bayfraud.ib trojan?

Discussion in 'Malware Help (A Specialist Will Reply)' started by TimW, Nov 22, 2005.

  1. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    anyone know how to get rid of this stuff?!!

    Inline log attached!
     

    Attached Files:

    • Log.txt
      File size:
      4.1 KB
      Views:
      0
    Last edited by a moderator: Dec 4, 2005
  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.

    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis
     
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now I'm really p'sed!!!

    I posted earlier about finding something that karspecsky identified as a bayfraud.ib trojan ..... couldn't download any anti-virus software.... always said it was corrupted. Manually removed all the trojans .... ran everything in the how to post on removing and fixing before you post..... nothing worked and so I said the heck with it and reformatted the disk and re-installed xp and quess what ... nothing downloads with out it being corrupted!!!! AAARRRGGG!!! I haven't a clue as to what to do next ..... any good ideas? Please!!!!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Now I'm really p'sed!!!

    You should be replying in your original thread not a new one. I'm merging you back!
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    There was no need to format and reinstall. Something may have sot installed correctly during installation.

    Did you install an Anti-Virus and Firewall before going on the internet?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Didn't install firewall ..... counting on my router to do that (shich is working on my other two computers) ... have tried downloading avg/ avast/ port blocker/ mozilla/ none of it will install .... corrupt files, please re download .... this was after the new install of xp. The only things that have insatlled where a squared and adaware.
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Post a HijackThis log as an ATTACHMENT.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I finally got avg to download and set up. Updated four times before it got it correctly downloaded .... ran it and no viruses. Just ran it again and it reports error reading boot files and can't open any of the hdd. Ran a squared and it found 6 malware files ... deleted and avg is running properly. What is going on? Why won't anything download and install properly?
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    I will have a better idea what is going on with your system after I get to look at your HijackThis log.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Here is the HJT file:
     

    Attached Files:

  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    This log appears to be from Safe Mode, it needs to be from Normal Mode.

    Scan with HijackThis and fix the following line:
    This is a file that belongs to AntiVir Personal and will cause conflicts with AVG Free.

    Next open Windows Explorer navigate to and delete the following file:
    Reboot to Normal Mode and post a fresh HijackThis log.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The file is from normal mode (interesting thing is this was happening when I was running the puter in windows 2000 pro - now its xp pro!!) Will do as suggested and restart in safe and re-post HJT.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Had the first file fixed by HJT ... couldn't find the second file .... started in safe mode ... here is the file form the last scan with HJT:
     

    Attached Files:

  14. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your are running HijackThis from the wrong location; you had it in the right location when you ran HijackThis the last time.

    Delete this file:
    C:\Documents and Settings\Administrator\Local Settings\Temp\delus.exe

    It appears that you don't have Windows installed completely.

    Please run Panda Online Scan. After the scan attach the log to your next post. Also please follow the below:

    1 - Please EXTRACT all files from Qoologic Tool to its own folder - C:\Program Files\QoologicFinder . Then, DoubleClick Find-Qoologic.bat to run the tool. It should produce a log - Please attach that with your next post!

    2 - Please EXTRACT all the files form RKFiles Tool to its own folder named C:\Program Files\RKTOOL. Then, Please boot to SAFE MODE and DoubleClick rkfiles.bat to run the tool. Let it run and then, when it finishes, look for a log at C:\Log.txt and please attach that log.

    Now come back here and post all three logs as attachments
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Get's weirder and weirder ...... puter was off and dsl cable unplugged .... plugged in dsl cable and puter started up, but not fully (no monitor( ...shut down, pulled power plug, held button for ten seconds and plugged inpower .... started up by itself ..... went to explore and looked for file to delete ...no local under C:\documents\administrator\local..... went to Panda for the scan ....downloaded the tools, at the end of the second download, puter restarted itself ..... got back on and did the scan .... found nothing!! ... downloaded the rkfiles and the Qooloic2 files. created folders for both ... extracted to each folder ... message no files to extract. AVG (which stopped working after deleting the last HJT item from previous post), started working and downloading updates ...running now. Here is the HJT log from a run after all this happened:
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    OK.... Puter just restarted itself after I retied extracting the Qoolic and RK files ... which they did this time.... will attach ..... thinking of pulling a HDD from a different puter and running it in the problem one and see if it also has problems.
    Here are the two logs:
     

    Attached Files:

  17. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your logs indicate this is not a malware issue. It is very likely Windows was not installed correctly.

    Instructions for doing a Clean install of Windows XP.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have had no problems installing on other puters ..... will do it again and see what happens .....
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Aborted the install because of constant messages that files couldn't be copied...
    will try switching cdroms.....have not had this much problem with any of the other 'puters!
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    A final update ..... and thanks for all who tried to help .... after xp would not properly install (files not copied correctly .... page fault errors and blue screen of death during installation), I checked the bios for system problems and noticed that it was reporting the ram as 262.244 mb (this with two sticks of 128 ram installed!!) Replaced the ram and everything is working just fine!!
    A lesson to be learned.....
     
  21. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Glad you got it sorted out.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds