AV keeps detecting Trojan32/jpgiframe.a

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by C1B3R5NYP3R, Sep 3, 2012.

  1. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Step daughter states that all her files and folders went missing. Thought her ex done it but once I started digging into it, it seems that it may be due to malware. No AV installed when I got a hold of her laptop, (Compaq Presario CQ60) so I installed M$ security essentials. Then I started getting popups from the AV saying it was resolving issues. I went into the history and found multiple instances and decided to go through the steps.
    Ran all the scans but I believe I am going to need some help getting rid of the infections.

    Thanks!
    Ciber
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Is the below found by Roguekiller something you use? If not delete the C:\Users\lwilson\AppData\Local\gigglinggamesSA folder.

    Rerun Hitmanpro. You can have it delete all those malware remnants.

    Uninstall the below using Revo Uninstaller. Try Revo Uninstaller.
    Choose the option on the bottom of the list (#4). Be very careful while deleting the bolded registry items ONLY!! This software will create a system restore point for you as well prior to uninstalling a software program.
    • Shop To Win
    • WhiteSmoke US Toolbar
    • WhiteSmokeTranslator
    • Price Peep


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines (if they exist) but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R3 - URLSearchHook: WhiteSmoke US Toolbar - {cce665dd-f6dd-4808-968e-eaec971f70ef} - C:\Program Files (x86)\WhiteSmoke_US\prxtbWhit.dll
    • O2 - BHO: WhiteSmoke US - {cce665dd-f6dd-4808-968e-eaec971f70ef} - C:\Program Files (x86)\WhiteSmoke_US\prxtbWhit.dll
    • O2 - BHO: PricePeep - {FD6D90C0-E6EE-4BC6-B9F7-9ED319698007} - C:\Program Files (x86)\PricePeep\pricepeep.dll
    • O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo\YontooIEClient.dll
    • O3 - Toolbar: WhiteSmoke US Toolbar - {cce665dd-f6dd-4808-968e-eaec971f70ef} - C:\Program Files (x86)\WhiteSmoke_US\prxtbWhit.dll
    • O4 - HKCU\..\Run: [Shop To Win] C:\Program Files (x86)\Shop To Win\ShopToWin.exe

    After clicking Fix exit HJT.


    Delete these folders.

    • C:\ProgramData\5a36e5ad1ebdd68d30a0e296dc479232_c
    • C:\Program Files (x86)\Conduit

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Sorry it took so long to get back here. I have talked to my step daughter who says she doesn't know where those programs came from rolleyes So I started doing what you requested.

    I am a little stumped at this:

    Could you elaborate on this as the Revo uninstaller looks pretty basic. (maybe I havent gotten that far into the program and will make sense soon enough)
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My apologies, the instructions could be outdated now. The program is very straight forward to run, just go ahead and uninstall using it. :)
     
  5. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Just an FYI for future reference....

    I uninstalled "Shop to win" but it states "Some elements could not be removed. These can be removed manually" I used the most advance form of removal. Then it led me through a search for the remaining files. This is where the "bolded" registry files are at. I only deleted the bold ones...

    Ill take screen shots on the next one and save them. Let me know if you want to look at them...

    (Just my way of trying to repay the favor)
     
  6. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Seems like everything is running fine. Only problem I have seen is the fact that all the doc's, pics, music, etc. are still missing from their repective places. Not sure if there's anything that can be done about that but would be nice to have all that back in place when I giver her this pc back. I dont know how it normally runs so I cant say if its better or not. I guess time will tell.

    Attached is the MGLogs you requested...

    On a side note, I noticed her computer is a day behind (24 hrs exactly) Noty a big deal to fix.. Didnt know if it might throw a red flag up or not so I just thought I would throw it out there...
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good morning!

    Qwiklinx <--- I missed this one! Uninstall this crap too using Revo.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Please download and save the below to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Did that help?
     
  8. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Done this.


    And I did recieve a success message on the merge..



    This did not restore anything to my knowledge....

    Any other ideas on restoring the missing files?

    I have a data recovery program but it takes soo long and half the time freezes before it finishes. Not to mention it just puts everything into 1 file and doesn't put it back where it belongs... Don't wanna do this unless its a last resort...
     

    Attached Files:

    Last edited: Sep 5, 2012
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Could you elaborate on this please? Do you mean they are missing from the start menu?
     
  10. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    I mean the folders are there but the files are MIA :confused

    For example, if I go into the music folder, the only thing there is the "sample music" and a couple "shadowed" .ini files. Same with pictures too.
    She said it done some sort of update then crashed and when she rebooted , the desktop background was completely different and all the files were missing.

    I would have to talk to my step daughter for any additional details.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think you would be better off asking about this in the software forum. Is there anything else I can help you with here in Malware removal? All running well?
     
  12. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    everything seems to be running ok.

    Should I delete the quarantined items?
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    The link provided here only takes me to a green backsplash page. I even tried going through the "read and run me first" and same thing going that way as well...

    Ill see what I can do to figure this step out until this is fixed. If I cant figure it out I'll let you know
     
  15. C1B3R5NYP3R

    C1B3R5NYP3R Private First Class

    Was unable to edit last post. Seems this is a problem with the "cleaned" pc. No troubles accessing from my netbook...
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    One of those READ ME's I need to edit. Glad you're all sorted. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds