as I'm aware.

Now, I was jittery for a couple of hours after this but managed to calm down after I scanned my system several times and nothing dodgy appeared. I was just about to head to bed but I decided to check one last time before hopping off and was greeted with another threat?
http://puu.sh/cOILf/692e652499.png

I'm not sure what's going on. My friend said that I may have to reformat my PC/reinstall Windows, and I'm a little stressed about that because I do not have the Windows disc on me. I don't know how I managed to pick up these trojans, or if they've been latent for a while and have only decided to start being a pain now. I'm worried that this may've been a keylogger because I was having issues with my keyboard being slow/unresponsive when inputting text. Silly me thought that it may've just been the fact that his keyboard is wireless and I'd actually damaged the dongle so I just assumed it was faulty hardware. However, since I've scanned my system and quarantined the buggers, I haven't had any issues so I'm guessing it was related to this trojan.

One thing that I'm thinking may be the root of the issue is that I did visit a website that I trusted earlier yesterday. I have AdBlock installed and NoScript but I was still seeing porny/dodgy ads on the site. Upon checking the URL of the site using AdBlock, I found that the actual site was hosting the ads from its own servers to probably circumvent the filters AdBlock has in place. I'm finding this really suspicious so I'm wondering if this is related.

Please help, I'm not sure what to do. I've never had a trojan before (as far as I'm aware) so I'm really anxious and probably won't get any sleep until I can hopefully get this resolved/know what course of action needs to take place. If you need more info, I will be glad to provide it.
« Last Edit: November 14, 2014, 03:03:46 PM by lishaftw »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Somehow infected with trojan(s), please help!
« Reply #1 on: November 13, 2014, 06:31:48 AM »
Attach your basic logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Somehow infected with trojan(s), please help!
« Reply #2 on: November 13, 2014, 06:44:47 AM »
Attach your basic logs. (MBAM, FRST and aswMBR..!!)
Instructions: https://forum.avast.com/index.php?topic=53253.0

Done, thank you so much for the quick reply. The addition.txt is the FRST thing.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Somehow infected with trojan(s), please help!
« Reply #3 on: November 13, 2014, 06:46:19 AM »
You're welcome, now you've to wait a bit...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Somehow infected with trojan(s), please help!
« Reply #4 on: November 13, 2014, 07:16:02 AM »
You're welcome, now you've to wait a bit...
I just scanned again with MWB and it's found something. It seems like something is downloading these trojans onto my computer. Ah, I'm honestly going to have a panic attack - I didn't expect to deal with all this stuff at quarter past 6 in the morning.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Somehow infected with trojan(s), please help!
« Reply #5 on: November 13, 2014, 07:18:42 AM »
Ah, I'm honestly going to have a panic attack - I didn't expect to deal with all this stuff at quarter past 6 in the morning.
Don't worry, the experts have some powerful tools at hand. :)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Somehow infected with trojan(s), please help!
« Reply #6 on: November 13, 2014, 08:18:22 AM »
Thank you. I can see that the experts here are really awesome and helpful, I just hope my issue won't be too much of a pain for them to look at.

Last couple of scans (10+ maybe? lol) with MWB and Avast have been clean. I think my USB stick may be infected because at the time of discovering the last infection, it was plugged into my system. Since I've removed it, I haven't received any alerts/nothing has been quarantined. I did transfer a folder full of txt files to the USB stick and it was plugged in the system for maybe an hour or so whilst I was removing other threats.

I've pretty much been scanning constantly back and forth on both. Still nervous though. It's my own fault really, I should've had some form of browser protection, but I thought NoScript and AdBlock would be sufficient. I know better now. Fingers crossed this will be something simple to fix.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: Somehow infected with trojan(s), please help! [Unsolved]
« Reply #7 on: November 13, 2014, 08:41:31 AM »
Quote
I think my USB stick may be infected because at the time of discovering the last infection, it was plugged into my system.
see the guide Asyn gave link to....scroll down to SPECIFIC INFECTIONS LOGS /  MCShield instructions ...run as instructed and attach log

removal experts will be online later today, usually after work hours european time   ;)




« Last Edit: November 13, 2014, 08:45:30 AM by Pondus »

REDACTED

  • Guest
Re: Somehow infected with trojan(s), please help! [Unsolved]
« Reply #8 on: November 13, 2014, 08:50:17 AM »
Quote
I think my USB stick may be infected because at the time of discovering the last infection, it was plugged into my system.
see the guide Asyn gave link to....scroll down to SPECIFIC INFECTIONS LOGS /  MCShield instructions ...run as instructed and attach log

removal experts will be online later today, usually after work hours european time   ;)
Thank you!

Is it okay if I wait until my main system is clean before I install and use MCShield? I'm just worried about my rig because I game on this and I don't want these infections to break anything. So far there have been no further infections so I don't want to risk anything.

Haha,  I'm in Europe myself so I guess I'll be waiting a long time for a response. Oh well, I'll just keep scanning.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: Somehow infected with trojan(s), please help! [Unsolved]
« Reply #9 on: November 13, 2014, 08:54:40 AM »
Quote
Is it okay if I wait until my main system is clean before I install and use MCShield?
yepp   ;)


REDACTED

  • Guest
Re: Somehow infected with trojan(s), please help! [Unsolved]
« Reply #10 on: November 13, 2014, 01:43:01 PM »
Last 14 avast! scans (mix of full and quick) have come up clean.
Last 20 MWB scans have also come up clean as well.

No new infections found since the last one that MWB picked up at 6am. It's now over 6 hours later.

I am really, really tired and I haven't slept, haha.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: Somehow infected with trojan(s), please help! [Unsolved]
« Reply #11 on: November 13, 2014, 04:06:15 PM »
Last 14 avast! scans (mix of full and quick) have come up clean.
Last 20 MWB scans have also come up clean as well.

No new infections found since the last one that MWB picked up at 6am. It's now over 6 hours later.

I am really, really tired and I haven't slept, haha.
D'oh! .... why do 34 scans as removal experts are notified.........why do quick and full as full will do the same as quick and then some?




REDACTED

  • Guest
Re: Somehow infected with trojan(s), please help! [Unsolved]
« Reply #12 on: November 13, 2014, 04:13:02 PM »
Last 14 avast! scans (mix of full and quick) have come up clean.
Last 20 MWB scans have also come up clean as well.

No new infections found since the last one that MWB picked up at 6am. It's now over 6 hours later.

I am really, really tired and I haven't slept, haha.
D'oh! .... why do 34 scans as removal experts are notified.........why do quick and full as full will do the same as quick and then some?
I scanned so much because I was worried that whatever is infecting my system would continue to corrupt files while I wait for a response from the removal experts.

The last time I scanned and things were clean (before I posted here), I was going to go to sleep. Before I did, I scanned once more and MalwareBytes found another trojan. So I am a little paranoid that there may still be something hiding. Did I make a mistake?  :'(

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37549
  • Not a avast user
Re: Somehow infected with trojan(s), please help! [Unsolved]
« Reply #13 on: November 13, 2014, 04:19:06 PM »
Quote
Did I make a mistake?
no, but the removal experts here will fix it one go, or two.....the computer in not going anywhere   ;)



Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Somehow infected with trojan(s), please help! [Unresolved]
« Reply #14 on: November 13, 2014, 04:57:09 PM »
Hi you only have the partial infection so it is not active
CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
2014-11-12 22:45 - 2014-11-12 23:00 - 00000000 ____D () C:\ProgramData\SosecRigey
2014-11-12 22:45 - 2014-11-12 22:45 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.