Trojan / Malware infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mark_25, Jul 7, 2008.

  1. Mark_25

    Mark_25 Private E-2

    Hi guys I think I've got a trojan or virus / malware on my PC - I've followed everything in the Readme file so far and got as far as running SUPERAnti-Spyware, the trojan seems to have blocked me from installing the other apps as when I double click after disabling all my other protection software they won't install or run.

    I've previously tried running AVG Free a few days back and that found a trojan which I removed to the vault. I've since cleared the vault as instructed. I've also run CCleaner, ATFCleaner, Microsoft Anti-Malware, Malware Removal Tool and Lavasoft Ad-Aware previous to coming on this forum. I've got some other stuff installed such as TuneUp Utilities 2008, O&O Defrag, and SpeedUpYourPC UniBlue which I'm not sure whether they're worthwhile programs to install or not. I'll also admit now that I tried to install Service Pack 3 with an unlicensed Windows XP Professional and that has more than likely given me the virus from either the WindowsGenuineAdvantage serial or the crack for TuneUp Utilities, there's also a Serials and Cracks folder on my computer from a custom install of Windows XP Borg Edition I'm guessing these serials have a lot of embedded viruses, trojans and cracks in them and assume there likely to cause more trouble in the long run, think I'm going to have to save for a Windows XP license once I've got this mess sorted.

    The trojan has blocked me from using Firefox completely in Windows XP, it sometimes pops up buttons asking for me to install suspicious anti-adware software, and whenever I google for anything to do with the removal it brings me to a similar suspicious site, I can however get online with Ubuntu and download files to my Windows XP partition.

    I've included a log file for SUPERAnti-Spyware. I can post one up for HijackThis if that's required.

    Any help would be greatly appreciated, thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What exactly happens when you try to run ComboFix, MalwareBytes and the MGTools.exe? Do you get error messages? What do they say exactly? Have you tried running them in safe mode? DId you rename ComboFix as instructed and downloaded to the desktop?
     
  3. Mark_25

    Mark_25 Private E-2

    When I double click in Normal Windows XP mode they just do nothing fail to load at all, SUPERAntiSpyware was the only one that would install and work, I haven't tried the trick with renaming ComboFix from the desktop yet, I will try this now and try running in Safe mode also. Thanks.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know what happens. :)
     
  5. Mark_25

    Mark_25 Private E-2

    Success =) renamed combofix on the desktop and it seems to have fixed the trojan, still have a lot of software on my computer I don't know what to do about and not sure if I'm totally clean.

    Thanks a lot for this, I'm lucky to have been able to get onto this site via ubuntu or I may have needed to format.

    Do I need the following still installed?

    O&O Defrag
    TuneUp Utilities 2008
    SUPERAnti-Spyware
    Ad-Aware SE Professional
    AVG 8.0 Free
    Speed Up My PC 3
    Malware Removal Tool
    Microsoft AntiSpyware
    CCleaner
    ATF Cleaner
    Registry Booster 2

    My aim is to just get an up-to-date working copy of Windows XP Professional, I don't have an official Windows XP CD (my dad bought this computer a few years ago (came bundled with AOL and Norton Antivirus ugh, tried to remove that computer went to ----, tried installing McAfee over that, went even worse since upgraded to WinXP Professional (with a free version for students from uni), went even worse, formatted and installed Windows XP Borg Edition, put a lot of pirated software and cracks on here mainly stuff that's just for getting the PC up to speed.

    My aim now is just to take off anything I don't need and get the computer running up to high speed (its only 512 Mb Ram), fully updated, Sevice Pack 3 installed.

    I mainly use for e-mail, web browsing, iTunes, Bittorrent, forums, software such as the above, MSN. I also have a H: drive partition for music. Ideally I just want advice on achieving the above, I'm happy to stop using the pirate software I prefer not to pirate software, but feel a bit annoyed that I have to pay for software just to make my PC function as it should hence the Ubuntu partition. Any advice on what I should do next to ensure I'm virus free and get any necessary freeware software installed, and remove what's on here. Just link me to the appropriate and relevant threads, cheers.

    Also after reading that thread about removing software from startup in msconfig I seem to have stuff running that I thought I'd removed. Computer still runs a bit slow but not too bad. I'm also getting windows asking me to automatically update Windows Genuine Advantage Notification and Security Update for Microsoft.NET framework (I think I uninstalled the .NET framework also as I no longer do any programming or SQL etc).

    Also do I need to pay for a licensed copy of Windows XP to get Service Pack 3 installed, I installed a Windows Genuine Advantage hack, maybe I should pay for it but really can't afford it till payday.
     
    Last edited: Jul 7, 2008
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to attach the log from running COmboFix as well as the logs from Malwarebytes and the log from running the MGTools which would be here -> C:\MGLogs.zip.
     
  7. Mark_25

    Mark_25 Private E-2

    Here you go, cheers.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This should not be where it is...frankly I would delete it:
    C:\WINDOWS\transp.gif

    Now disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\%username%\Local Settings\Temp

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  9. Mark_25

    Mark_25 Private E-2

    All done. Thanks again for your help.

    MGlogs.zip attached.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running?

    Are you having any other issues?
     
  11. Mark_25

    Mark_25 Private E-2

    Things seem to be running pretty well now thanks for all your help. Trojan seems to have gone, only thing is I would like to be able to get Windows Updates and Service Pack 3 installed but I think I'll need to get a licensed copy of windows XP for that. Any advice on which software apps to keep and what to remove in light of my post above, also any ways of keeping the boot time faster? Can I remove all these anti-malware scanners and logs?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need to get a licensed copy or call Microsoft and have them sell you a legit key.

    You may wish to use a Startup Manager for your start times.

    You should uninstall SAS, Ad-aware SE and follow the guide in the last past of the clean up:
    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    2. Click START then RUN
    * Now type "%userprofile%\Desktop\cf" /u in the runbox ( or whatever you renamed it to) and click OK.
    * Note: The space between the cf and the /U, it must be there.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  13. Mark_25

    Mark_25 Private E-2

    Thanks again, I have done all this and now installed Comodo Antivirus, Comodo Firewall, AVG Anti-Spyware, Spybot Search and Destroy, Spyware Blaster from the link you sent me. Are these good choices, see below.

    I've also ran ATF Cleaner, CCleaner and windows disk cleanup on drive C: + ran scandisk on drive C: and am now defragmenting with O&O defrag complete scan on Drive C: as well as Drive H: (music storage partition). I've also ran registry mechanic and fixed all problems.

    Earlier today the startup program link wasn't working but will download that when I get a chance tomorrow.

    With all this protection software running in the background and after doing all the above it still seems I'm getting a slow boot speed on windows xp on my computer and it can run pretty slowly still even with a few programs such as msn, itunes and firefox with two or three tabs open. I'm guessing its just the case now that my PC can't run much faster without upgrading my RAM and motherboard? I only have 512 Mb and I think only 448 in use, how much should I be looking at upgrading to for super speed boot times and being able to switch between programs without slow loads / crashes.

    Annoying thing is if I run the computer without an antivirus and firewall running I can get it running at a pretty decent loading speed and boot time. I'm guessing it's also worthwhile for me to check all my out of date drivers and get these updated?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would say that upgrading the ram may increase speeds ....all of these issues should be addressed in the software section.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds