Found Trojan.BHO not sure if I got rid of it

Discussion in 'Malware Help (A Specialist Will Reply)' started by trisha, Mar 5, 2009.

  1. trisha

    trisha Corporal

    I d/l some games from Iwin.com. I didn't know their site is a malware site until I ran Malwarebytes today. It found Trojan.BHO and it said it was in Iwin folder.

    I did the Read and Run Me First stuff. Can you please check my logs to see if they are clean?

    Also, over the past week or so I have noticed that my files have lost their icons. I don't know how to explain this except to say that files used to be associated with FireFox no longer show the FireFox logo, it is just an icon with no logo. Other files are like that too. So I guess what I am saying is the files no longer show an association to a program.

    Thanks
     

    Attached Files:

  2. trisha

    trisha Corporal

    Here is the combofix.txt log.
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience during this time.

    kestrel13!
     
  4. trisha

    trisha Corporal

    Thanks for the response....Waiting patiently:wave
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there trisha

    Not much to do here:

    1) Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right

    click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following

    lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:



    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O15 - Trusted Zone: http://*.facesofthemissing.org
    O15 - Trusted Zone: http://gm.iwin.com
    O15 - Trusted Zone: *.mycrimespace <--- because we don't recommend you add ANY site to your TZ

    After clicking Fix exit HJT

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    3) Use windows explorer to find and delete the below:


    C:\32788R22FWJFW <--- CF leftovers
    c:\program files\temp01


    4) Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files

    from the current day).

    C:\WINDOWS\Temp
    C:\Documents and Settings\Trisha\Local Settings\TEMP

    5) Now Run Ccleaner!

    6) Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.


    Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
    Last edited by a moderator: Mar 10, 2009
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member


    right click the icons / properties / find target ....if it doesnt, you will need to make a new icon.
     
  7. trisha

    trisha Corporal

    The fixMe.reg was successful. I did have some difficulty with the process because I copied the text from the e-mail and it put extra spaces in the text. I then came to the thread and copied the quoted text, the spaces disappeared and the fix worked.

    You told me to delete files and the following file/folder was not there:

    c:\program files\*temp01*

    Attached is the file you requested.
     
  8. trisha

    trisha Corporal

    Sorry, hear is the requested file. The one labeled *example* shows what I am talking about the change in the icons.
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Good evening Trisha

    This was my fault, and I do apologise. I was having trouble with my browser yesterday--managed to edit the post with internet explorer---but of course, you had email notification of my reply..

    I'll take a look at your logs this evening and get back to you as soon as I can :)
    Kes
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Regarding your screenshot... what's the problem? I see hidden files and folders showing because the running of MGTools automatically does this.

    You said:

    So perhaps doing what was suggested earlier will help. You may wish to work thru this problem in the software section as it is not really topic for the malware forum.
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  12. trisha

    trisha Corporal

    Thanks for all of your help. I toggled System Restore and it appears things are running more smoothly now.

    I will do as you suggested and look in the software section for the other issue.
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You're welcome, trisha-- best of luck :wave
    Kes
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds