Malware and Trojans Detected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Anndora, Mar 7, 2008.

  1. Anndora

    Anndora Private E-2

    Hello! This is my first time posting here and was referred here by a friend whom said the help was wonderful. I've been battling detected trojans for the last 2 days and from researching it appears they are malware. I cannot seem to rid my system of this malware. It is my hope that you will be able to help me succeed in curing my pc. I am currently following the advice from the thread called Read & Run me first. Attached is the Rapport.txt file that was the outcome of the first scan ran. I am continuing to step 2 and will post those results as soon as they are complete. Thank you for your time. =)

    p.s. some of the items detected include Dropper.Agent.***, Dropper.Generic.***, and Downloader.Agent.***
     

    Attached Files:

  2. Anndora

    Anndora Private E-2

    Ok, just completed step 2 and the attached is the report that was saved.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  4. Anndora

    Anndora Private E-2

    Ahh, sorry about that. I think I followed the entire page now. I am attaching the files that I got from the scans that I did. Thanks again for the help. =)
     

    Attached Files:

  5. Anndora

    Anndora Private E-2

    I'm adding a 2nd SAS log named SASlog2.txt. My husband informed me that he stopped the first scan after it found 2 trojans and he clicked next removing them. I did a full scan over night and saved the 2nd scan as SASlog2.txt. I hope this didn't mess anything up. I forgot to add it to my previous post. I'm very sorry about that. =/ The log.txt and MGlogs.zip have taken place after the 2nd SAS scan.
     

    Attached Files:

    Last edited: Mar 8, 2008
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Actually you are looking good ..let's do two things:

    Please disable all anti-virus and anti-spyware programs while we do the following:

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    And If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    *How to Protect yourself from malware!
     
  7. Anndora

    Anndora Private E-2

    Thank you very much for your help, time and patience, TimW. I really appreciate it. :) Things seem to be running smoother now. I'm so happy that I don't have to throw my pc out of the window. ;) I hope you have a good evening.

    Anndora
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds