Major Trojan infection!!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by avscannow, May 29, 2009.

  1. avscannow

    avscannow Private E-2

    Hey guys!
    Thanks Chaslang for helping me a year ago. Your steps cleaned my computer and kept it that way....until.
    This time I have another problem again. My sister came to visit me and was on facebook and got a bunch of pop-ups that I could here from the other room. I came running in to see and sure enough, it was a trojan infection. By the time I got to look at it was too late.
    I've been trying to work on ridding it using the steps you've listed initially but for whatever reason... I can't get Malwarebytes or Spybot S&D to install properly or even run. They just hang up! However, I've noticed a few things that occured. iexplore.exe pops up eventhough there is no web browser open. I'll kill it in task manager and a few mins. later, its back. Also, during installation (and unistallation) of the two programs, I've noticed a few things opening as well on taskmanager. regasm.exe being one of them, which I looked up to be an irc.aladinc.n trojan, during the installation of one of those programs. When I had finally thought that I had installed them (they took longer than normal to install), I clicked on the programs to start but nothing happened. I saw it show up on task manager but a minute or two later it just disappeared. Combofix did the exact same thing!
    So, with all that said, I have not been able to run any of the programs listed, however I was able to get AVG to install and run. But before that I also did a scan on the Symantec website and it popped up with 8 infections. I'm running the AVG now and will try to work on the other two, as well as the combofix and mgtools logs.
    But if I can't get them to run what can I do or provide you with to get your expert advice once again ol' wise one?

    Thanks
    Brit
     
  2. avscannow

    avscannow Private E-2

    Alright guys,
    I finally got the rest of the programs to install and run thanks to AVG! It was able to do a scan and got rid of some malware that allowed me to systematically install and run the other programs needed. So here are my logs.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I see you are running both ZoneAlarm Security Suite as well as AVG. You should either disable ZoneAlarms virus scanning or remove AVG.

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:


    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    -
    Now run Ccleaner to clean out only temp files and nothing else!

    Now run the ( but this time make the agreement to HJT) C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  4. avscannow

    avscannow Private E-2

    Thanks for helping me!
    That's the first thing I did, which was disable virus scanning on Zone Alarm. I was planning on removing AVG after I was done but this program has been working great, along with the others, but I know I should only keep two malware remover programs. However, I did run four of them one after the other just to see what the other missed. But I did run the two just like the READ ME FIRST thread says and I'll uninstall the other two when this is done.
    Back to the steps, the Avenger link you provided did not work, but I went to the site it directed me to and downloaded it from there, I just hope its the right version. It was the Avenger program from Swandog469. You can check the link.
    Also, I did run the other two malware remover programs AFTER I sent the logs, so when I ran the Avenger program, I noticed that some of the entries in the log says it wasn't there. It's probably due to the other malware remover programs ran. I re-ran AVG (the first time, it kept restarting my computer at a certain folder in the Programs folder in the C:\ drive) and then I ran Spybot S&D. Spybot caught more when I ran it. I don't know if I should have done that but I got nervous because it found more malware. I wanted it off so i could use my computer.
    Needless to say, my computer seems to be running great again. But I'm still very nervous and will continue to be until you give me the all clear sign.
    So here are my logs.
    Thanks again for your help!
    Brit
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is not at all what we say in the Read and Run First instructions! We specifically tell you to only have ONE AV program. Either disable ZoneAlarms virus scanner or remove AVG.

    Your logs are clean.....If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  6. avscannow

    avscannow Private E-2

    Thanks for your help Tim. I uninstalled AVG and the rest of the tools used but kept SUPERanti Spyware and Malwarebytes. I followed the rest of the instructions and will keep it clean!!!
    This site is the greatest! Thanks again!!!

    Brit
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome....safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds