Multiple Trojans

Discussion in 'Malware Help (A Specialist Will Reply)' started by writer997, May 17, 2005.

  1. writer997

    writer997 Private E-2

    I am working on my niece's computer. She let her antivirus run out and now she is loaded with trojans....I followed your steps to clean out what I could. But, I am having a problem deleting some of them.....they keep changing file names when I try.

    Trojan Horses

    TR/DROP.DELF.DJ.2

    TR/VB.W

    TR/Dldr.Wintool.B :eek:
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you have run ALL the steps in:

    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    And after doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. writer997

    writer997 Private E-2

    Thanks! :D
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the directions for installing HJT properly. You are running it from the ZIP file which is what we specifically ask not to be done. You will not get any backups this way. This is where you have it.
    C:\DOCUME~1\LILJON~1\LOCALS~1\Temp\Temporary Directory 1 for HJT.zip\HijackThis.exe

    Please extract it from the ZIP file and install into the folder requested. Do this before continuing.

    However, I do not see any real signs of problems in your log. The only item that I'm concerned about is this line:

    O23 - Service: Intranet Service (IntranetService) - Unknown owner - intranet.exe (file missing)

    I'm not sure what this service is for. Do you know?

    Which program is telling you about those trojans you listed and does it provide more info (like filenames and paths)?
     
  5. writer997

    writer997 Private E-2

    I thought I was putting it into the C:\ Program Files\HJT...at least that is where I told it to go. :confused: When I saved as...I put in in C:\Programs Files....maybe I need detailed instructions. Hey, I'm learning here, what can I say? Lol! Sorry 'bout that. I downloaded the free AntiVir PersonalEdition and ran that and it found all that stuff....I saved the log file if you'd like to see it. That intranet thingy was part of the Trojan. :(
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes post the log! So it would seem that my intuition was correct about that intranet.exe file!

    You may have put HijackThis.zip into the C:\Program Files\HJT folder but you must extract the hijackthis.exe file from the ZIP file. That is what I mean by "you are running it directly from the ZIP file". You are not extracting the executable program out of the ZIP file.


    The below will work for WinXP based system since it can deal with ZIP files.
    You need to create the C:\Program Files\HJT folder. Do the following:
    - Click START and select Explore.
    - Select the drive where Windows is installed (normally C:)
    - Navigate to the C:\Program Files folder and select it.
    - Now click the on the top menu where it says File and then select New.
    - Then select Folder
    - A new folder is created and highlighted.
    - Just type HJT to overwrite the default name (New Folder)

    To extract hijackthis.exe:
    - locate the HijackThis.zip file you downloaded and right click on it
    - Select Extract All and click Next
    - Browse your way to the C:\Program Files\HJT folder created above
    - Select the folder and click Next
     
  7. writer997

    writer997 Private E-2

    Hey there again! I think I did it right this time hon! I was able to get rid of some of them, but the last one is still there...so this is what the AV gave me and I am including the log file for you too. ;) Thanks a lot! You're the best! :D

    C:\SYSTEM VOLUME INDORMATION\-RESTORE{D4AFD415-EE98-418E-AE82-7030B37BD67F}\RP60\A0013869.EXE

    Called the TR/VB.W trojan
    :eek: :mad:
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If your antivirus is finding that file in system volume, it would have to mean that you do not have System Restore disable per step one of the READ ME FIRST. Double check to make sure it is off. It should remain off until we declare you to be clean. If it is not off, turn it off then reboot. After reboot run another scan with you AV and see if it finds anything.

    We still need to get rid of the intranet.exe service and the file. Try the below steps after get System Restore disabled.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Intranet Service (or look for IntranetService with no space) right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":'

    Intranet Service

    Again if the above name does not work, use the short name with no space: IntranetService

    After that exit Hijackthis and then restart it an do a new scan. If you see the below entry, fix it:
    O23 - Service: Intranet Service (IntranetService) - Unknown owner - intranet.exe (file missing)

    Let me know the results of all the above.
     
  9. writer997

    writer997 Private E-2

    http://img138.exs.cx/img138/4117/happy9vl.gif Thanks! Ya know....I did turn off my systems restore.....when I checked, it was back on like you said. SO ...this time it stayed off and I was able to get rid of that intranet service thingy. I ran the scan again and this time it popped up with something called Applesauce2. So I tracked down the location and deleted anything that was connected to it like ap2.zip
    Then I rebooted and ran another scan and BINGO! http://img221.exs.cx/img221/9969/yes24au.gif All gone! I am a happy camper now! Thanks so much for all your help! http://www.planetsmilies.com/smilies/love/1/love29.gif I have learned so much in here! :D :cool: Tracey
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds