I think I have a trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Nessie Mareschall, Dec 30, 2008.

  1. Nessie Mareschall

    Nessie Mareschall Private E-2

    Okay so this Laptop Is really old, and I've had problems with it before.

    I've used hijackthis before to get rid of my problems but someone walked me threw it since i have NO idea what I'm doing or what I'm looking for.

    Just a few minutes ago a friend of mine ran an ad-Aware scan on my Laptop
    and it detected Malware - Win32 (i think those were the numbers) on here. He said he hit remove and that should take care of it. But he's done that before and it hasn't work.

    So I ran a hijackthis scan. Annnd I don't know what I'm looking for again xD

    Nothing else on my pc (spybot or avira has detected anything but they never have so If i could get a little help it would be great.

    I'll attach the log file hijackthis gave me.
     

    Attached Files:

  2. Nessie Mareschall

    Nessie Mareschall Private E-2

    I also forgot to add the other scans I did
    SuperAntiSpyware
    Malwarebytes Anti-Malware
    ComboFix

    I'm also having trouble doing the MGtools scan
    It downloaded to my desktop
    and it says not to have it do that and i can't find where to have it downloaded to
    Fire fox automatically downloads things to my desktop @__@

    And spybot detected KeenFinder?
    When i had it fix the problem a green check was next to it so i guess it fixed it?

    But here are the other 3 scans i did
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open My computer / open the c drive ....now drag MGTools.exe onto that window. It will now be C:\MGTools.exe. Now double click it and wait for it to finish running ( not forgetting to make the agreement for HJT).

    We will review your logs as you come up in the quece.
     
  4. Nessie Mareschall

    Nessie Mareschall Private E-2

    MGTools.exe, seems to be stuck @__@
     
  5. Nessie Mareschall

    Nessie Mareschall Private E-2

    I THINK this is the MG file im supposed to attach.
    If this isnt the log file please let me know
    @__@
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Other than seeing this:
    Code:
    Registry Keys Infected:
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> No action taken.
    HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> No action taken.
    HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> No action taken.
    HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> No action taken.
    HKEY_CLASSES_ROOT\Typelib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> No action taken.
    
    You need to re-run SAS and have it fix what it finds.

    You also need to use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 1"

    Reboot, and download and install:
    Java Runtime 6

    Attach the new SAS log.
     
  7. Nessie Mareschall

    Nessie Mareschall Private E-2

    Hm, SAS doesn't seem to be finding those thingies
    @__@
     

    Attached Files:

  8. Nessie Mareschall

    Nessie Mareschall Private E-2

    Actually I lied
    I just looked at Malwarebytes Anti-Malware's quarantine
    And they are all in there.
    It says I can delete them all or Restore them.
    Should I delete them?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My bad....I did mean MBAM, not SAS. And you can either leave the items in quarantine or delete them, it doesn't matter.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  10. Nessie Mareschall

    Nessie Mareschall Private E-2

    ugh @__@
    my mother must have move ComboFix to a subfolder
    cuz it wasnt on my desktop anymore
    but i found it
    xD
    thou i can't seem to uninstall it like you said
    @__@
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created. Or in whatever subfolder they were put in.
     
  12. Nessie Mareschall

    Nessie Mareschall Private E-2

    Okay i deleted the ones i could find
    I couldnt find
    C:\WINDOWS\nircmd.exe, C:\combofix.txt, C:\ComboFix-quarantined-files.txt logs
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hi, Nessie

    Did you do a system wide search for nircmd.exe, combofix.txt, and ComboFix-quarantined-files.txt logs... and delete them if found?

    dr.m
     
    Last edited: Jan 2, 2009
  14. Nessie Mareschall

    Nessie Mareschall Private E-2

    Yeah. I found the nircmd.exe file but not the other 2
     
  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)
    Hi, Nessie-

    Just delete the one you can find, then continue with TimW's Final Steps instructions.

    Thanks,
    dr.m
     
  16. Nessie Mareschall

    Nessie Mareschall Private E-2

    What is Sun Java?
    I did a search and my pc doesnt seem to have anything of that name on it
    i have windows xp
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

  18. Nessie Mareschall

    Nessie Mareschall Private E-2

    um, im having a small issue
    ever since i deleted ComboFix and MGTools
    none of my files have been saving correctly.
    Pictures save but they can't be opened...
     
  19. Nessie Mareschall

    Nessie Mareschall Private E-2

    they seem to be saving as a media file
    even if i tell it to save as a jpg
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go HERE and scroll down to find the jpeg association fix.
     
  21. Nessie Mareschall

    Nessie Mareschall Private E-2

    it does it with not just jpg files
    png saves weirdly as well
    >__o
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you pursue this in the software section for further help. :(
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds