Trojan Email...Stupid Mistake

Discussion in 'Malware Help (A Specialist Will Reply)' started by Shaggers, Nov 15, 2010.

  1. Shaggers

    Shaggers Private E-2

    So I mailed a package about a week ago, then a couple days later I received an email from someone posing as dhl...the email said something to the effect of "your package couldn't ship, check attached file for information about"...some kind of code or something, I can't remember. Lucky timing for whoever sent the email...it was a very important package so I (stupidly) rushed through to see what was wrong and BAM...got hit with a trojan.

    I downloaded and ran everything in the "read and run me first" thread as best as I could. I wasn't able to run Mgtools, however, and after hours of frustration and massive headache, I just gave up on that one. So if that's absolutely necessary, if someone could help me through that, that would be much appreciated. Anyway, I hope I attached everything needed to help me out with this.
     

    Attached Files:

  2. Shaggers

    Shaggers Private E-2

    whoops...forgot the malwarebytes log...here it is:
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rename C:\MGTools.exe to magpie.com. Reboot into safe mode. Now try and run the C:\magpie.com.

    If you really were not able to run it then move onto the next steps:

    Download and install HijackThis

    Do a system scan only and save a log file to attach here for my reviewal.

    Also:

    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply. :)
     
  4. Shaggers

    Shaggers Private E-2

    Ahh thank you. That worked, I should have tried running in safe mode earlier, duh on me. Here's the mgtools zip file.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like the scans took care of the malware. We only have some junk to clean up.

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now tell me how things are working!
     
  6. Shaggers

    Shaggers Private E-2

    Hey that totally worked, thanks TimW! And Kestrel13! Yep I got a successful message after adding that to the registry and everything seems to be in perfect working order. Thanks again for taking the time to help me out. I REALLY appreciate it.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just do this before we wrap up:

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some data on it
    • Right click on the screen and select > Select All
    • Press Control+C
    • Open a notepad and press Control+V
    • now please ATTACH that report to this thread
     
  8. Shaggers

    Shaggers Private E-2

    hmm...this seems like an ominous sign...found non-standard or infected mbr? Don't know what that means but it doesn't sound friendly.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your OS CD? If so, change the bios to allow the cd drive to be the first boot device and then boot to the cd. Go into the Recovery Console and type:
    Fixboot.
     
  10. Shaggers

    Shaggers Private E-2

    No...I don't. I moved a little while ago and I think I left it at my parents house.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This may or may not work, as it has been failing lately, but let's see:

    * Run MBRCheck.exe
    * Wait until you see the following lines:
    o Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    o Options:
    [1] Dump the MBR of a physical disk to file.
    [2] Restore the MBR of a physical disk with a standard boot code.
    [3] Exit.
    Enter your choice:

    * Please push the 'Y' key and then press Enter
    * When the program asks you to Enter your choice: enter 2 to Restore the MBR and press the Enter key
    * Now the program will ask you to "Enter the physical disk number to fix (0-99, -1 to cancel):"
    o Enter 0 and press the Enter key.
    * The program will show Available MBR codes as below

    * You need to select your version of Windows from the list. For example, enter 0 or 1 for XP or enter 3 for Vista.....etc. and then press Enter.
    * The program will prompt for confirmation. Type 'YES' and hit Enter.
    * Left click on the title bar (where program name and path is written). From menu chose Edit -> Select All
    * You will see all the text in the window get highlighted.
    * Hit the Enter key on your keyboard to copy all of the text into the clipboard.
    * Paste that text into Notepad, save it to your desktop as MBRfix.txt
    * Restart your PC.
    * Attach the MBRfix.txt file to your next message..

    Now please re-run MBRCheck.exe and attach that log also.
     
  12. Shaggers

    Shaggers Private E-2

    not sure I did it right, but here's the goods:
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Appears to not have worked. You can try creating a Recovery Console disc so you can boot to the recovery console and do a fixmbr command:

    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds