also @ TechSpot: TechSpot 2X Giveaway: Win an ATI Radeon HD 5850, BenQ LED Mini Projector, more...
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

TechSpot Double Giveaway: Win an ATI Radeon HD 5850, BenQ LED Mini Projector, more prizes...

Recovering from some nasty trojans, may I ask some assistance?

Closed Thread
Bookmark Thread Tools
  #1  
Old 05-15-2007
Newcomer, in training
 
Member since: May 2007, 3 posts
Well I made some pretty stupid moves today. Got myself a few baddies. I was confident enough to take care of the "obvious" stuff (A system folder in Program Files with one suspicious exe called AVP.exe? Haha.... yeah right)

Unfortunately most of them were backdoors that give information out, I tried to disconnect the internet as quick as possible but who knows what the hell got out. It's kind of scary.

Annnnyway. I followed the directions in that topic, and here are my latest hijack and combofix logs. Any help would be greatly appreciated thank you

Oh... and don't let the recently created rundll32, msconfig, and taskmanager worry you. I put those there myself after the malware trashed 'em. Cheeky little bastard isn't it.

Sorry for the double post... I just kind of did it without thinking
Attached Files
File Type: txt ComboFix.txt (8.9 KB, 2 views)
File Type: log hijackthis.log (5.8 KB, 2 views)

Last edited by howard_hopkinso; 05-15-2007 at 07:02 PM.. Reason: POSTS MERGED: PLEASE USE THE EDIT BUTTON, RATHER THAN MAKING A NEW POST WHEN THERE ARE NO OTHER REPLIES INBETWEEN, THANKS.
  #2  
Old 05-15-2007
Banned
 
Member since: Aug 2004, 25,945 posts
[B]Hello and welcome to Techspot.[/B]

You have posted your HJT log from safe mode. I need to see a HJT log from normal mode please.

Also, you haven`t posted an AVG Antispyware log, nor have you given the results of the AVG Antirootkit scan.

Please go back to [URL="http://www.techspot.com/vb/topic58138.html"]this thread[/URL] and follow all the instructions exactly, then post the requested logfiles.

Regards Howard

[color=red][b]This thread is for the use of[/color] Hopeful Death [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 05-15-2007
Newcomer, in training
 
Member since: May 2007, 3 posts
Okie. I was a little scared to go back to what was crawling with trojans before. But they appear to be inactive so apparently I did enough alone to stop the damage. But I need to wipe out the traces too.

Latest logs.

The root thing came up completely clean.

As for AVG.... well... I cut a little corners. I did full scan and after 3 hours it was only 1/10 of the way done. I'm kind of on a schedule here so I just let it scan in /Windows and /Program Files. I didn't make a report for some reason, I dunno. But I can tell you that it found 2 things. One was Weatherbug, minor adware. The other was winrkq32 or something like that, which was a trojan.

Edit: On second thought, it's going a LOT faster on normal mode. If it finishes anytime soon I'll update the post with that log too
Attached Files
File Type: log hijackthis.log (6.5 KB, 2 views)
File Type: txt ComboFix.txt (8.1 KB, 1 views)

Last edited by Hopeful Death; 05-15-2007 at 07:32 PM..
  #4  
Old 05-15-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Your logs look clean. However, it appears you`re not running any antivirus software, this is a huge security risk and needs to be addressed asap.

Download and install one of the free antivirus programme in the instructions [URL="http://www.techspot.com/vb/topic58138.html"]HERE[/URL]. Then, do a full system scan and delete whatever is found.

I still need to see an AVG Antispyware log, otherwise I can`t say with any certainty whether your system is clean.

Run HJT with no other programmes open. Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: (no name) - {1B7E284A-63CC-4459-B7FA-F4BF2E84628F} - (no file)

O17 - HKLM\System\CCS\Services\Tcpip\..\{0AA69EE6-26C6-4655-8B01-4837728B504C}: NameServer = 208.67.222.222,208.67.220.220

O17 - HKLM\System\CCS\Services\Tcpip\..\{3070F698-787C-479B-B18F-478AFA881E91}: NameServer = 208.67.222.222,208.67.220.220

O17 - HKLM\System\CCS\Services\Tcpip\..\{B7310C77-A707-4BF5-8AA8-F4C60F06C280}: NameServer = 208.67.222.222,208.67.220.220

O17 - HKLM\System\CS1\Services\Tcpip\..\{0AA69EE6-26C6-4655-8B01-4837728B504C}: NameServer = 208.67.222.222,208.67.220.220

O17 - HKLM\System\CS2\Services\Tcpip\..\{0AA69EE6-26C6-4655-8B01-4837728B504C}: NameServer = 208.67.222.222,208.67.220.220

[b]Only fix the above 017 entries, if they don`t belong to your ISP.[/b]

O20 - Winlogon Notify: winrkq32 - winrkq32.dll (file missing)

Click on the fix checked button.

Close HJT and reboot your system.

Other than the above, your HJT log is clean.

Please post an AVG Antispyware log.

Regards Howard

[color=red][b]This thread is for the use of[/color] Hopeful Death [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #5  
Old 05-15-2007
Newcomer, in training
 
Member since: May 2007, 3 posts
What do you mean if it's from my ISP? The addresses 208.67.222.222,208.67.220.220 are the DNS addresses that I'm using if that means anything.

Anyway, yeah, it's going as we speak. Picked up another Trojan too(Downloader.LoadAdv)

That makes the 5th freaking one. Sheesh. Whoda thought I could get them all within the span of 3 minutes after being clean for 6 years!

Also, the biggest offender I had was a program called smanager.7.exe. I managed to get rid of it, but I couldn't find much official info on it.

More shenanigans, I couldn't install any programs under normal mode because they would automatically close in 5 seconds.

Heh, you know, sure they're bad, but they do provide for some amusement...

Sorry, just killing time waiting for this scan to finish =D

Last edited by Hopeful Death; 05-15-2007 at 07:53 PM..
  #6  
Old 05-15-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Ok mate no problem.

I`m going off line now for a few hours, as I`ve been at it all day and I`m getting very tired. I`ll be back to check your AVG Antispyware log in a few hours.

Regards Howard

[color=red][b]This thread is for the use of[/color] Hopeful Death [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Nasty XP Issue Windows OS 2 03-08-2007 09:16 PM
Help removing just this one nasty Virus & Malware removal 6 03-05-2007 08:24 PM
Nasty Trogen Virus & Malware removal 3 01-15-2007 05:57 AM
Nice Or Nasty Norton The Meeting Spot - Chat & Socialize 28 12-02-2005 01:45 AM
another hurricane - possibly nasty. The Meeting Spot - Chat & Socialize 3 09-22-2005 06:55 AM


All times are GMT -4. The time now is 08:49 PM.