possible backdoor trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by SScytrome, Mar 8, 2011.

  1. SScytrome

    SScytrome Private E-2

    AVG detected "win32.FAKAV.zys". Malware fighter detected "trojan.dropper".

    They were both quarantined and deleted. But my computer has still been acting strange. I notice more processes running than usual, the screen randomly flickers, my anti-virus was disabled one day, and when I was downloading updates the other day my computer just randomly shut off without even finishing or giving me any warning.

    Hopefully someone can help.


    (Running 64-bit windows, didn't download or run RootRepeal.)
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why did you not allow MBAM to delete PUP.Dealio?

    I am not seeing any other malware in your system, but you need to tell me what issues you are still having, if any.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  3. SScytrome

    SScytrome Private E-2

    I'll scan again and remove it.


    Ran hijackthis and fixed what you told me to.

    fixme.reg "successfully merged with the registry"



    I didn't download windows updates for a long time, I just hope there's not something undetectable on my computer. Just wanna make sure.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I might suggest uninstalling Iobits Malware Fighter for a little while and see if there is any improvement at all. But before you do:
    You know what the exact file and file path was?
     
  5. SScytrome

    SScytrome Private E-2

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You didn't answer TimW's question:
    Let's run an online scan:
    Using ESET's Online Scanner

    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip and the ESETscan.txt logs to your next reply.
     
  7. SScytrome

    SScytrome Private E-2

    I was on a online shopping site last week, the screen went blank for a few seconds and came back. Sometimes when I restart my computer the modem doesn't detect a link.


    I also just think it's suspicious every time I run some sort of scan 3 or 4 process's run and randomly stop. (Like something is using a tool or program to make itself seem undetectable.)
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What processes? You need to run CCleaner and clean out your temp folders. Other than that, I am not seeing any malware on your system.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds