Help! I cannot remove this Trojan.downloader!

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by illyiii, Oct 10, 2004.

  1. illyiii

    illyiii Private E-2

    This morning, I downloaded and ran all of the following, per the instructions provided on this web site: ad-aware(with plug-in), ccleaner, spywareblaster, stinger, aboutbuster, hsremove, cwshredder, spybot, kill2me. There were no problems running anything, I did what I was supposed to in safe mode, etc.

    However, I still cannot get rid of the virus on my computer. Symantec will delete a trojan downloader, but it always seem to comes back. I also get error messages involving media.exe and ipc.exe, and when i go online, a new browser will often start-up, pointed to, i believe, a planetnana website.

    If I post a Hijack This log, can someone assist me in removing the problem? Thanks in advance!

    Nathan
     
  2. Ciz

    Ciz Corporal

    have you tried turnining system restore off before scanning (if your using XP)?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first step of the instructions already specifically tell you to do this.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not mention running any of the online scans or Stinger. Also there are some Alternative Scans to try.
     
  5. illyiii

    illyiii Private E-2

    sorry, to be clear, i did turn off system restore; i then shut down via the start menu, and rebooted in safe mode, and ran Trend Micro's Scan and Symantec Security Check (both for viruses and the security check). I then ran stinger, and then Ccleaner, Ad-Aware and Spybot, CWShredder, Kill2Me, about:Buster, HSRemove. I did, however, just realize I did not do the alternate scans like ADS SPY. I will get on this and report back. Thanks!
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! Let us know when you are done. If still having a problem, post a HJT log as an attachment.
     
  7. illyiii

    illyiii Private E-2

    Sigh. After running the alternate scans, still no luck. I have attached the 'hijack this' log. Thanks in advance for your help!

    Nathan
     
  8. illyiii

    illyiii Private E-2

    'Hijack This' log as attachment.
     

    Attached Files:

  9. Kodo

    Kodo SNATCHSQUATCH

    illyiii,
    you need to shut down Trillian and firefox and put HiJackThis in its' own folder (like C:\HJT) . Run it again and post another log. Thank you.
     
  10. illyiii

    illyiii Private E-2

    Done. Thanks for your help!
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're still forgetting to shutdown ALL browsers. You had this running:
    C:\Program Files\Mozilla Firefox\firefox.exe

    Make sure you have system restore disabled and viewing of hidden files enabled.
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Find the below processes and End them:
    crsss.exe
    autp.exe
    ??plorer.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {1DAC3629-9364-2DC1-8253-665579F62A69} - C:\WINDOWS\System32\vakzf.dll
    O4 - HKLM\..\Run: [Windows media service] crsss.exe
    O4 - HKLM\..\RunServices: [Windows media service] crsss.exe
    O4 - HKCU\..\Run: [Uahe] C:\Documents and Settings\Peters\Application Data\autp.exe
    O4 - HKCU\..\Run: [Hhlan] C:\WINDOWS\System32\??plorer.exe
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=191585e81560aabb3492edc27876f5dcfc5e67fbea1e9980930a267886cdf8b394af9617218610d9cced3a6487811e61632e7fda9906d63a444e1147752ccb3c3b:7f5b7c181d725f79a3ce39e343d9492c

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\crsss.exe
    C:\Documents and Settings\Peters\Application Data\autp.exe
    C:\WINDOWS\System32\??plorer.exe <--- let me know if you see any similar named files in system32 (like explorer.exe).

    No reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  12. illyiii

    illyiii Private E-2

    I did the first part of what you asked (that is, deleted out the files in HJT). However, when I rebooted in safe mode, the three things you told me to delete were not there.
    [C:\WINDOWS\System32\crsss.exe; C:\Documents and Settings\Peters\Application Data\autp.exe; C:\WINDOWS\System32\??plorer.exe <--- let me know if you see any similar named files in system32 (like explorer.exe).]

    In system32, I did not see any files that looked like explorer.com or any variation of the first two letters. So you know, I did enable the ability to view hidden files when I was sifting through those directories. Any idea why I could not find them?

    I am attaching my HJT log - I'd appreciate it if you could tell me what else, if anything, i need to delete. Thanks for all your help! It usually takes my network 10 minutes or so to boot me off, so I will wait to see if it happens again -- if so, i will go to another computer and post it.

    Nathan
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your log looks clean now! Any problems?
     
  14. illyiii

    illyiii Private E-2

    no problems so far - i think it worked. :)

    thanks a ton - you are awesome!

    nathan
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Good job!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds