Trojan.Agent/Gen-PWS Removed???

Discussion in 'Malware Help (A Specialist Will Reply)' started by gingerninja, Nov 27, 2010.

  1. gingerninja

    gingerninja Private E-2

    Hi,

    I'm helping a friend who's laptop has been playing up recently. I'm not entirely sure of the symptoms since she's a novice computer user (so couldn't descrobe in detail what's been the problem) and I've not had access to the pc until today. I think she was unable to connect to the net and was getting popups asking to buy software etc.

    Anyway, I've completed the Read & Run Me First section and the logs are attached. It's a 64-bit system running Windows 7 Home Premium.

    The SAS scan picked up and removed the Trojan.Agent/Gen-PWS and Malwarebytes found a couple of things after that. I didn't run the combofix or rootrepeal parts due to the 64-bit issue.

    It should be noted that she had not got any Antivirus software installed. I ran through the Read & Run Me section before installing the Free AVG software and performed a scan using that afterwards - mainly because I'd read of conflicts between AVG and some of the programs used in the cleanup.

    Essentially I'd like to know if there are any further scans needed or is the system clear for me to run through the final steps of removing the tools?

    Should I advise that she changes all of her passwords, since there may have been a keylogger on the system as a result of the trojan? Does anyone know anything about this Trojan and the presence of keyloggers and other identity stealing properties?

    Thanks to anyone who can point me on what to do next and for taking the time to check the logs.

    Gingerninja
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The PW.exe file is associated with antivirus programs like the below ( to name a few ):
    • Win 7 Security 2011
    • Vista AntiMalware 2011
    • Vista Internet Security 2011
    • XP Guard, Win 7 Antispyware 2011
    • XP Internet Security 2011
    • XP Antispyware 2011
    It is not know to be a password stealer. It just causes frequent annoying alerts and unwanted scanner popups. These tactics aimed at convincing you to pay for these fake/useless programs and at possibly getting your credit card info. If your friend tried to purchase one with a credit card, that credit card account should be closed.

    However all that being stated, it would not hurt to change passwords anyway.

    The logs are clean but you do need to get this PC properly protected.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  3. gingerninja

    gingerninja Private E-2

    Thank you Chaslang

    It's good to get a bit of background info on the virus. I can now tell my friend how this kind of thing works so that she'll be a bit more aware in the future.

    As mentioned I've installed AVG Free for her and I'll be keeping Malwarebytes installed and will get SpywareBlaster for her to run in the backgound.

    With regards to a Firewall is the Windows 7 firewall ok to do the job or is it worth getting another (like Comodo) to protect her. I'd like to keep things as simple as possible for her since she's inexperienced with computers.

    Thanks again.

    Gingerninja :)
     
  4. gingerninja

    gingerninja Private E-2

    And will also be keeping SAS having read your post properly and will suggest she buys the full version.... ;)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    AVG does have built in antispyware protection and can be a resource hog. If your friend winds up complaining that the PC performance seems bad, uninstall AVG and use Microsoft Security Essentials ( free ) or Avira.

    Third party firewalls are still significantly better than the builtin Windows firewalls; however, if the understanding/using of a firewall like Comodo ( that will ask questions ) is too difficult for them then stick with the Win 7 firewall and see how things work out.
     
  6. gingerninja

    gingerninja Private E-2

    Perfect.

    Will pass all your info on.

    Thanks again!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds