trouble removing trojan/mallware

Discussion in 'Malware Help (A Specialist Will Reply)' started by landerv, Feb 10, 2010.

  1. landerv

    landerv Private E-2

    Hey, ive been having this problem of pop-up always opening in IE.
    so i checked on virusses with micro trend security system which found a trojan.agent/Gen-CDesc, also there are cookies always returning, i have no clue if thats normal. ive followed your guide as good as i could but im running on a windows 7 premium 64-bit so i couldnt use some programs.
    here are some of my logs...Thank You for taking a look at my thread.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why am I not seeing any Anti-virus program on this system??

    Let's start with this:

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\Users\Lander\AppData\Local\Temp\Gvl.exe
    C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
    C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
    C:\Windows\TEMP\SEPFA5A.tmp
    C:\Windows\TEMP\UDD58D.tmp
    C:\Users\Lander\Local Settings\TEMP\3228_1
    C:\Users\Lander\Local Settings\TEMP\3628_1
    C:\Users\Lander\Local Settings\TEMP\3704_1
    C:\Users\Lander\Local Settings\TEMP\3916_1
    C:\Users\Lander\Local Settings\TEMP\4208_1
    C:\Users\Lander\Local Settings\TEMP\4388_1
    C:\Users\Lander\Local Settings\TEMP\4472_1
    C:\Users\Lander\Local Settings\TEMP\4608_1
    C:\Users\Lander\Local Settings\TEMP\6432_1
    C:\Users\Lander\Local Settings\TEMP\a.dat
    C:\Users\Lander\Local Settings\TEMP\Gvk.exe
    C:\Users\Lander\Local Settings\TEMP\Gvl.exe
    C:\Users\Lander\Local Settings\TEMP\mm1.mht
    C:\Users\Lander\Local Settings\TEMP\mm2.mht
    C:\Users\Lander\Local Settings\TEMP\mm3.mht
    C:\Users\Lander\Local Settings\TEMP\mm4.mht
    C:\Users\Lander\Local Settings\TEMP\PCW2201.tmp
    C:\Users\Lander\Local Settings\TEMP\PCW2201.xml
    C:\Users\Lander\Local Settings\TEMP\PCWF4B.tmp
    C:\Users\Lander\Local Settings\TEMP\PCWF4B.xml

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. landerv

    landerv Private E-2

    Thanks for looking at my thread. to start of annoying i could not find
    should i wait for further instructions or just continue with what you said below that quote? i have checked HijackThis 5 times and couldnt find it, im running windows 7, i double clicked it and also say run as administrator but it seems its not in it anymore.
    there should be a anti-virus sytem on it called Trend Micro internet security.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Continue on with the fix.

    Trend Micro is not showing in your add/remove list.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds