CashTitan

Discussion in 'Malware Help (A Specialist Will Reply)' started by TrevorHu, Sep 4, 2010.

  1. TrevorHu

    TrevorHu Private E-2

    I'm sorry to trouble you with this, but from what I have read here, I think you may be able to help.
    A few days ago I started getting audio ads when my PC was running, but no applications were running at the time. I opened task manager and discovered iexplore running in Processes, even though I do not use IE (Firefox user). I downloaded and ran Malwarebyte and it found some unsavoury files which I deleted. I then took a look at installed programs and discovered this "Tagging System Cashtitan" and as others before me found, I was unable to remove it.

    I hope I have followed your instructions correctly and am attaching the requisite logs.
    Any help you can provide would be greatly appreciated.
    I should add that no additional malware has been found since I originally ran Malwarebyte.
     

    Attached Files:

  2. TrevorHu

    TrevorHu Private E-2

    Please find attached the Rootrepeal log.

    Thanks again.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I am seeing in your logs is this:
    c:\windows\system32\spbjcutehtb.exe
    If you don't know what this is for, delete it.

    What issues are you still having?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    @TimW - somethings you need to take care of:

    The below is installed:
    Tagging System Cashtitan


    And the below registry key is for it and notice the DLL file to also remove.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    In fact, here is the fix for TrevorHu to use.


    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  6. TrevorHu

    TrevorHu Private E-2

    Thank you both for your time and help. I'll get to it later today.
    :)

    Kind regards,
     
  7. TrevorHu

    TrevorHu Private E-2

    As requested I have attached the log files.
    The cashtitan program has disappeared now!
    One thing that does puzzle me is how it got there in the first place. I run Norton Internet Security 2010 and ALWAYS have it update definitions automatically.
    Everything seems OK at the moment and I would like to thank you again for going to all this trouble for a complete stranger. It really is much appreciated. :)
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good catch, Chas.

    Your logs are clean. How you got infected is any ones guess.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If more people who pay for software like this would complain to the companies about their inability to block, detect, or remove everyday malware seen like this in forums all over the world........ well maybe some of them would start to do a better job and reduce our work load. ;) However you do also have to take some of the blame as it likely arrived due to something you were doing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds