Win32 trojan and other spyware problems

Discussion in 'adware, spyware & hijack cleaning' started by SomeGuyNameAl, May 24, 2004.

Thread Status:
Not open for further replies.
  1. SomeGuyNameAl

    SomeGuyNameAl Registered Member

    Joined:
    May 24, 2004
    Posts:
    4
    Hi, I am doing the step 3 to get rid of the trojan, here's my log file

    I just want to get rid of the trojan, other than that, i dont have too many problems, except that i cant get rid oft he trojan.

    please help, thank u.

    Al

    Logfile of HijackThis v1.97.7
    Scan saved at 2:16:38 PM, on 24/05/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Messenger Plus! 2\MsgPlus.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe
    C:\WINDOWS\Mixer.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-aware.exe
    C:\Documents and Settings\Al\Local Settings\Temp\Temporary Directory 1 for hijackthis1977.zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Al/My%20Documents/1Updated/bookmark.htm
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)
    O4 - HKLM\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe"
    O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe"
    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
    O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
    O4 - HKLM\..\Run: [atijwf] C:\WINDOWS\atijwf.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
    O4 - HKCU\..\Run: [MessengerPlus2] "C:\Program Files\Messenger Plus! 2\MsgPlus.exe" /WinStart
    O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/7d90ae05585062/housecall.antivirus.com/housecall/xscan53.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38128.4581597222
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  2. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Hi Al,

    Have only HijackThis running and fix :

    O2 - BHO: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)

    O3 - Toolbar: (no name) - {D848A3CA-0BFB-4DE0-BA9E-A57F0CCA1C13} - (no file)

    O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
    O4 - HKLM\..\Run: [atijwf] C:\WINDOWS\atijwf.exe
    O4 - HKCU\..\Run: [msmc] C:\WINDOWS\System32\msgked.exe

    Restart PC after doing so in Safe Mode : Here's How and rtemove (if still present) :

    c:\installer\id53.exe <- this file
    C:\WINDOWS\atijwf.exe <- this file
    C:\WINDOWS\System32\msgked.exe <- this file

    Clean temp internet files

    restart again in normal mode

    Hope this helps

    Cheers,
     
  3. SomeGuyNameAl

    SomeGuyNameAl Registered Member

    Joined:
    May 24, 2004
    Posts:
    4
    thanks for replying quickly.

    I thought the problem was gone, but I use an antivirus program called AVG, and they keep telling me that my trojan is still around. =(

    They called it "Trojan horse downloader.small.4.bq"

    I cant seem to get rid of it? should i run the hijackthis program again?

    Thanks in advance.

    Al
     
  4. Unzy

    Unzy Registered Member

    Joined:
    Nov 2, 2003
    Posts:
    1,098
    Location:
    Belgium
    Tell us the exact location where AVG finds this on your PC

    Cheers,
     
  5. SomeGuyNameAl

    SomeGuyNameAl Registered Member

    Joined:
    May 24, 2004
    Posts:
    4
    Its located here

    c:\system volume information\_restore{B6C0C81A-BDBF-41CF-BF96-394D9F0A30DD}\RP32\A0001519.exe
     
  6. snowbound

    snowbound Retired Moderator

    Joined:
    Feb 18, 2003
    Posts:
    8,723
    Location:
    The Big Smoke
    It looks like it is in your systems restore.

    Just disable it, reboot,enable it, create a new restore point and do another AV scan to make sure it is gone.

    If u are not sure how to disable systems restore here's how,

    http://www.pchell.com/virus/systemrestore.shtml

    Hope this helps.


    snowbound
     
  7. SomeGuyNameAl

    SomeGuyNameAl Registered Member

    Joined:
    May 24, 2004
    Posts:
    4
    cool, i think it worked !

    thanks so much! =D

    Al
     
Thread Status:
Not open for further replies.