Several Trojans detected

Discussion in 'Malware Help (A Specialist Will Reply)' started by Neferatun, Apr 5, 2015.

  1. Neferatun

    Neferatun Private E-2

    Hello! I hope you can help me. Several Trojans have been detected using Avast AV and SuperAnti-Spyware programs. They are Trojan.Agent/Gen-Mytob, Win32:Wysotot-D, and Win32:GenMaliciousA-HLJ.

    I can't seem to find much info on these viruses except that they may be false positives. However, my computer has been very slow and sometimes non-responsive. :cry

    All of this seems to have started with a program update of Comodo Firewall a while back. Shortly after the update my computer started slowing down and freezing up. I realized, unbeknownst to me, that somehow during the Comodo program update another program called Advanced System Care was installed. It appeared to be conflicting with the Avast, Comodo, and WinPatrol programs (among others I use based on MG recommendations), so I uninstalled it. My computer was running a little faster and with less freezes, but was still not as before. I did a Restore to a point before the Comodo program was updated and all was well for a few weeks. I did not update anything except the AntiVirus definitions. Then these Trojans started popping up on scans as well as several corrupted system Restore points. Also, every time the AntiVirus scan runs it detects new and different corrupted system Restore points.

    I've read all instructions and performed the scans as directed. The logs are attached.

    I did have three problems while running MGTools:
    1) HijackThis Beta pop-up box saying "For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HijackThis may NOT be able to fix this. If that happens, you need to edit the file yourself. To do this click Start, Run, and type: notepad c:\WINDOWS\System32\drivers\etc\hosts and press Enter. Find the line(s) HijackThis reports and delete them. Save file as 'hosts.' (with quotes) and reboot. For Vista and above: simply exit HijackThis, right click on the HijackThis icon, choose 'Run as administrator.'" I did not follow the instructions, I clicked OK and and it continued to scan.
    2) ProcDll Logger pop-up box saying "ProcDll Logger has encountered a problem and needs to close. We are sorry for the inconvenience. If you were in the middle of something, the information you were working on might be lost." The only option was the Close button, so I clicked it and it continued to scan.
    3) This one is very strange because Comodo was completely disabled during entire scan processes. Comodo firewall pop-up box saying "GetLogs.bat is trying to execute MiscInfo.bat" with options of Allow, Block, etc. Then the pop-up box disappeared before I could read the rest of the dialog. It usually does not just disappear; you have to click on one of the choices it gives.

    I have ran these tools in the past and have never seen the problems above.

    Thank you so much in advance for your time and help.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have logs showing exactly what was detected and exactly where? There isn't really anything showing in your logs other than perhaps a little junkware.
     
  3. Neferatun

    Neferatun Private E-2

    Thank you very much for looking at the logs. :)

    I only have the Avast scan log, which is attached, however; I don't think it shows everything that is in quarantine. The files that are quarantined in Avast are:
    Infection: Win32:GenMaliciousA-HLJ [Trj]
    Files Infected: C:\Program Files\IOBit\Smart Defrag3\SDUpgrate.exe
    C:\Program Files\IOBit\Smart Defrag2\smartdefrag3-free.exe

    Infection: Win32:Adware-gen [ADW]
    Files Infected: C:\System Volume Information\-restore{360080CA-6493-46AA-8443-B5782B61398D}\RP807\A0077474.exe
    C:\System Volume Information\-restore{360080CA-6493-46AA-8443-B5782B61398D}\RP806\A0077410.exe

    I'm not sure if this is significant, but, when I was working with Super Anti Spyware, trying to save the log file, all my desktop icons suddenly aligned to the left without me telling them to.

    Then the files that were quarantined in Super Anti Spyware were gone; as well as the scan logs. I don't know how or why. I don't know how to retrieve the scan logs from this program. However; the files that were in quarantine are:
    Trojan.Agent/Gen-Mytob (Text Twist - 6 files infected)
    Trojan.Agent/Gen-Clicker (Luxor2 - 3 files infected)

    Your time and help are greatly appreciated. Thank you so much. :)
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    All of the above are false detections. The first two were just from your IOBit software and the last items were in System Restore and were really only from SUPERAntiSpyware.

    Those are not files. Those are names of infections which are of no help to me.


    Since nothing has shown in any of your logs, I would have to say that you do not have any malware to worry about.
     
  5. Neferatun

    Neferatun Private E-2

    That's good news. :) I will now update all protection software and run scans as usual. Hopefully that will clean all the junkware and my computer will speed up a bit.
    Thank you again so very much for your time and help. :)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds