uTorrent trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by rblayton, May 12, 2008.

  1. rblayton

    rblayton Private E-2

    I ran my CA anti spyware it found uTorrent trojan that it can't remove. Tried the read & run me first posting,SuperAnti Spyware & Spybot both froze the computer before it finished, Malewarebytes & combofix ran good, but when I downloaded MGTools & ckicked on the icon nothing came up it looked simular to a data file. I am posting Combofix log.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    You need to attach the log from Malwarebytes.

    I suggest you try unchecking the options mentioned for SUPERAntiSpyware where it mentions what to do if you have a Blue Screen/crash. If that does not work, try running it in safe boot mode.

    Skip Spybot; however you need to get MGtools to run. Make sure you DOWNLOAD (not open or run) and save the MGtools.exe file to your root folder as requested. Then you need to double click the MGtools.exe file to run it. Based on your ComboFix log you did not name MGtools properly. You have this which cannot run!!!!!

    C:\MGtools.1.2D0D17.efw

    It should be:

    C:\MGtools.exe

    If you just simply rename the improperly named file to MGtools.exe, it will run.
     
  3. rblayton

    rblayton Private E-2

    I posted Malwarebyte & MGToolslogs
     

    Attached Files:

    Last edited by a moderator: May 12, 2008
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you try the things suggested for SUPERAntiSpyware?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not disable Spybot's Teatimer as requested in the READ ME. It could be getting in the way of running other tools like SUPERAntispyware. Disable Spybot's Teatimer now (see the READ ME) then uninstall Spyware Guard which is too old to be of use anymore (you also already have Pest Patrol from CA installed and don't need Teatime or Spyware Guard ), then uninstall Viewpoint Media Player as requested in step 1 of the READ ME.

    Then reboot your PC. Now see if SUPERAntispyware will run. If it does, attach a log.

    Also tell me if CA is still detecting problems. If so, attach a log that shows exactly what it is detecting and where.
     
  6. rblayton

    rblayton Private E-2

    I did try to run in safe mode it froze there too. I did disable teatimer but reenabled it . I have now disabled it. Will try SuperAnti Spyware again.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure you do the other items a gave first too.

    Note: You should not use Teatimer if you are going to keep CA's Pest Patrol installed.
     
  8. rblayton

    rblayton Private E-2

    I did everything and ran in safe mode and it froze up.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we will skip SUPERAntispyware.

    You never answer the below from message number 5.
     
  10. rblayton

    rblayton Private E-2

    This is the log. It is still detecting it.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you referring to the below folder?

    C:\Documents and Settings\Joe\application data\utorrent

    It is more than like due you or someone else having used the below application which is not a problem it is just a potential problem as are all P2P or torrent programs:

    µTorrent

    I'm not sure why CA cannot just delete the folder but you can do it manually. However it is not even a problem.
     
  12. rblayton

    rblayton Private E-2

    I don't know it keeps coming up and it won't delete and there is problems with my dvd burning soft won't work proberly also spybot and suoerantispyware won't run anymore. They use to all work until this showed up. Also Real player keeps coming up saying I need to download for this file to play but the file does not exist on the computer.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But did you try to delete the folder yourself?

    Sorry this is not a malware issue.

    I suggest that you uninstall them, reboot (do not skip), redownload current versions and reinstall and see what happens. If you still have problems, describe EXACTLY what happens when you try to run them.

    I donn't understand this sentence. Download what to play what? If they are saying you need to download a file, it would not be on your PC! That is why they are saying you need to download it. This also does not sound like malware; however I want you to run the below just incase.


    Download and run FindAWF by noahdfear.
    • Please download FindAWF by noahdfear.
    • Save to your desktop.
    • Double-click the FindAWF icon.
      • If a Security Alert shows, allow the program to run.
    • As instructed, press any key to continue.
    • Use the following option: Press 1 then Enter to scan for bak folders
    • The scan may take a while, please be patient.
    • When done, a text file, Find AWF report is produced.
    • Please attach the Find AWF report in your next post.
     
  14. rblayton

    rblayton Private E-2

    The Real player comes up and says file C:/whatever needs to download something for real player to be able to play this file, but C:/whatever does not exist.
     

    Attached Files:

    • awf.txt
      File size:
      284 bytes
      Views:
      2
    Last edited by a moderator: May 13, 2008
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to be specific! What is whatever and what is something?

    The FindAWF log is clean, thus it is looking more and more like any remaining issues are not malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds