Need help with trojans / viruses.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Julie Indi, Dec 4, 2004.

  1. Julie Indi

    Julie Indi Private E-2

    I wasn't really sure where this belonged. I saw another virus / trojan thread in here, so I thought it was okay to post here as well.

    I have the same problem as Kodo had. Norton says that I have viruses / trojans, but I get the error " Cannot delete because the file is in use. Please close all programs and try again ". However, when I DO close all my programs, it STILL will not delete. And I followed the pathway in safe mode / normal mode to manually delete the files, but they are not there, and not hidden, either.

    I don't know what to do. I've run HiJack This and I have no problems with my computer that I can see, following the tutorial [ I use HJT on a daily basis, so I'm pretty familiar with it now ].

    I ran the HouseCall online scanner on TrendMicro and it found things in a Java folder I had, but I uninstalled the program after HouseCall said the files were non-correctable, and I deleted another .dll that HouseCall said was infected. I have already rebooted and everything has been / is running fine, but Norton still says I have viruses.

    I have run Ad-Aware and Spybot :: Search and Destroy and rid myself of the spyware found there, and have run Norton WinDoctor [ last time that fixed my " virus " problem, I had deleted the file and it still said it was there, but that is not the case this time, I cannot even find the files to delete them! ] and everything seems fine.

    The culprits are as follows ::

    C:\Program Files\Internet Explorer\illshsqm.exe [ Backdoor.Berbew ]
    C:\RECYCLED\164831.exe [ Trojan.Startpage ]
    C:\RECYCLED\354133.exe [ '' ]
    C:\RECYCLED\835713.exe [ '' ]
    C:\RECYCLED\916193.exe [ '' ]
    C:\WINDOWS\SYSTEM\Jpgiaa32.exe [ Backdoor.Berbew ]


    Please help?
     
  2. Turcoloco

    Turcoloco MajorGeek

    Julie if your system is infected and thetrojan/virus scanners do come up with file names then they shold be there unless they are not already quarantined or deleted.
    Also are your the Folder Options settings configured to display hidden&system files?
    Open any folder, then from the top menu > Tools > Folder Options > View and make sure the 'Show hidden files and folder' is selected, also I would recommend unchecking (clearing) the 'Hide extensions for known file types' option.
    I just wanted to mention that as far as the infection or the trojan infection goes since KODO experienced that before he should be able to fill you in on it...
     
  3. Turcoloco

    Turcoloco MajorGeek

    Also do not take trojan infections lightly, unlike common spyware/adware infections, Trojans can and do infect legit and vital OS files making it impossible to kill or remove when Windows is running in the normal mode, disabling the paging file and booting in the 'Safe Mode' would not allow the services and startup application to start along with Windows. Also prior to booting in the safe mode, you should disable the System Restore service
    (right-click My Computer icon> Properties > System Restore and check the box to diable it). After cleanup, just to make sure no legit OS files were deleted, System File Checker should be run: Start > Run > sfc /scannow

    This utility would scan for deleted Windows system files and recover them.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Juli,

    If you have not alread done so, please attempt to follow all the steps in this Sticky thread < READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal >

    If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    If still having a problem after the above, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.

    Note: you should empty your Recycle Bin since some of your problems were shown to be there. (CCleaner from the READ ME FIRST should do that for you.)
     
  5. Julie Indi

    Julie Indi Private E-2

    Yes, I had my folders set to view hidden files and folders.

    Funny thing is, .. 0__o; Now Norton says that I don't have anymore viruses / trojans .. e_e; Maybe Norton was just playing games with me .. I ran Norton WinDoctor and two days later the virus scan stopped picking things up. All I did after that was run HJT once .. so I don't really understand. :\

    But thank you for your help. :3 I appreciate it. ^_^
     
  6. Julie Indi

    Julie Indi Private E-2

    Alright .. I have run HiJackThis and gotten my logfile. I see nothing suspicious, so hopefully you won't either.

    And I have read those stickies before, I was just really, really confused as to why Norton would not delete the infected files it found, and why HouseCall said my files were non-correctable.

    But .. supposedly they are gone now, Norton stopped saying I had viruses .. e_e; Sooo .. I dunno.

    Here's my logfile.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please post your complete (unfiltered if using filters) HJT log including the process list.

    Question: Why is McAfee online scan shown to be running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds