Trojan BHO

Discussion in 'Malware Help (A Specialist Will Reply)' started by replacement, Oct 16, 2008.

  1. replacement

    replacement Private E-2

    Hello Admins.

    I recently found out that something bad is sitting in my machine. My PC was lagging for few days and than random links were opening off my sight. See screen shot below.


    Than i did the "Run me First" stuff from your forum, seems no effect at all but i found out that 'Trojan BHO' files can not be deleted buy any of the programs from that section.

    Please help me with this problem.

    Thanks for your attation
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then if you went thru our Read and Run Me first procedures you should also have ran the other scans ..those being SUPERantispyware, Malware Bytes and MGTools.

    So in your next reply if you could also upload to us those logs mentioned above that would be great and we can take a look at what's happening with your machine and work out a remedy.

    Thanks
    Kes13!
     
  3. replacement

    replacement Private E-2

    here you go...
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi

    That's great, almost all the logs have been uploaded correctly now except for just one more that I need from you, that being:
    • MGlogs.zip

    Notice that you attached mgtools.log...which was actually a Hijackthis log.
    What I want from you is the zip file which will be located on your C Drive.

    Many thanks
    Kes13!
     
  5. replacement

    replacement Private E-2

    yep see it)
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thanks, am taking a good look at your logs right now and will get back to you with some steps to follow as soon as I possibly can.

    Kes13!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    This needs to be cleaned up, it is a great place for malware to hide:
    C:\Documents and Settings\Gaming\Desktop\

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the "Input script here:"
    part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Be sure to tell us how things are running.
     
  8. replacement

    replacement Private E-2

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't clean up your desktop as I advised. :(

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking fix, just exit HJT.

    Now use windows explorer to find and delete:
    C:\Windows\85EBB28365AF4C539EBE7C0A232762F7.TMP

    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.

    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.

    If you use Firefox browser

    * Click Firefox at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    * Click Opera at the top and choose: Select All
    * Click the Empty Selected button.
    o NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main ATF Cleaner menu to close the program.

    Tell me if you are having any other malware issues before we do the final cleanup.
     
  10. replacement

    replacement Private E-2

    sorry could do that(clean my desk top), becouse some files i have there are currently used in my movie edditing programs, and if i move them i would need to serch them a lot long time) but ill do it... is this what i suppose to do to my 2nd PC or still this one?

    *UPDATE*

    well i did everything what you told me....and right i dont see the links oppening by them selves or anything like that. I feel like, "i need to buy you a beer now" for fixing my stuff ) :D
     
    Last edited: Oct 17, 2008
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As to the desktop, you can create folders to put some of those files in..:)

    If you are not having any other malware issues, then we need to clean up:

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you do get a success message, then:
     
  12. replacement

    replacement Private E-2

    Thanks a lot:wave But i have one more question to ask, what is a good anivirus that i can buy for my both PCs? I tried Panda, and Kaspersky. On 2nd PC i have Kasperskyy right now installed? Any ideas what is a good one to buy right now?
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Paid for anti-virus software is not necessarily better than freeware and is often so bloated that it puts a drag on the system. I would recommend one of the programs listed in the How to protect yourself link. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds