plz help: Trojan.dropper,Dialer.trojan

By kossa
Sep 16, 2006
  1. Hello to everyone! I've got some problem with Trojan.dropper and Dialer.trojan. I've done all the things mentioned in the instructions and here are my logs.... thank you in advance
  2. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Hello and welcome to Techspot.

    ou might want to copy and paste these instructions into a notepad file. Then you can have the file open in safe mode, so you can follow the instructions easier.

    Turn off system restore.(XP/ME only) See how here.>

    Boot into safe mode, under your normal user name(NOT THE ADMINISTRATOR ACCOUNT). See how here.>

    In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how here.>

    Open your task manager, by holding down the ctrl and alt keys and pressing the delete key.

    Click on the processes tab and end process for(if there).


    Close task manager.

    Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = this if you didn`t set this proxy yourself, or you don`t know what it is.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = ÓõíäÝóåéò

    R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - (no file)

    O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)

    O2 - BHO: (no name) - {4E7BD74F-2B8D-469E-DCF7-F96DA086B434} - (no file)

    O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART

    O4 - HKLM\..\Run: [cyayzlcfyuch] C:\WINDOWS\System32\vqyoyxl.exe

    O17 - HKLM\System\CCS\Services\Tcpip\..\{C9E0BD1A-F075-4BFB-A685-7BDB86C93492}: NameServer =,<ONly fix this, if it doesn`t belong to your ISP.

    Click on the fix checked button.

    Close HJT.

    Locate and delete the following bold files and/or directories(if there).

    C:\WINDOWS\System32\P2P Networking

    Delete all files in Ewido quarantine.

    Reboot into normal mode, turn system restore back on and rehide your protected OS files.

    Post a fresh HJT log and let me know how your system is running.

    Regards Howard :wave: :wave:

    This thread is for the use of kossa only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
  3. kossa

    kossa TS Rookie Topic Starter

    Everything seems fine now! thank you so much. The only problem that remains is about Windows update. I try to update manually from but I have this message:
    Files required to use Microsoft Update are no longer registered or installed on your computer. To continue:

    1)Register or reinstall the files for me now (Recommended)
    2)Let me read about more steps that might be required to solve the problem

    when I sellect 1) nothing happens... ActiveX are enabled, JavaScript works, cookies enabled... any ideas??

    Here is my final log, thank you for your time!
  4. howard_hopkinso

    howard_hopkinso TS Rookie Posts: 24,177   +19

    Your HJT log is clean.

    I`m afraid I have no idea what your problem is with Windows Updates.

    Make sure you use IE for windows updates.

    Make sure that the automatic updates service is enabled and set to automatic in services.

    Click start/run and type services.msc into the run box and press the enter key.

    When the window appears, maximise it. Look for Automatic updates and see what status it has. I.E Atomatic/manual/Disabled. If it`s set to manual or disabled, double click on it and change it to automatic, then click start. Click apply/ok.

    If you have any further virus/spyware problems, please post in this thread.

    Regards Howard :)

    This thread is for the use of kossa only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...