Tried Read and Run Me First- Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by a12curlyq, Sep 30, 2008.

  1. a12curlyq

    a12curlyq Private E-2

    I am not very good with computers, so I tried my best to follow all of the directions in the "Read & Run Me First" as closely as I could. I can not tell you what I (or possibly somebody else) was doing at the time that I got this trojan. I began having advertisements popping up when I wasn't on the internet, and I decided to run Symantic Endpoint Protection. The endpoint protection found "trojan.flush.g" which I tried to delete using the symantic and by following the instructions on their website. Even after attempting to delete them using these methods I kept getting pop ups saying that there was a Trojan.flush.g AND a Trojan horse being quarantined. This started happening about a week ago. I also ran the Spybot search and destroy in safe mode which found "hupigon13" I deleted that, and it hasn't come back in any more of my scans, so I'm not sure if it is related. No matter how many times I try to delete these trojans, they seem to keep coming back.

    I'm sorry that this is all the information that I can give, and I will really appreciate any help that anyone can give me!
     

    Attached Files:

  2. a12curlyq

    a12curlyq Private E-2

    Another attatchment...
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Before we can get started, you need to disable Spybot's Teatimer as was requested in the READ & RUN ME. See this: How to disable Spybot's TeaTimer


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Now uninstall the below software:
    Viewpoint Manager (Remove Only) <-- should have been uninstalled in step 1 of the READ ME
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  4. a12curlyq

    a12curlyq Private E-2

    Thank you for your help! I really appreciate you taking that time for me. So far everything is working out fairly well. I certainly hope it continues to go well! I'm sorry that I missed some of those things in the Read and Run me first :eek:.

    I did recieve a "success" message when merging the fixme.reg with the registry.

    Here are the attatchments that you asked for...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Since you started using MSconfig again, I cannot help you. The fixes did not work properly due to this. If you wish to be helped, you must follow the instructions in step 1 of the READ & RUN ME to put your PC into Normal Startup mode and you must remain in normal startup mode. It is a VERY BAD idea to use MSconfig like you are doing. You may also have to disable Teatimer again after doing this.

    Also delete the below file if found:
    C:\WINDOWS\system32\s4u5eFKB.exe_

    After you do this you will have run GetLogs.bat again and attach a new MGlogs.zip log.
     
  6. a12curlyq

    a12curlyq Private E-2

    I am SOOOOO confused right now.

    I am honestly trying to follow the directions AS I UNDERSTAND THEM. I don't know what I am even doing/ not doing that I am not supposed to be doing because I'm just trying to follow the directions EXACTLY as I read them. So, if I've done something incorrectly it's because I must not have comprehended the directions correctly.

    When I follow the directions to turn off teatimer, it is showing that it is already off.

    I have no idea how to delete that particular file or what I am supposed to do at this point.

    I went to the IT place on my campus and they ran some more scans and said they removed things from my computer. After doing that and doing what you told me, things have been running fine.

    I can tell you are becoming frustrated, and I know you are doing this as a favor to me (somebody you don't even know) but I am frustrated too because I just do not understand what i'm doing/ not doing.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are doing this at the same time that you are working here then that is the problem. Once you begin working on any forum like this you need to only do what we request and nothing else at all until your issues have been fixed. Then you are free to do what you want.

    The main problem I had was that you or your IT person, started using MSconfig again to control startups. You were not using MSconfig when you posted your first logs and now you are. This is the problem. So just do what was rquested in step 1 of the READ & RUN ME and put your PC into normal startup mode and then get a new MGlogs.zip file and attach it. We can continue afterwards. We still have more to do. If you don't know how to delete that file, we can give you instructions to do so, but first I need MSconfig in Normal Startup mode and I need a new log.
     
  8. a12curlyq

    a12curlyq Private E-2

    Ok, I believe I've put things back the way that you are asking them to be. I'm sorry, that's my fault, I was unaware that it had been changed.

    I was not sure if I was supposed to do the things that you told me earlier in this thread over again, so I did NOT do it over again because I didn't want to mess anything up again.

    Here is the log you asked for, I'll wait for your reply to do anything further.

    Thank you.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now we need to use ComboFix again.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Now doubleclick the fixme.reg file saved to your desktop in the previous fix and allow it to be added to your registry.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. a12curlyq

    a12curlyq Private E-2

    Here are the logs...
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds