Malewarebytes Quarantined Itself (keylogger trojan?) Please Help

Discussion in 'Malware Help (A Specialist Will Reply)' started by Christo123, Sep 27, 2012.

  1. Christo123

    Christo123 Private E-2

    Ok, so for some reason malwarebytes has quarantined itself. I was using the computer a couple days ago when I got 3 "alerts" that malewarebytes wanted to quarantine something. So I blindly (dumbly?) allowed it to. (In retrospect, I do not have the Pro edition of malwarebytes so there shouldn't have been any active scanning going on).

    So the computer starts running crappy (slow & choppy) and I can't open Malwarebytes. So I redownload it in another location and open it and there are 3 things in my quarantine:

    Trojan.Keylogger is the "Vendor" and it lists the "Item" as C:\Windows\winsxs\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.7600.16385_en-us_106f9be843a9b4e3\comctl32.dll.nui

    The next item quarantined has a "Vendor" called Trojan.Goldun and the "Item" is my malwarebytes (E:\zStuff\Malewarebytes'Anti-Maleware\mbam.exe)

    The third thing is "Vendor" Trojan.Banker and the "Item" C:\Windows\System32\NLSData0000.dll

    So I've updated malwarebytes and run a full scan but it comes up clean.

    I have Yahoo toolbar and on it Yahoo Mail button. Normally when I press the button, it gives me "Mail Preview". Now when I press it, it tells me "To help protect the security of information you enter into this website, the publisher of this content does not allow it to be displayed in a frame"

    It only started doing that after the 3 quarantined items appeared, so I assume they are somehow linked.

    So that brings me here. I've followed all the directions under the "READ & RUN ME FIRST" thread.

    I ran RogueKiller scan as directed and will attach the report.

    I ran a Malewarebytes Quick Scan as directed, nothing was found, I will attach the log.

    I ran TDSSkiller, "No threats found" and I don't appear to see a log I can attach.

    I ran HitmanPro, "No threats found" I will attach the log.

    I am running MGtools right now, but it is close to midnight and I need to sleep. In case something happens overnight, I don't want to lose everything I've just typed, so I'm posting this now and I will post the MGtools log in the morning.

    Thank you in advance for all your help.
     

    Attached Files:

  2. Christo123

    Christo123 Private E-2

    MGTools still appeared to be running when I woke up, so I rebooted my computer and ran it again while I was at work. I will now post the log for that.

    Thank you

    Maybe not, I can't get the zip file to upload. I see lots of ewrrors in the MGtools scan, the last one saying "Could not create output file C:/MGlogs.zip"

    But then it says your log file is C:\MGlogs.zip (note the backwards \ )

    I'm not sure what to do next. Please & thank you for your help
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Possibly because of where you put it and how you named it. There is no 'e' after the 'l' in malware. Thus it should be Malwarebytes Anti-Malware. Also the E:\zStuff folder could be trigger something.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is the correct direction of a \ in Windows. The other direction was standard for UNIX. However for many programs these days, it does not matter.

    Did you disable UAC and reboot your computer after disabling it? MGtools will not run properly if you had not. Also you antivirus or other protection programs could cause a problem. Try disabling them and then run MGtools.
     
  5. Christo123

    Christo123 Private E-2

    The extra E was probably a typo by me as I could not copy/paste it but rather I had to type it all out by hand.

    I will try to run MGtools again
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay. If you still have trouble, do the below.



    Please click Start, All Program, Accessories and you will see ( among other things ) a Command Prompt entry.
    • Right click the Command Prompt entry and select Run As Administrator.
      • It is critical that you run it this way.
    • If you do this properly, a command prompt window will open with a title of Administrator Command Prompt.
    • Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple/brown is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    SN64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    nwktst <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    GRK64 <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    getnetinf<-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Now look for the C:\MGlogs.zip file and attach it no matter what happened while doing the above.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds