Need help removing a desktop hijaking Trojan.

It wiped out my desk top, a process called vpoon shows running in startup files and the Intel graphics icon is now coming up in regular boot on task bar.

I used the DIY log section and here is the malware log and I ran roguekiller after finding the trojan and I have attached those files:

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.09.30.06

Windows 7 x64 NTFS (Safe Mode/Networking)
Internet Explorer 8.0.7600.16385
SD :: MININT-4F38PMO [administrator]

9/30/2012 7:46:17 PM
mbam-log-2012-09-30 (19-50-38).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 210625
Time elapsed: 3 minute(s), 5 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|vpoonHvNrUjJtee.exe (Trojan.FakeAV) → Data: C:\ProgramData\vpoonHvNrUjJtee.exe → No action taken.

Registry Data Items Detected: 2
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) → Bad: (0) Good: (1) → No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) → Bad: (0) Good: (1) → No action taken.

Folders Detected: 0
(No malicious items detected)

Files Detected: 5
C:\ProgramData\vpoonHvNrUjJtee.exe (Trojan.FakeAV) → No action taken.
C:$RECYCLE.BIN\S-1-5-18$0969aa2923041fd3a04a6e12edee7bcd\n (Trojan.0Access) → No action taken.
C:$RECYCLE.BIN\S-1-5-21-2107614648-1780357811-3228383531-1002$0969aa2923041fd3a04a6e12edee7bcd\n (Trojan.0Access) → No action taken.
C:\Users\SD\AppData\Local\Temp\32724828.exe (Trojan.Agent.Gen) → No action taken.
C:\Users\SD\Local Settings\Application Data\Temp\32724828.exe (Trojan.Agent.Gen) → No action taken.

(end)

your malwarebytes log say “No Action Taken” you need to click the “Remove Selected” button after scan to quarantine the infections

Follow this guide and attach the logs (not copy and paste) http://forum.avast.com/index.php?topic=53253.0

AdwCleaner
Malwarebytes
OTL
aswMBR

Sorry yes I did that, the instructions I thought indicated to copy the log before I hit delete. So I deleted in malware and roguekiller, am I good or do I need to run something else?

if you want a check inside by a removal specialist?

follow the guide i gave you and attach the requested logs

I am confused, the guide says not to do all the steps if you have a certian trojan (which I did, lets hope its gone)m so do you still want me to do all of them?

The OTL log and aswMBR are attached. The previous posts have the rogue killer

We will need to use Combofix to repair the damage

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

https://dl.dropbox.com/u/73555776/OTL_Fix.GIF

:OTL
FF - prefs.js..extensions.enabledAddons: rndjyevwvj@rndjyevwvj.org:1.0
FF - prefs.js..extensions.enabledAddons: crossriderapp435@crossrider.com:0.72.17
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\crossriderapp435@crossrider.com: C:\ProgramData\CodecCheck\firefox [2011/11/12 18:07:08 | 000,000,000 | ---D | M]
[2012/05/11 16:10:50 | 000,004,733 | ---- | M] () (No name found) -- C:\Users\SD\AppData\Roaming\Mozilla\Firefox\Profiles\mv0k3ima.default\extensions\rndjyevwvj@rndjyevwvj.org.xpi
[2011/11/12 18:07:08 | 000,000,000 | ---D | M] ("Premiumplay Codec-C") -- C:\PROGRAMDATA\CODECCHECK\FIREFOX
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-2107614648-1780357811-3228383531-1002\..\Toolbar\WebBrowser: (no name) - {10CECF4F-A96E-4803-8AC2-F565FB29FF47} - No CLSID value found.
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

:Reg
[HKEY_CLASSES_ROOT\CLSID\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InprocServer32] 
""="%systemroot%\system32\wbem\wbemess.dll" 
[-HKCU\Software\Classes\clsid\{12d0253a-7c96-815c-11e0-3034bbd97cc0}] 

:Files
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt  /c
ipconfig /release /c
ipconfig /renew /c

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

FINALLY

run farbar service scanner

https://dl.dropbox.com/u/73555776/FSS.GIF

Tick “All” options.
Press “Scan”.
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

While you were responding I was runnign maleware. It caught another item and I posted that log as well as the new OTL log I just did. I let maleware delete the new trojan but now on boot up a black screen appears telling me there is a disk error and then it cancels itself and loads windows.

Here is the OTL quick scan log, now I am off to do the second

and the combo fix log

here is the fss log, aside from the message at boot up it seems OK

Looks good, any outstanding problems ?

Yes after removing the second trojan on boot up a black screen appears with a disk needs to be cleaned and then it says the rquest was dfeleted and finishes booting up windows. Did the trojan attack the BIOS?

I have yet to come across a BIOS virus, it may be that windows detected a dirty bit on the hard drive. How is it booting now ? Any problems

same message, I just reinstalled firefox as my secondary. I am going to defrag and try booting again, maybe that will help.

PS thanks for helping me again and as always how’d you get so smart

It may be beneficial to run a disc check to clear any dirty bits… Do you know how to do that ?

Uh oh, to quickly find the defrag I searched for defrag, disk defragmenter came up and so did something just called defrag. Disk defragmenter only shows my recovery disk and the other one bring up a small DOS window that quickly scrolls through white letters and poof disappears. Is this normal? And no not sure how to do a check…

OK could you follow the destrucions here on how to schedule and run a check disc http://www.w7forums.com/use-chkdsk-check-disk-t448.html

That did the trick, you are a viruses worst nightmare you are. Your assistance was brilliant thanks ever so much

Any further problems before I tidy up ?