Trojan.BHO continues to infect registry

Discussion in 'Malware Help (A Specialist Will Reply)' started by suckpuppet, Jan 10, 2009.

  1. suckpuppet

    suckpuppet Private E-2

    Please if you can help remove or prove I'm no longer threatened I would be most appreciative. Thanks.

    I have run everything your fine site has suggested and rid my PC of most of whatever first attacked my PC. I think it was trojans: fake-alert and antivirus 2009. MBAM and SAS seemed to have cleaned up most of it along with Combofix.

    However, there remains an infected registry key that both MBAM and SAS still find and say they will remove on reboot but are not successful in doing so. I have a feeling that the underlying trojan is still lurking somewhere. I took a risk and tried to delete the key manually using regedit and met resistance from the registry.

    I have attached the MBAM and SAS logs. If you have time to help, please let me know which other actions you need and logs...
     

    Attached Files:

  2. suckpuppet

    suckpuppet Private E-2

    Attaching the MGlogs and Combofix log. Please help.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean....but we need to do a few things;

    1) Remove either McAfee or Avira as you should have only one AV program!

    2) Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    3) Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    If you are not having any other malware issues, then:

     
  4. suckpuppet

    suckpuppet Private E-2

    Thank you for your help. Everything you said makes sense. Unfortunately, I was obsessed with removing that last infected registry key. Rather than wait for your post, I gave regedit a shot. Long story short, I ended up doing a factory restore of my PC, which cleaned out more than just my trojan remnant.

    Again, thanks for the help.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds