I think I have a trojan.

Discussion in 'Malware Help (A Specialist Will Reply)' started by pintsizekath, Sep 22, 2006.

  1. pintsizekath

    pintsizekath Private E-2

    I have followed the instructions and completed the scans in the "Read and run me first" thread.
    I think I may be infected with SmitFraud.

    I have been getting lots of error messages and I thought it was because I was running Windows Millenium.

    I couldnt download a Firewall or Antivirus (everything I downloaded after I reinstalled the OS was corrupt), Internet Explorer kept closing and when I try to open"Help" I get an error message. If I try to open System Information I get an error message also.

    I have disabled 2 items in "Startup":-

    Rundll32.exe powrprof.dll, LoadCurrentPwerScheme

    Mstask

    Things seem to be working better. I am not getting as many error messages and Internet Explorer is staying open.
    I managed to download and install BitDefender 9 ProfessionalPlus last night and it was working fine, (but when I started the PC this morning it keeps disabling).
    I have also been able to download the scans etc.

    I have run the following and added some of the logs.
    CounterSpy (I had to run this last because it wouldnt respond when I tried earlier).
    BitDefender
    PandaActiveScan
    GetRunKey
    ShowNew.

    I have also tried to run SmitRem after reading the "ShowNew" Logfile.
    It wouldnt run properly but I think this is because it isnt compatible with ME.

    The ShowNew Log says this: "Locating all files created in C:\WINDOWS\System\Components within the last 90 days.
    This folder is now being used by Trojan.FakeAlert.CX aka SmitFraud No matches found"

    I have enabled the startup items for the Hijackthis Log, but the only entries I dont understand are the 2 at the top. Should I attach this too?

    I would appreciate any help to get my PC running properly again.

    Thanks Kath.
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Yes please attach all logs that are requested in the guide :)
     
  3. pintsizekath

    pintsizekath Private E-2

    Thanks for the quick reply.
    I will post the other logs now.
    Regards Kath.
     

    Attached Files:

  4. pintsizekath

    pintsizekath Private E-2

    I have just tried to send another Logfile. IE closed with an error message so in case you didnt receive it I will send it again.
    It is the Logfile from SmitRem which I thought didnt run properly but I found this whilst locating the other ones I sent.
    It looks like it may have removed something!
    Fingers crossed.
    Kath.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't see any problems in your logs but note that you did not attach the GetRunKey log (the runkeys.txt file).

    Also SmitRem did not find anything. What it reported is just normal entries.
     
  6. pintsizekath

    pintsizekath Private E-2

    I have attached the RunKey.txt Log to this post.
    Do you think it might be the pc at fault rather than a virus?
    Do you know of any other reason why I cant download an antivirus without it being corrupt?
    Kath.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try downloading and installing this Mozilla FireFox
    Try using it to download programs and see if you have the same problem. But note that you already have an antivirus installed. If you are going to install a different on, you must uninstall Bitdefender before installing the new one.
     
  8. pintsizekath

    pintsizekath Private E-2

    Hi again
    I have downloaded Firefox and it seemed to work fine for a while.

    I uninstalled the BitDefender AV as it wasnt working properly (kept disabling by itself) and downloaded DefenderPro firewall and Antivirus (2 seperate programs).

    When I tried to install them an error message said that they were corrupt and it may be possible to bypass the check using the /NCRC command.

    I did this and they worked fine for a while, then when I started the PC again an error message appeared saying that the files were corrupt.

    Now when I try to start the firewall or the AV I get a message saying that the License key has expired or the file is corrupt.

    I currently have no working firewall or AV but have kept CounterSpy after installing it for the first lot of scans.

    Help! What am I doing wrong?

    Any help would be greatly appreciated.

    Thanks Kath.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Where did you download Defender Pro from?
    Did you buy it or is it a trial?

    Attach new logs from GetRunKey and HJT.

    Also run the below and attach the requested log:

    Using Sophos Anti-Rootkit
     
  10. pintsizekath

    pintsizekath Private E-2

    Hi
    Many thanks for all your help.

    I have attached a newHJT log and a RunKeys log, but unfortunately I couldnt get the Sophos Anti-rootkit scan to work.

    I wasnt sure if it was corrupt so I downloaded it a second time to try again but it didnt make any difference.

    I went to the file it was in and clicked on the Sargui.exe file as I presumed this was the one which would open it all.

    I kept getting this error message "The SAR2.DLL file is linked to missing export kERNEL32.DLL: Verify version info W".

    I havent a clue what this means.

    Is the Sophos scan compatible with ME?

    The AV and firewall were a trial. I didnt even need a key after I downloaded them and the trial hadnt run out.

    I now have another working firewall installed (McAfee) but the virus scan (which is part of it) wont work.

    I am not sure where to go from here.

    Any more suggestions?

    Kath.
     
  11. pintsizekath

    pintsizekath Private E-2

    Whoops! I got so carried away with writing I forgot to add the logfiles.
    Here they are.
    Sorry!
    By the way, why is the logfile for HJT still called hijackthis if I have renamed it to analyse.exe?
    Kath.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What you name HijackThis.exe has nothing to do with what the log file will be named by default.

    You logs still do no show any signs of malware. Whatever problems you are having are more likely related to some problem within your Windows installation.

    Where did you get McAfee from? Is it a paid version?

    My only suggestion would be for you to ask a few questions in the Software Forum and make sure you say you have already checked for malware. I think you may need to stop downloading and installing free trials and should only use the tools we recommend in the How to Protect yourself from malware! sticky thread. And you may want to consider downloading them onto another PC and then having them burned to a CD. Then you can use that CD to install on your PC. This way you know you are not getting corrupted downloads.

    Sorry about the Sophos Anti-rootkit! I forgot you were running Win Me. It is not compatible.
     
  13. pintsizekath

    pintsizekath Private E-2

    Hi
    The Mcafee firewall is a trial.

    I will follow your suggestions and hope it helps.

    If things dont improve and I decide to reinstall the OS will this get rid of any malware if its there?


    As I have only just reinstalled it there isnt anything on the PC that I need to keep.

    Many thanks for all your help.

    Regards Kath.
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you had malware, an fdisk, format, and reinstall would remove it. It would also cure problems related to your OS being corrupted. However, you must be sure that you are not re-installing from corrupted media. Are you CDs original copies from Microsoft?
     
  15. pintsizekath

    pintsizekath Private E-2

    Yes its an original.
    I also have an original windows 98 cd as I upgraded from that.
    I wish I hadnt bothered now.
    Do you think windows 98 is better than ME?
    I know that its very old now but this laptop wont take XP.
    I have tried to use my brothers original XP cd with SP2 on it but when I did the system requirements test it said there were a couple of things it needed though I cant remember what now.
    You mentioned an Fdisk,format. Are these the same thing?
    I have formatted an hard drive once!
    Not sure if I have the confidence to do it again though.
    Kath.
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Personally I never liked Win ME but it does have some nice features (like system restore for one) that were missing from the Win98 platform. Upgrading from Win 98 to Win ME was not a good idea though. I have found it is much better to do a clean full install of Win ME rather than upgrading. If you decide to go back to Win 98 just be sure that it is at least Win 98 SE not just plain old Win 98.

    How about Win 2K? It is more stable and more current than the Win 98 & ME operating systems and also is still supported by Microsoft and many other software products. Can your PC run it? Do you have a copy of Win 2K?

    No! Fdisk is where you will delete all partitions on the hard disk and then recreate them (or create just one). Before you can use a hard disk, it must be divided up into what is commonly referred to as logical partitions (which could be one partition too). You can use Fdisk to divide an 80 Gb hard disk up into two 40 Gb partitions (that is just one example, it is not a requirement). Formatting is something you do to each partition to make it ready for your operating system.

    Read this: http://support.microsoft.com/kb/q255867/

    Formatting is the easy part. You just type the command and wait for it to complete. Reinstalling your OS is more work!

    REMEMBER that doing an fdisk and format will erase ALL of your current information. Thus you must backup anything you will need later when you reinstall before you do this because otherwise it will be gone forever.
     
  17. pintsizekath

    pintsizekath Private E-2

    Hi
    The more I think about it the more I realise that it might be the ME disk that is at fault.

    When I was installing it I got a couple of error messages but closed the error message box and the installation resumed.

    Is there any way to check if the disk is ok?

    Do you think maybe something didnt install properly and if so is there anyway to put this right?

    Regards Kath.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not get error messages during the install! If you do, you should write down the exact word for word error message.

    No there is no easy way to check if the disk is okay!

    None of this is really a topic for this forum though. We really are too busy with malware issues to work on hardware/software issues like this in this forum.

    I would suggest if you want to pursue this topic further that you gather more info on the error messages and start a thread in the Software Forum.
     
  19. pintsizekath

    pintsizekath Private E-2

    Okay, will do.

    Many thanks for your help.

    Regards Kath.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds