Cash Titan Redux - File 1

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Bluesbreaker, Nov 22, 2010.

  1. Bluesbreaker

    Bluesbreaker Corporal

    Hi - well I did all that you said I should in the Read Me First sticky - including running Malware, SuperAntiSpyware (and acknowledging the point about them not being that effective unless purchased).

    I also ran MG Tools and am attaching the relevant files per instructions. I'm not a very proficient computer geek but I am trying! One thing though - as I was doing these scans, periodically I would get ads (the audio only) play through the speakers....In addition, when I logged in today, I noticed the first cashtitan ad, in french. (?!)

    Its like an exorcism. Ok let me see if I can make this work and I thank you for all of your help. I've uploaded the MG Tools files and the OTM logs. I will provide the Malwarebytes and SuperAntispyware logs in the next thread.

    Thanks again!

    Blues
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Sorry bu no you did not. We need the logs from the below:
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • RootRepeal
    On the contrary, the free versions are very effective. They just do not find and fix CashTitan because ever case of it is different which is why you should not be trying to run instructions given to someone else. They have nothing to do with your infection.
     
  3. Bluesbreaker

    Bluesbreaker Corporal

    Hi - thank you for getting back to me.

    You are correct in that I only posted a couple of files but I noted that I will provide the Malwarebytes and SuperAntiSpyware in the next thread (not this one as the files are still running). As for effective, I was just going by this point:
    " Unless you purchase them, they provide no protection. " which I may have misinterpreted.

    As for specific instructions, I had googled Cash Titan as a problem file to remove and came upon this site. As I noted in my first thread, I'm not a very technical computer person so I got a little nervous about root repeal. So I'll be attaching the logs from Malware, SAS, Rootrepeal and finally Combofix shortly.

    Thanks again for all your help! So if I attach the aforementioned additional files, we'll be ok?

    Why is this Cash Titan so prevalent and annoying anyways?

    S
     
  4. Bluesbreaker

    Bluesbreaker Corporal

    RON Ads by Cash Titan! That just popped up right now. And there was a girl talking about going back to school, fyi...
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    Yes but you did not run ComboFix and RootRepeal and ComboFix would be used to perform your fix once I have all of your logs.

    Protection is what you get when you purchase them, but the free tools still perform scanning and removal of any detected malware.

    Great. ;) If the future, I advise you not to use fixes posted for anyone but you. All fixes are created for the PC in question and are not always applicable to another persons PC and in some cases you could potentially cause problems by running fixes not designed for you.


    Sorry but you will not like the answer. People like yourself, download and install things that they should not.

    Once you get me the other logs, I can give you a fix with ComboFix.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You already have the logs from SUPERAntiSpyware and Malwarebytes. They are located are here:
    Code:
    "C:\Documents and Settings\William Dinkha\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    Nov 10 2010 35612 "SUPERAntiSpyware Scan Log - 11-10-2010 - 23-50-37.log"
    "C:\Documents and Settings\William Dinkha\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    Nov 10 2010  2308 "mbam-log-2010-11-10 (06-20-13).txt"
     
  7. Bluesbreaker

    Bluesbreaker Corporal

    OK! So here goes. I ran the whole gamut between last night and today and here are the files.

    Root repeal
    Combofix
    SAS
    Malware

    and the other ones from last night are the MG Tools.

    Hopefully this takes care of it!

    Thanks again for all your help!

    btw- how did you know where the filepaths were for SAS and Malware? Its like you have a pathway into my computer...
     

    Attached Files:

    Last edited: Nov 23, 2010
  8. Bluesbreaker

    Bluesbreaker Corporal

    By the way - that trojan or spyware that I was after is called "Advance Performance Platform Cashtitan" and it is still in my list of Add/Remove Programs (today, November 23rd, after running those programs).

    Just an fyi.

    Ok - I'll wait for your response.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    From the logs that are part of MGtools. They help us find problems and allow us to taylor make specific fixes for each user.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old Sun Java version:
    Java(TM) 6 Update 6


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    After reboot, delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\William Dinkha\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Bluesbreaker

    Bluesbreaker Corporal

    one thing - I've followed the instructions to the point where you say run CCleaner.

    What is this?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is a program you were supposed to have already installed and run in step 3 of the READ & RUN ME. So how many instructions did you skip?
     
  12. Bluesbreaker

    Bluesbreaker Corporal

    :-o

    Chaslang - thanks so much for everything. I'm attaching the Combofix.txt and MGLogs.zip files. I also 'cheated' and looked into Add/Remove programs and didn't see the CashTitan.

    I think we may be done?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. Bluesbreaker

    Bluesbreaker Corporal

    Chaslang - thanks again for all your help. Seems that everything has checked out.

    I know that you have a section on how to prevent malware and I will review it. Prior to this, anytime I was downloading something or surfing, I'd always have Avast on and scan the files with Avast. Somehow, I still got this malware into my system.

    I'm pretty good in that I didn't have any fatal situations like some of the threads I've noticed here. That said, they were still getting in.

    Second, I'm really just interested in why you do these things, like a personal mission to destroy malware or whatever (which I'm not making a joke of, I'm serious) and I guess it can be like unlocking puzzles and cracking codes, which is a profession in itself. What was your trajectory like - did you do a Phd in Computer Science, did you just fall into computer languages and move into this or where you just effing around on a computer and before you know it, you were doing this?

    I mean, its fantastic stuff.

    Take care and I'll be posting here and there I'm sure. Great community...
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    I do it because I have the ability to do so and many people need help as you can tell. ;)

    I'm a research and development engineer working in the telcommunications industry and have always used computers to help in my work. Being an engineer and having used computers for many things ( including programming in many computer languages ) I have developed quite a lot of knowledge about the Windows Operating System. Fixing problems with Windows ( including malware problems ) just evolved from a couple of fixes here and there into its own full blown malware removal forum. As people learned we could help them, the word kept spreading quickly and the forum grew enormously in popularity throughout the world.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds