TechSpot

[Resolved] I have Win32:Trojan-gen {Other} virus, Please check my log

By mickey524
Jan 18, 2008
Topic Status:
Not open for further replies.
  1. Attached is my hijackthis logfile.. Please help.. :) Thanks in advance!
  2. Blind Dragon

    Blind Dragon TS Evangelist Posts: 4,048

    Uninstall HJT

    You are running an out of date version of Hijackthis you also have it installed in an incorrect directory. And judging by the directory C:\Documents and Settings\ai2\Desktop\Win32Trojan-gen {Other}\hijackthis.exe

    I would say there is a good chance you are infected :D

    1)Download and install the LATEST version of HJT (currently v2.0.0.2) from http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe (Run the HijackThis Installer and it will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe. Please don't change the directory. It will also automatically OPEN HJT, CLOSE IT)

    2)Open Program Files folder and rename hijackthis.exe to Crusty.exe because some malware can hide from highjackthis. Right click the HijackThis.exe file and choose rename to do this. Right click the Crusty.exe file and choose send to desktop(create shortcut).

    ***Under no circumstances should you add any items to the HJT ignore list. Under no circumstances should you change the directory that highjackthis downloads to.
  3. mickey524

    mickey524 TS Rookie Topic Starter

    Hi Blind Dragon,

    Thanks for the fast reply.. I already installed the new version of hijackthis. Here's my new log file.. please check :) thanks!
  4. Blind Dragon

    Blind Dragon TS Evangelist Posts: 4,048

    Viruses/Spyware/Malware, preliminary removal instructions

    You really need to run through these instructions as HJT is not a stand-alone cleaning tool and it does not scan the entire system.

    The trojan that you are seeing is a generic name assigned to trojans picked up by Avast

    After the 15 steps come back and post the 3 requested logs as attachments
  5. mickey524

    mickey524 TS Rookie Topic Starter

    Hi Blind Dragon,

    I'm done with the 15 steps.. Attached are the 3 log files.. :)
  6. momok

    momok TS Rookie Posts: 2,272

    Hi,

    1. Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):

    2. Save this as CFScript on the desktop.
    3. Referring to the image below, drag CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe.
      [​IMG]
    4. ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.
      Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang

    Thereafter, please post a fresh HJT log and the resultant ComboFix log from the above instructions as attachments into this thread.


    Regards,
    momok =)

    This thread is for the use of mickey524 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our Security and The Web forum.
  7. mickey524

    mickey524 TS Rookie Topic Starter

    hi momok,

    here's the combofix log file along with a new hjt log.. :)
  8. momok

    momok TS Rookie Posts: 2,272

    Hi,

    Your logs look clean now.

    1. Please download and run CCleaner via step 9 of the instructions HERE.

    2. Delete all files in AVG Antispyware Quarantine folder. (located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine)

    3. Turn off system restore (XP/ME only). Learn how to do that HERE.
      This will remove all the remaining nasties from your old restore points.

    4. After that turn system restore back on.
      This would have created a new safe and clean restore point for your system.

    5. Often times, an infection can occur again not due to the incompetence of programs, but because of user habits.
      May I recommend you to read this article.
      This can help to prevent future infections.

    Should you have any further problems, please post in this thread.


    Regards,
    momok =)

    This thread is for the use of mickey524 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  9. mickey524

    mickey524 TS Rookie Topic Starter

    Thanks a lot momok! Everything seems fine now.. Thanks for all your help! :)
  10. momok

    momok TS Rookie Posts: 2,272

    Thread closed as the problem appears to have been resolved. Should the original starter require it to be reopened, please PM a mod.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.