Trojan-Phisher-Snifula ... hard to get rid of.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by PetitJedi, Dec 9, 2006.

  1. PetitJedi

    PetitJedi Private E-2

    Okay, so I'm all new to this - not only this forum, but basically having to fix my computer all by myself. I don't know a lot about the language yet, but just enough I'd say.... but speak slowly just in case.

    Basically, after changing the RAM in my laptop (Dell Inspiron 8000, Windows 2000 Professional) I had some IE-problems. So, I got the brilliant idea to sweep my system for eventual spyware, and I stumbled over two trojans.

    The one was a Trojan-downloader, and the other was a Trojan-Phisher-Snifula. I deleted the two of them, thinking it'd be fine.

    However the Snifula keeps reinstalling itself in my system. I have deleted it several times in Webroot Spysweeper, and I downloaded a Trojan-tool to get rid of it as well, but none of it worked (to be honest the Trojan-remover didn't even find it) and I don't know what to do anymore - searching through other helpforums, I noticed a lot of people posted Hijackthis-logs, and I thought I should try to download it - but not being an advanced user, I suppose it wouldn't help.

    What do I do?
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome :)

    The best course of action to start with is the below, its primarally cleanup steps and log posting that will not only clean up some of the easier malwares but generate some logs that our malware specialist can look at and issue you soem further removal instructions if needed, but do not skip any step and if their is one you cannot run tell us why?


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.




    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. PetitJedi

    PetitJedi Private E-2

    Well... things sort of go wrong from the very beginning. I don't know how to get my pc in a 'MSconfig Startup Mode' - I do follow the tutorials, but it's not accepted by my system.
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi :)


    Your running windows 2000 so you dont have msconfig so skip that part and continue on with the rest.
     
  5. PetitJedi

    PetitJedi Private E-2

    ...working in HijackThis...

    So, I worked my way thruogh five of the steps - and is not to continue, gah it's a lot of things to do and download ... but it's all necessary, I can see that.

    Now I however have bit of another problem - how do I run my computer in Safe Mode, since it's a Windows 2000 Professional and doesn't do msconfig?
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    I know alot of steps to go through an all, but they are geared up to cover all aspects of malware, easier to clear all out than deal with seperate parts, also the cleaning routines give your PC a spring clean.

    But onto Safe Mode, you can at boot hold the F8 key down or continually tap it if your PC gives you the beeping sound warning of a stuck keyboard key, which will give you a menu listing of 3 main options , choose "safe mode with networking"
     
  7. PetitJedi

    PetitJedi Private E-2

    Okay, so I admit I've been putting things up a little, I haven't done the 5th step yet.

    The thing is, that I did try to boot to SafeMode, I was about to continue, and then I chickened out on the first Ccleaner-procedure, because I'm not sure I'm doing things right.

    My problem really is that I'm not sure I translate the manual properly - I'm Danish, which means I translate everything, and that my computer is running in Danish. I almost think that 'Safe Mode' is 'Sikker Tilstand' when rebooting, btu I'm not sure and I'm so worried I might cause more damage than I'll help my computer.....
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That is Safe Mode!
     
  9. PetitJedi

    PetitJedi Private E-2

    Heheh, wow somebody who knows Danish n_n

    Actually I did my daily Webroot Spysweep today, and the trojan wasn't there anymore! I think I've finally cleaned my system out properly. Should I still run the Hijackthis-log?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not really! I just knew that because I dealt with it before.

    Before we would accept a HijackThis log. All the steps in the READ & RUN ME must be completed. That includes attaching of the five other logs that Halo requested. HijackThis logs alone do not provide an adequate representation of the malware status on a PC. If you really want to be sure you system is clean then complete the instructions given in message number 2.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds