Help removing Malantern please?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sixstring, Jun 16, 2011.

  1. Sixstring

    Sixstring Private E-2

    Hi. I'm trying to find help to remove Win32.Trojan.Malantern. This trojan hijacked a toolbar search function. I somehow removed the toolbar-search, but I'm pretty sure I still have the trojan. I'm contemplating a hard drive format, but am afraid of disaster. Any ideas would be greatly appreciated. Thanks for your time! Sixstring
     
  2. Sixstring

    Sixstring Private E-2

    SORRY! Just found the "what to do first list". I apologize for any inconvenience.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    That's okay. Attach the requested logs when you are ready. :)
     
  4. Sixstring

    Sixstring Private E-2

    Hi. I hope everything is done correctly. I gave it 100%, but still not sure if everything is right. I am grateful for any help you might offer.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't forget not to attach individual logs out of the MGLogs.zip. All's you need attach is the actual C:\MGlogs.zip file please.
     
  6. Sixstring

    Sixstring Private E-2

    Sorry, I think I have it now. Thank you Kestril 13! !
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • DealPly <--- Uninstall this if you do not use it.
    • NetAssistant <--- Uninstall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. Sixstring

    Sixstring Private E-2

    Thank You. Net Assistant and DealPly are UNINSTALLED. MGlogs.zip is attached.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll

    After clicking Fix exit HJT.

    Delete this folder: C:\Program Files (x86)\Freeze.com

    How are things running for you now?
     
  10. Sixstring

    Sixstring Private E-2

    Hi Kestrel13! NOTE ATTACHED *HIJACK THIS* LOG.
    Only 2 of 3 objects showed up during the MGtools.analyse scan. The one which did NOT show up was:
    O2 - BHO: NetAssistantBHO - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll

    PS: HAPPY BIRTHDAY!
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks! :)

    How are things running for you now then?
     
  12. Sixstring

    Sixstring Private E-2

    Kestrel13! : I'm sorry if I misunderstood, but should I continue the process with MGtools.analyse, since only 2 of the 3 objects you listed (for deletion) appeared in the HijackThis results log? (Please note attached HijackThis log attached in previous message). Thank you.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, just do the Hijackthis fix, followed by:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  14. Sixstring

    Sixstring Private E-2

    OK Kestrel13!, The HijackThis.zip log is ATTACHED.
    Can you tell me if this process has removed my Win32Trojan.Malantern? It is a very bad Trojan.

    Anything else to do?
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What Identified this anyway? I am not seeing any signs of malware but if you have software id'ing something as a trojan then I need to know a file and a file path.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Tell me what problems remain please.
     
  16. Sixstring

    Sixstring Private E-2

    Kestril13! : Thank you for your patience!

    I could not run the fix.ME.reg file. It would not save as " *fix.ME.reg* ", but it did save as " fix.ME.reg ", without the asterisks. It was saved to "All Files". I double clicked AND right click "Merge" and got the following error message:

    Cannot import C:\Users\Bill Lap Top\Desktop\fix.ME.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor. -->

    ALSO: When I ran SUPERAntiSpyware it found Trojan.Agent/Gen-FakeAlert(Local). I Quarantined and Removed it. -->

    ALSO: I re-installed AVG Free and turned Windows Firewall back on, is that OK?
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What about Malantern......? Anything detecting that now, that's the main thing I want to know about at this stage.
     
  18. Sixstring

    Sixstring Private E-2

    No Malantern detected. AVG and Windows Defender NEVER found it. I only knew I had it because it gave me a new "search" bar. When I googled the search bar name it said it was a Malantern Trojan. I somehow removed the search bar early on but thought the Trojan was still active. Thanks.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome. :) Safe surfing!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required (If we renamed it please rename it back to Combofix.exe.
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  20. Sixstring

    Sixstring Private E-2

    THANKS KESTREL13! All your help is appreciated!
     
    Last edited by a moderator: Jun 21, 2011
  21. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem! ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds