plz help: Trojan.dropper,Dialer.trojan

Status
Not open for further replies.
Hello to everyone! I've got some problem with Trojan.dropper and Dialer.trojan. I've done all the things mentioned in the instructions and here are my logs.... thank you in advance
 
Hello and welcome to Techspot.

ou might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

Turn off system restore.(XP/ME only) See how here.> http://www.bleepingcomputer.com/forums/tutorial56.html

Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.> http://www.bleepingcomputer.com/forums/tutorial61.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.> http://www.bleepingcomputer.com/forums/tutorial62.html

Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

Click on the processes tab and end process for(if there).

Networking.exe
vqyoyxl.exe

Close task manager.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 193.63.75.18:3128Fix this if you didn`t set this proxy yourself, or you don`t know what it is.

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ÓõíäÝóåéò

R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)

O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)

O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-DCF7-F96DA086B434} - (no file)

O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

O4 - HKLM\..\Run: [cyayzlcfyuch] C:\WINDOWS\System32\vqyoyxl.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{C9E0BD1A-F075-4BFB-A685-7BDB86C93492}: NameServer = 195.170.0.1,195.170.2.2<ONly fix this, if it doesn`t belong to your ISP.

Click on the fix checked button.

Close HJT.

Locate and delete the following bold files and/or directories(if there).

C:\WINDOWS\System32\P2P Networking
C:\WINDOWS\System32\vqyoyxl.exe

Delete all files in Ewido quarantine.

Reboot into normal mode, turn system restore back on and rehide your protected OS files.

Post a fresh HJT log and let me know how your system is running.


Regards Howard :wave: :wave:

This thread is for the use of kossa only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Everything seems fine now! thank you so much. The only problem that remains is about Windows update. I try to update manually from http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en but I have this message:
Files required to use Microsoft Update are no longer registered or installed on your computer. To continue:

1)Register or reinstall the files for me now (Recommended)
2)Let me read about more steps that might be required to solve the problem

when I sellect 1) nothing happens... ActiveX are enabled, JavaScript works, cookies enabled... any ideas??

Here is my final log, thank you for your time!
 
Your HJT log is clean.

I`m afraid I have no idea what your problem is with Windows Updates.

Make sure you use IE for windows updates.

Make sure that the automatic updates service is enabled and set to automatic in services.

Click start/run and type services.msc into the run box and press the enter key.

When the window appears, maximise it. Look for Automatic updates and see what status it has. I.E Atomatic/manual/Disabled. If it`s set to manual or disabled, double click on it and change it to automatic, then click start. Click apply/ok.

If you have any further virus/spyware problems, please post in this thread.

Regards Howard :)

This thread is for the use of kossa only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Status
Not open for further replies.
Back