Tricked by the messenger trojan!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by Eduardo0104, Aug 19, 2009.

  1. Eduardo0104

    Eduardo0104 Private E-2

    Hello!
    I as chatting with a buddy of mine about a movie and the "Hey! want to see a video of hot Argentinian women in bikinis" message popped up. I asked my friend what it was and he told me it was a movie (because we we're talking about one in the first place) So I clicked and it took me to a web page that looked like Youtube but wasn't. Since then I've been battling with this problem but can't seem to get it fixed.

    I started by running my antivirus (Avira) and it came up with a trojan (can't remember the name right now) and it supposedly fixed it. But then Windows Defender started telling me that "win32/possiblehostsfilehijack" was detected.

    So I started searching and stumbled upon your amazing website and ran the READ & RUN ME FIRST Before Asking for Support and solved some of the glitches. But I still think somethings wrong. One of the major problems is that my internet connection is running REALLY slower than before on my network.

    Can someone help me?

    My system specs are:
    Compaq Presario F700 Notebook
    AMD Turion 64 X2 TL-58 1.9GHz
    Memory (RAM) 2.0 GB
    System 32-bit OS (Vista Home Premium)
    Internet is DSL via wireless router
     

    Attached Files:

  2. Eduardo0104

    Eduardo0104 Private E-2

    Tricked by the messenger trojan!!! 2

    This is the last log file from MGlogs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Why are you running this PC without an antivirus prorgam?

    According to your logs, pnly some minor things to do remain. Perhaps this remaining issue is due to something else you have installed lately. Like perhaps TubeMaster++ or WinPcap both of which were installed on Aug 10th. Why did you install WinPcap?

    Let's fix the remaining issues that I do see.


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O9 - Extra button: HP Smart Select - {58ECB495-38F0-49cb-A538-10282ABF65E7} - (no file)
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 22, 2009
  4. Eduardo0104

    Eduardo0104 Private E-2

    Hello again :).
    Just to answer a few questions before running this. I was running the Avira Antivir ever since i got the pc. Loved it so far, I thought it had real time internet security as well, doesn't it?
    And as for WinPcap, I downloaded it so I could run the tubemaster++ program that allows you to capture any flash media from your internet browser as long as you have the program running. So I think it's a safer way of downloading tunes than from p2p programs.

    Ok, now on to the recommendations. I'll let you know in a bit how it all goes.
     
  5. Eduardo0104

    Eduardo0104 Private E-2

    Here is the Log file after following the last steps.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It has antivirus and antispyware protection but it does not include a firewall which you need snce the Windows firewall is not adequate.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures in step 3 the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds