Nmap

Discussion in 'Malware Help (A Specialist Will Reply)' started by bananzi, Nov 3, 2014.

  1. bananzi

    bananzi Private E-2

    I have a couple of programs on my computer I never installed, Nmap and Wincap.
    I suspected they might be malware. I checked online and it seemed save to uninstall them. However they keep being reinstalled somehow.
    I tried Revo uninstaller. They came back. Went online for instructions.
    Tried those (and they included registry keys to delete), but again they automatically get reinstalled. I'm very suspicious. Should I be?
    Has anyone else run into this problem? If so, is there a solution?
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Let's dig deeper...

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide

    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual update Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only RogueKiller and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run the rest of the READ & RUN ME FIRST instructions on the infected account.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. bananzi

    bananzi Private E-2

    Thanks. Attached are the logs.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nmap and WinPcap are legit programs to aid in packet capturing. They can be used by legit programs like Wireshark ( you don't have this installed ) or by same gaming programs. Yes they could also be used by malware but this is rare.
     
  5. bananzi

    bananzi Private E-2

    Is there any legitimate reason they would get automatically reinstalled ?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Possibly by the program on your PC that is using them. Since your logs are basically clean, it is not likely to be a malware issue. Why do you ask? Did you try uninstalling them and they did not uninstall?

    See the below which also list some programs that make use of WinPcap

    http://en.wikipedia.org/wiki/Pcap
     
  7. bananzi

    bananzi Private E-2

    Yes I did. They actually seem to have uninstalled, for example the associated folders and registry keys got erased. However on the next startup they all came back. I've become a bit paranoid about malware and this really made me suspicious. However since my logs are clean I feel a lot better, although not entirely free of suspicion.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I'm not sure why that would happen unless something else you use requires then.

    Try this. Uninstall Nmap and then reboot. If it asks you if you want to uninstall WinPcap when you uninstall Nmap, make sure you say yes.

    If you did not uninstall WinPcap during the Nmap uninstall then uninstall Winpcap now.


    Are you sure that you did not install Nmap to begin with. See >> http://filehippo.com/download_nmap
     
  9. bananzi

    bananzi Private E-2

    I'll be out of town for a few days, but I'll try this as soon as I get back.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     
  11. bananzi

    bananzi Private E-2

    I'm back in town. Just for you info, you were right some other program was using Nmap.
    It was iYogi, a PC security utility which is legitimately on my computer.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for letting us know what was using it. But by the way, I don't consider iYogi a security program. iYogi is the provider of on-demand remote tech support services which thus is likely why they wanted to sniff packets on your PC. Not a company or service I would recommend. Too many bad reviews about them being a scammer. But then again perhaps some people have found it helpful.
     
    Last edited: Nov 15, 2014
  13. bananzi

    bananzi Private E-2

    I searched online for iYogi and the results were frightening.
    They used the tactics mentioned in some of the posts on me, and got me for over $200. At the time it seemed like a good investment. Now that I checked them out I feel I got ripped of. That's all water under the bridge by now. What concerns me is that I let one of their techs have remote access to my computer and install some programs. The reviews I've read online make this now seem like a really bad Idea. If I remember correctly the tech had me enable remote access to my computer. How do I reverse that, and should I remove all their installed programs?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall iYogi and then uninstall Nmap and WinPcap and then see if they stay uninstalled.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  16. bananzi

    bananzi Private E-2

    That did it, thank you very much. You know the thing that gets me about
    iYogy is I got connected to them when I clicked on support for McAfee.
    I wish more people knew what I now know about them.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Well use the power of the internet to shout about it. If you use Twitter or Facebook, make use of them. And have your friends repost, and their friends....etc. ;)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  18. bananzi

    bananzi Private E-2

    Ok will do. Thanks again
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You'e welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds