Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Trojan.ransom  (Read 32919 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Trojan.ransom
« Reply #15 on: September 02, 2012, 07:38:56 PM »
Please run ESET again because the infections were not cleaned. Also, please tell me how your computer is running now.
Windows 8 and Windows 10 dual boot with two SSD's

MP1975

    Topic Starter


    Apprentice
    Re: Trojan.ransom
    « Reply #16 on: September 03, 2012, 11:48:27 AM »
    Mission control we had a problem...

    I ran it again as instructed and the first time when it was finished and I hit FIX it took to me a screen trying to sell me the software. When I hit the 30 day free trial it didn't seem to do anything. I started it again and it finished telling me there were no problems found and again taking me to a screen trying to sell me the software ? I do not see a report.

    My computer runs just great to be honest it's just the last several times I've run Malwarebytes it shows an infection. Before it does affect my compuetr I would like to get rid of it.

    You've been a big help Thanks again,
    MP.
    Dream untill your dreams come true.

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Trojan.ransom
    « Reply #17 on: September 03, 2012, 04:13:44 PM »
    Quote
    I ran it again as instructed and the first time when it was finished and I hit FIX it took to me a screen trying to sell me the software.
    I just ran ESET again on my computer and I don't see any Fix button or free trial. You should not be seeing anything like that. Please try running it again. Also, please post another MBAM log.
    Edit. I just finished the ESET scan and I received the same sales pitch so something has changed at ESET.
    « Last Edit: September 03, 2012, 05:34:52 PM by SuperDave »
    Windows 8 and Windows 10 dual boot with two SSD's

    MP1975

      Topic Starter


      Apprentice
      Re: Trojan.ransom
      « Reply #18 on: September 04, 2012, 11:06:07 AM »
      Dave ,

      I "Must have" run asw ? I'm a dolt.

      "BUT" The good news is I ran MBAM and the original Trogan is no longer showing up. I can assume I now have a clean bill of health .

      Malwarebytes Anti-Malware 1.62.0.1300
      www.malwarebytes.org

      Database version: v2012.09.04.08

      Windows 7 Service Pack 1 x64 NTFS
      Internet Explorer 9.0.8112.16421
      MP :: MP-PC [administrator]

      9/4/2012 1:02:03 PM
      mbam-log-2012-09-04 (13-02-03).txt

      Scan type: Quick scan
      Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
      Scan options disabled: P2P
      Objects scanned: 206759
      Time elapsed: 1 minute(s), 16 second(s)

      Memory Processes Detected: 0
      (No malicious items detected)

      Memory Modules Detected: 0
      (No malicious items detected)

      Registry Keys Detected: 0
      (No malicious items detected)

      Registry Values Detected: 0
      (No malicious items detected)

      Registry Data Items Detected: 0
      (No malicious items detected)

      Folders Detected: 0
      (No malicious items detected)

      Files Detected: 0
      (No malicious items detected)

      (end)


      Again thanks much for the help and patience,
      MP.
      Dream untill your dreams come true.

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Trojan.ransom
      « Reply #19 on: September 04, 2012, 04:10:38 PM »
      Let's give it a few days to see how it works then come back and we'll do some cleanup.
      Windows 8 and Windows 10 dual boot with two SSD's

      MP1975

        Topic Starter


        Apprentice
        Re: Trojan.ransom
        « Reply #20 on: September 04, 2012, 09:36:23 PM »
        Very cool !!!!

        And I always "thought" I was clean as a whistle. lol

        Gonna learn something new.

        Again can't thank you enough,
        MP.
        Dream untill your dreams come true.

        MP1975

          Topic Starter


          Apprentice
          Re: Trojan.ransom
          « Reply #21 on: September 09, 2012, 01:06:42 PM »
          Dave ,

          I just ran Superantispyware, malwarebytes and avg and everything is clean, no more Trojan.

          Any other tweaking or clean up you can suggest would be a big help.

          Thanks much,
          MP.
          Dream untill your dreams come true.

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Trojan.ransom
          « Reply #22 on: September 09, 2012, 01:40:40 PM »
          Just a cleanup and we should be done.

          Download this program and run it Uninstall ComboFix .It will remove ComboFix for you.

          ***************************************************
          Download OTC by OldTimer and save it to your desktop.

          1. Double-click OTC to run it.
          2. Click the CleanUp! button.
          3. Select Yes when the "Begin cleanup Process?" prompt appears.
          4. If you are prompted to Reboot during the cleanup, select Yes
          5. OTC should delete itself once it finishes, if not delete it yourself.
          ****************************************************
          To set a new Restore Point.

          Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
          Click the Start button , click Control Panel, click System and Maintenance, and then click System.
          In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
          To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
          This will give you a new, clean Restore Point.
          ***********************************************************
          Clean out your temporary internet files and temp files.

          Download TFC by OldTimer to your desktop.

          Double-click TFC.exe to run it.

          Note: If you are running on Vista, right-click on the file and choose Run As Administrator

          TFC will close all programs when run, so make sure you have saved all your work before you begin.

          * Click the Start button to begin the cleaning process.
          * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
          * Please let TFC run uninterrupted until it is finished.

          Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
          *****************************************************
          Use the Secunia Software Inspector to check for out of date software.

          •Click Start Now

          •Check the box next to Enable thorough system inspection.

          •Click Start

          •Allow the scan to finish and scroll down to see if any updates are needed.
          •Update anything listed.
          .
          ----------

          Go to Microsoft Windows Update and get all critical updates.

          ----------

          I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

          SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
          * Using SpywareBlaster to protect your computer from Spyware and Malware
          * If you don't know what ActiveX controls are, see here

          Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

          Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

          Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
          Safe Surfing!
          Windows 8 and Windows 10 dual boot with two SSD's

          MP1975

            Topic Starter


            Apprentice
            Re: Trojan.ransom
            « Reply #23 on: September 09, 2012, 01:49:57 PM »
            Will do all suggested just to let you know I use Firefox and not Explorer. No difference in what to run ?
            Dream untill your dreams come true.

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Trojan.ransom
            « Reply #24 on: September 09, 2012, 05:09:35 PM »
            Will do all suggested just to let you know I use Firefox and not Explorer. No difference in what to run ?
            Some say FireFox is a more secure browser but it really doesn't make any difference.
            Windows 8 and Windows 10 dual boot with two SSD's

            MP1975

              Topic Starter


              Apprentice
              Re: Trojan.ransom
              « Reply #25 on: September 10, 2012, 10:29:11 AM »
              Dave ,

              Completed all suggestions , I opted out of spyblaster because it wanted me to either sign up for something or pay 14.95 and a funny thing with secunia (sp?) I ran it and updated what needed to be updated. Then, not sure why, I reran it again i guess to make sure the updates took and it listed the same software ? I went to the java site and it told me I had the latest version it also lists flashplayer twice. Otherwise everything else was completed.

              Thanks much,
              MP.
              Dream untill your dreams come true.

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Trojan.ransom
              « Reply #26 on: September 10, 2012, 04:34:45 PM »
              Quote
              Then, not sure why, I reran it again i guess to make sure the updates took and it listed the same software ?
              Sometimes if there are remnants of a previous program such as a previous version of Java not removed it will trigger a warning.
              Quote
              Thanks much,
              You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
              Windows 8 and Windows 10 dual boot with two SSD's

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: Trojan.ransom
              « Reply #27 on: September 13, 2012, 04:54:51 PM »
              Please download AdwCleaner by Xplode onto your Desktop.
              • Double click on AdwCleaner.exe to run the tool.
              • Click on Search.
              • A logfile will automatically open after the scan has finished.
              • Please post the content of that logfile in your reply.
              • You can find the logfile at C:\AdwCleaner[Rn].txt as well - n is the order number.
              Windows 8 and Windows 10 dual boot with two SSD's

              MP1975

                Topic Starter


                Apprentice
                Re: Trojan.ransom
                « Reply #28 on: September 13, 2012, 07:23:36 PM »
                Here ya go.

                # AdwCleaner v2.001 - Logfile created 09/13/2012 at 21:23:19
                # Updated 09/09/2012 by Xplode
                # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
                # User : MP - MP-PC
                # Boot Mode : Normal
                # Running from : C:\Users\MP\Downloads\adwcleaner.exe
                # Option [Search]


                ***** [Services] *****

                Found : Browser Manager

                ***** [Files / Folders] *****

                File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
                File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt
                File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
                File Found : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt
                Folder Found : C:\Program Files (x86)\Ask.com
                Folder Found : C:\Program Files (x86)\Common Files\Software Update Utility
                Folder Found : C:\Program Files (x86)\Conduit
                Folder Found : C:\Program Files (x86)\OApps
                Folder Found : C:\Program Files (x86)\Zynga
                Folder Found : C:\ProgramData\Babylon
                Folder Found : C:\ProgramData\Browser Manager
                Folder Found : C:\Users\MP\AppData\Local\Conduit
                Folder Found : C:\Users\MP\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk
                Folder Found : C:\Users\MP\AppData\LocalLow\Conduit
                Folder Found : C:\Users\MP\AppData\LocalLow\PriceGong
                Folder Found : C:\Users\MP\AppData\LocalLow\Zynga
                Folder Found : C:\Users\MP\AppData\Roaming\Babylon
                Folder Found : C:\Users\MP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager

                ***** [Registry] *****

                Data Found : HKLM\..\Windows [AppInit_DLLs] = c:\progra~3\browse~1\22630~1.40\{16cdf~1\browse~1.dll
                Key Found : HKCU\Software\AppDataLow\Software\AskToolbar
                Key Found : HKCU\Software\AppDataLow\Software\conduitEngine
                Key Found : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
                Key Found : HKCU\Software\AppDataLow\Software\PriceGong
                Key Found : HKCU\Software\AppDataLow\Software\SmartBar
                Key Found : HKCU\Software\Ask.com
                Key Found : HKCU\Software\BrowserMngr
                Key Found : HKCU\Software\Conduit
                Key Found : HKCU\Software\DataMngr
                Key Found : HKCU\Software\DataMngr_Toolbar
                Key Found : HKCU\Software\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk
                Key Found : HKCU\Software\ilivid
                Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
                Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
                Key Found : HKLM\Software\Babylon
                Key Found : HKLM\Software\BrowserMngr
                Key Found : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
                Key Found : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
                Key Found : HKLM\SOFTWARE\Classes\Conduit.Engine
                Key Found : HKLM\SOFTWARE\Classes\dnUpdate
                Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
                Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
                Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
                Key Found : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
                Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2438727
                Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2504091
                Key Found : HKLM\SOFTWARE\Classes\Toolbar.CT2856425
                Key Found : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
                Key Found : HKLM\Software\Conduit
                Key Found : HKLM\Software\DataMngr
                Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97D69524-BB57-4185-9C7F-5F05593B771A}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk
                Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
                Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
                Key Found : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
                Key Found : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
                Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
                Key Found : HKU\S-1-5-21-3145774003-3066190270-2427905049-1001\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40B7-AC73-056A5EBA4A7E}
                Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
                Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{b64982b1-d112-42b5-b1e4-d3867c4533f8}]
                Value Found : HKCU\Software\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]
                Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}]

                ***** [Internet Browsers] *****

                -\\ Internet Explorer v9.0.8112.16421

                [OK] Registry is clean.

                -\\ Mozilla Firefox v15.0.1 (en-US)

                Profile name : default
                File : C:\Users\MP\AppData\Roaming\Mozilla\Firefox\Profiles\7ehyr3dl.default\prefs.js

                [OK] File is clean.

                -\\ Google Chrome v [Unable to get version]

                File : C:\Users\MP\AppData\Local\Google\Chrome\User Data\Default\Preferences

                [OK] File is clean.

                *************************

                AdwCleaner[R1].txt - [6096 octets] - [13/09/2012 21:23:19]

                ########## EOF - C:\AdwCleaner[R1].txt - [6156 octets] ##########
                Dream untill your dreams come true.

                SuperDave

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: Trojan.ransom
                « Reply #29 on: September 13, 2012, 07:50:57 PM »
                Remove the Adware:
                • Please close all open programs and internet browsers.
                • Double click on adwcleaner.exe to run the tool.
                • Click on Delete.
                • Confirm each time with OK
                • Your computer will be rebooted automatically. A text file will open after the restart.
                • Please post the content of that logfile in your reply.
                • You can find the logfile at C:\AdwCleaner[Sn].txt as well - n is the order number.
                Windows 8 and Windows 10 dual boot with two SSD's