win32.monitor.spy buddy, win32.trojanspy.agent, tr/trash.gen

Discussion in 'Malware Help (A Specialist Will Reply)' started by helpwanted, Mar 28, 2010.

  1. helpwanted

    helpwanted Private E-2

    Completed the Read and Run First and the XP Clean-up. Still getting pop-up ads and runtime errors.

    Saw a thread on how to clean up a hidden driver related to the trash.gen using combofix, but felt I better send what I had first. Unsure if I saved the logs before or after I fixed; the last few days are a bit of a blur . . . coming up a very steep learning curve. I appreciate your patience as well as your guidance.

    FYI, have yet to download the current java version. Typically download onto a flashdrive at the library or a friend's computer who has highspeed (I have dial-up). As best as I can figure, I had saved 26 pages of a geography dictionary and one or more were infected. Antivir and Zonealarm didn't catch them. Friend has Kaspersky and that didn't catch these either (she's not happy). So what, if anything, might have prevented this?
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system. I must assume that you had MBAM fix the problems that it found. Tell me exactly what issues you have still.
     
  3. helpwanted

    helpwanted Private E-2

    Thanks for checking. As I indicated, I'm coming up a steep learning curve. Glad to hear that all the logs look good; thanks for letting me know.

    What's still occurring? For example, as I was working through the various weblinks on your sites, popup ads showed up. They would flash for a second or two and then disappear. I have pop-up blocker enabled.

    Also, I have been getting runtime errors. Unsure if that's related. Have posted that also on the software forum with various other information.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not malware. These are Vibrant Media Advertisements. When you move your mouse over keywords with double underlines, a related advertisement will briefly be shown. This is how many websites attempt to offset some of the costs of running the website (which is quite expensive).

    Yes you should begin with runtime errors by posting in the Software Forum and be sure to give them the exact word for word error messages and error numbers.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds