FBI trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by maglib, Oct 25, 2012.

  1. maglib

    maglib Private First Class

    I had the FBI trojan thing asking me for $200... The support forum seems to have gotten rid of it. I'm attaching the logs and hoping you'll say I passed. Thank you again!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    • O2 - BHO: BHO Project - {cbc5b60a-aa4d-45f6-84c2-d086f320299a} - (no file)
    • O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
    • O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] "C:\Windows\is-78VLN.exe" /REG /REGSVRMODE

    After clicking Fix exit HJT.


    Delete this unless you know what it is: C:\ProgramData\dsgsdgdsgdsgw.pad

    Also delete this:
    C:\Program Files (x86)\Common Files\Spigot


    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  3. maglib

    maglib Private First Class

    Warm thanks! I hope you are safe from the storm!

    I did all you suggested. The PC seems to be running fine. The one file that was missing was:
    O4 - HKLM\..\RunOnce: [InnoSetupRegFile.0000000001] "C:\Windows\is-78VLN.exe" /REG /REGSVRMODE

    I did receive a success message on the merge.

    While running getlogs.bat I got windows error message reporting which went away.

    I also did delete the DSGS file but didn't do it till later and wasn't sure if I should rerun anything.

    Thanks. Stay warm and dry!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I would like for you to use MSConfig to put this machine back into normal start up mode.

    Is everything running nicely now?
     
  5. maglib

    maglib Private First Class

    Thanks for your help.
    Sorry I haven't responded but the storm came and no power for 2 weeks and then we were in a bad car accident and I haven't been able to focus enough on my PC problems. I thought it was better but now I keep having issues especially in IE (yes I know IE is terrible). Should I start over and rerun again since it's been so long?

    thank you and sorry once again.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    So sorry to hear you were in a car accident, but glad you're on the mend!?

    Yes please. It would be best, once you have chance.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds