![]() |
IOBit Software
|
|
|
||||||
| Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient. |
![]() |
|
|
Thread Tools | Display Modes |
|
#1
|
|||
|
|||
|
About 2 days ago AVG started to pop-up (about every 5 minutes) a message threat detected:
filename C:\\Windows\temp\ouvv.temp\svchost.exe Trojan Horse Clicker.AEIO Procesname: C:\Windows\System32\svchost.exe Proces-ID: 664 The proces-ID always refers to the processes: Power PlugPlay DCOMLaunch I looked up the corresponding dll's from these processes but their creationdate hasn't changed. I also put them through an online scanner (http://virusscan.jotti.org/nl) and they were all clean. A complete scan with AVG doesn't detect anything. I have attached the logfiles. Except for RootRepeal which gave the following error: FOPS - DeviceIOControl Error! Error Code = 0xc0000024 Extended info (0x000000e8) I would really appreciate if someone could look into them. |
| Sponsored links |
|
|
|
#2
|
||||
|
||||
|
Welcome to Major Geeks!
You must put ComboFix on your Desktop as the instructions requested. You have it in the below folder. c:\users\Richard\Downloads\ComboFix.exe Uninstall the below software: Ask Toolbar Now go to TDSSKiller and Download TDSSKiller.zip to your Desktop
Now we need to use ComboFix
Quote:
Do not mouseclick combofix's window while it is running. That may cause it to stall. Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms. Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). Then attach the below logs:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
richardd (01-21-10) | ||
|
#3
|
|||
|
|||
|
Thanks Chaslang for looking into this!
As an additional problem the power switch from my external harddisk is broken so at this moment I don't have a complete backup of my data. I'll probably have the harddisk back from repair within 2 or 3 days so I want to wait before I go further with the cleaningproces. Furthermore things have gone worse since I made the log-files. I now have an additional pop-up from AVG. Sometimes it says Clicker.AEIO is the treath and other times Generic 16.ADCC is the treath. They both refer to the same proces-ID. I also get bleu-screen errors now and a slow machine. I don't know wether this comes from the trojan doing more harm, or because of the wrong use of ComboFix. ( I also run Windows 7 and I'm not sure ComboFix can work with that) ComboFix came up with a warning that SuperAntiSpyware was still resident so I killed it's process. Then ComboFix went on saying that there still was something active so I tried to abort ComboFix. This didnīt work and ComboFix went on and deleted c:\windows\system32\twain_32.dll So first I want to wait until I have my harddisk back and leave the infected PC off. Chaslang, can you advice me what to do next? Must I (after the backup) go on with your cleaning process or is there a possible way to undo the harm ComboFix maybe has done? (I can't do a systemrestore because that was turned off making the log-files) And thanks again for your time and effort. |
|
#4
|
||||
|
||||
|
Quote:
Quote:
Quote:
System Restore was not turned off by making log files.
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
| The Following User Says Thank You to chaslang For This Useful Post: | ||
richardd (01-21-10) | ||
|
#5
|
|||
|
|||
|
The bluescreen errors stopped by itself (maybe after permitting Windows to look for a solution after the restarts) and also the AVG pop-up stopped by itself. I had a few times a window pop-up that svchost.exe wasn't able to communicate but that also stopped by itself.
The thing that went on was that there kept C:\Windows\temp\ccfy.tmp folders appearing. But that seems to have stopped now after your steps. Looks very good! |
| Sponsored links |
|
|
|
#6
|
|||
|
|||
|
After about a day of using my PC again I still don't have any problems or weird folders appearing. I want to thank you very much!!
|
|
#7
|
||||
|
||||
|
You're welcome. Your logs are clean. Now you need to get this PC properly protected since it has none. The below will cover this.
If you are not having any other malware problems, it is time to do our final steps:
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
|
#8
|
|||
|
|||
|
Thank you for the final touch
|
|
#9
|
||||
|
||||
|
You're welcome. Surf safely!
__________________
"There are 10 types of people in this world. Those who understand binary and those who don't." Support Majorgeeks on Facebook: Majorgeeks Newsletter |
![]() |
| Tags |
| clicker.aeio, trojan |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Trojan-Clicker.WMA.Agent.d | Jenny 2 | Malware Removal | 1 | 01-10-10 02:01 |
| Trojan-Clicker.Win32.Delf.qg | Costapaul | Malware Removal | 1 | 04-24-08 12:04 |
| Clicker virus? | Tom_NY | Malware Removal | 3 | 12-30-07 11:25 |
| trojan add clicker cannot remove | laserh20 | Malware Removal | 3 | 12-19-07 12:47 |
| trojan clicker.c | flessa | Software | 4 | 01-21-04 16:16 |