Help! I have a trojan virus and can't get rid of it!

Discussion in 'Malware Help (A Specialist Will Reply)' started by KimberlyCrawshaw, Dec 2, 2009.

  1. KimberlyCrawshaw

    KimberlyCrawshaw Private E-2

    I noticed yesterday morning that I was getting weird pop ups and redirects to other sites. Internet Explorer would also freeze up and I would have to click on things twice to get a response, if it worked at all. I noticed when I would pull up task manager that I would supposedly have two instances of Internet Explorer running. I downloaded AVG and it found the viruses but they seem to be moving and never get deleted properly. I followed the steps as outlined for Malware Removal. Please find attached my log files. If anyone could help me, I would greatly appreciate it as I cannot afford a new computer right now.

    By the way, I have ZoneAlarm Security Suite and it didn't even detect the viruses...so much for security.

    I am running Windows XP, Service Pack 2.
     

    Attached Files:

  2. KimberlyCrawshaw

    KimberlyCrawshaw Private E-2

    Here are the rest of my log files.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's start with this.

    Are you running Zone Alarm Security Suite with the AV protection installed?

    Please use add/remove programs to uninstall:
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME
    J2SE Runtime Environment 5.0 Update 4"
    J2SE Runtime Environment 5.0 Update 6"
    Java 2 Runtime Environment Standard Edition v1.3.1_02"
    Java 2 Runtime Environment, SE v1.4.0_01"
    Java 2 Runtime Environment, SE v1.4.2_05"
    Java 2 Runtime Environment, SE v1.4.2_06"
    Java(TM) 6 Update 3

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\system32\fesekuko
    C:\WINDOWS\Temp\fb_1752.lck
    C:\WINDOWS\Temp\iswift.dat
    C:\WINDOWS\Temp\SDK8
    C:\WINDOWS\Temp\sfdb.dat

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. KimberlyCrawshaw

    KimberlyCrawshaw Private E-2

    This didn't work. I copied and pasted into notepad, and saved it with all files selected. I double clicked it, it pops back up, and then I left clicked it and selected merge. Neither way worked apparently. Let me know what to do next when you get the chance. Thanks!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    vBulletin has its flaws....so make sure that when you paste it into notepad that you do not have any space above the REGEDIT4 line.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds