trijan-virus infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by adamf, Jun 3, 2005.

  1. adamf

    adamf Private E-2

    hi can i first apoligize if i am in the rong part of the forum.
    i am not very proficient on pc's so i dont really know where to go and what to do.
    i have looked at a few other threads for spware/trojan/virus removal but i am at a loss to understand them to be honest.

    to start i have been trying to remove a trojan(?) problem for sevreal days with no success i have downloaded every free program i can think of or find but without and luck.

    it seems as if the trojan is locking me out of my own system?(is this possible)

    my pc already had norton internet security and antivirus 2005 which i though was upto date and protecting me so i am not sure how i got this problem (my kids all use the pc as well so ????????????)

    i have run a hijack this log to copy on here in the hope that some1 could help me but could you please be very explicit in your descriptions as i say i am not the most knowledgable on pc's.

    many thanks.

    Edit by chaslang: Unrequested inline log removed
     
    Last edited by a moderator: Jun 3, 2005
  2. adamf

    adamf Private E-2

    it maybe helpful to add what i have discovered so far!

    1) norton symantec will not detect/remove anything

    2)no online scans from anywhere will remove anything and only detect minor spywares that adaware cleans up.

    3) when i restart into safe mode i have the option of logging in as myself or as an administrator ( but i have never created an administrator account there should only be 1 account on the pc my own.every1 in the family uses my account)

    4) all removal programs say access denied to certain areas when i am logged in as myself but in the administrator account i cant run any removal programs as it wont let me. i have even tried saving programs to a CD but in the administrator accounti cant even open the cd to get to the programs.

    i hope this mat help some 1 to help me if there is any ther info i can supply please ask and i will respond as best i can.

    if what your request requires any amount of pc knowledge then please explain how i do what it is you need me to do.
     
  3. adamf

    adamf Private E-2

    hi the more i read the more i realise i am making a mess of this!.sorry guys n gals.

    i have been reading thr generic solution for "only the best aka HSA and about blank hijackers post.

    and what i have discovered is that i am 1 of the 1's who cannot be fixed with that method.(which i was very unsure i could do anyways its so complicated).

    could some1 please point me in the right direction now?

    if i have that unfixable 1 how do i fix it please?
     
  4. adamf

    adamf Private E-2

    hi guys i guess i have finally got round to what you all want.........sorry again!

    as i am sure you will understand those of us who dont know what we are doing just panic when something like this happens!

    i know where i am and what i need to do to provide you all with the information necessary to help me now

    i have downloaded all the files from your links (thanks for that makes things easier) and will run the tests you require now.

    please disregard all the nonsense i ahve put on here so far( i am sure you were anyway.lol)

    and i will submit the relevant details in a new thread with the correct information.

    thanks.
     
  5. adamf

    adamf Private E-2

    major trojan/spyware problem.

    hi i posted earlier on without running any of the tests you require to help you help me.

    the problem i have is that i am running a pc with windows xp home edition and recently had to do a full system restore (or so i thought) from the hard drive partition(i dont have restore disks).

    i have tried to run symantec online,trend micro online ad aware(with cleaner plug in) Ccleaner spybot,spyware blaster, mcafee avert stinger, CWshredder,kill2me,about buster.

    the problem is that the pc will not execute ANY OF THESE SCANS OR CLEANS.

    when i log onto the pc (safe mode) there are 2 options myself or administrator but i have never made an administrator account and if i try to do anything in my profile everything is locked out to me. if i go into the administrator account everything is still locked(best i can tell i am not very proficient on pc's).

    the windows explorer is v5 as i am unble to download any updates from windows except v5 updates so i havent as yet downloaded them.

    i am at a complete loss as to what i need to do now.

    i can run a hijack this file that a friend downloaded to cd on another pc for me but i have no idea what to do with it and how to resolve any problems it may show.

    i have not posted a log on here for you(as stated in the forum guide) but i can upon request.

    could some body please help me out here as i am completely lost now.

    i have tried getting other programs on cd but i get errors and am unable to install them so i dont think this is an option unless you guy/gals know differently.
     
    Last edited: Jun 3, 2005
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: major trojan/spyware problem.

    You should have just remained in your first thread. Posting additional threads for the same problem just delays you further from getting help and clutters up the threads. I'm merging you back into your first thread.

    Note you do not have an HSA or about:blank hijack of any form so I don't know why you looked at the Generic Solution at all.

    Did you run the READ ME FIRST steps in safe mode?

    By the way the Administrator account normally does exist and shows when you boot in safe mode.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: major trojan/spyware problem.

    Your original HJT log was not supposed to be posted unless requested and it should only be posted as an attachment to your message. Also you are running HJT incorrectly and you did not exit all your browsers before running HJT. Below are the steps for installing and using HJT; however there were no real problems indicated in your previous log. Please explain your exact problem with more detail.

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  8. adamf

    adamf Private E-2

    Re: trojan-virus infection

    hi many thx for your replies and can i once again apologize for the mess i am making of this (i am sure you get frustrated by this all the time).

    i have some additional information that may help you advise me on my next steps.

    i have manged to download and run AVG free antivirus and the results showed that my C:\windows\system32\winsi.exe was completely infected with:
    backdoor IRC SDbot155.5
    backdoor small 31.AE
    backdoor SDbot174.P
    backdoor small 27 AQ

    please note this IS NOT a full scan as the scan crashed and i am unable to get it to finish.

    one reason for this is maybe? that i was quarantining the files as they showed up and a pop up came up saying windows must shut down and crashed everything then rebooted (i assume this is the work of the infection).

    could some1 please advise me as to my next step?

    if i remove or attempt to remove(as i woudlnt know how to do it) all these registry items how would i replace them?

    it appears as though my original windows is infected with this so a system reload isnt an option unless i go and buy a new windows apllication (xp home etc).

    if i let avg run and delete all the infected registries what will happen?
    is there a way to download/save a new registry?

    regarding a hijack this log do you still want me to provide 1?

    yes i did run the read me first steps in safe mode!
     
  9. adamf

    adamf Private E-2

    Re: trojan-virus infection

    hi further progress made but the more i make the more confused i get.

    i have at last manged to run the omline scans in safe mode (with network support) i think i couldnt do that initially because the system wa crashing with so many errors.

    the position now is this!

    all other scans clear except syamntec online:

    this detects:
    1) system32 PIF download.trojan
    2)system32 TFTP248 W32 IRc bot gen
    3)system 32 winsci.exe w32 spybot.worm


    also when i run spybot (updated of course) it detects and supposedly fixes 5 DSO exploits: HKEY-users\5-1-5-18 5-1-5-19 5-1-5-20

    HKEy users\default\software\microsoft

    hkeyusers\5-1-5-21-725345543-82318204-83

    they are all noted as registry changes.

    everytime spybot detects and then fixes these and then i re-scan they are back again........even if i reboot or whatever.

    all other programs such as mcafee avert etc as on ur self help section run clean.

    i hope this information helps i will now reboot my pc and run the hijack this test and post the results.
     
  10. adamf

    adamf Private E-2

    Re: trojan-virus infection

    hijack this log attached.............


    sorry it means nothing to me but i guess it tells you folks what you need to know.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: trojan-virus infection

    The main reason for your problems is that your OS and IE versions are way out of date. After we fix your current problems, you MUST update your system.


    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Hardware Clock Driver or hwclock ... right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Hardware Clock Driver

    Or if that does not work, use the short name: hwclock

    Do not reboot if you are told a reboot is required to complete. Now exit HijackThis.

    After completing the above, move on to my next message.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: trojan-virus infection

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).

    Please run HijackThis and click on the "Open the Misc Tools Section" button on the open page. Then select "Open process manager" on the left-hand side. Look for the following process (or processes) and one at a time kill them by selecting it and then click "Kill process". Then click yes.
    C:\WINDOWS\System32\wincrs.exe
    C:\WINDOWS\System32\asdhuf.exe
    C:\WINDOWS\System32\winsci.exe


    After killing all the above processes, click "Back".
    Then please click "Scan" and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O4 - HKLM\..\Run: [ICQ Chat Service] icqjdhs.exe
    O4 - HKLM\..\Run: [Seghe Personal Firewall] asdhuf.exe
    O4 - HKLM\..\Run: [Window_Protect] winsi32.exe
    O4 - HKLM\..\Run: [Microsoft Crs Fix Serv] wincrs.exe
    O4 - HKLM\..\Run: [System Updates] winsci.exe
    O4 - HKLM\..\RunServices: [ICQ Chat Service] icqjdhs.exe
    O4 - HKLM\..\RunServices: [Seghe Personal Firewall] asdhuf.exe
    O4 - HKLM\..\RunServices: [Window_Protect] winsi32.exe
    O4 - HKLM\..\RunServices: [Microsoft Crs Fix Serv] wincrs.exe
    O4 - HKLM\..\RunServices: [System Updates] winsci.exe
    O4 - HKCU\..\Run: [Microsoft Crs Fix Serv] wincrs.exe
    O4 - HKCU\..\Run: [Seghe Personal Firewall] asdhuf.exe
    O4 - HKCU\..\Run: [System Updates] winsci.exe
    O4 - HKCU\..\RunServices: [System Updates] winsci.exe
    O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)

    After clicking Fix, exit HJT.

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\System32\wincrs.exe
    C:\WINDOWS\System32\asdhuf.exe
    C:\WINDOWS\System32\winsci.exe
    C:\WINDOWS\System32\icqjdhs.exe
    C:\WINDOWS\System32\winsi32.exe
    C:\WINDOWS\System32\hwclock.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now run Ccleaner (installed while running the READ ME FIRST). Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  13. adamf

    adamf Private E-2

    hi,attached is new hijack this log.

    there were a couple of things i should tell you (i guess) about how it went.

    i followed your instructions EXACTLY but:

    the hardware clock was hwclock (as u said)
    after killing the processes 023-service hardware clock driver(hwclock)-etc

    wasnt there!!!

    and in safe mode using windows explorer to delete.

    the first 3 were there but C:\windows\system32\icqjdhs.exe winsi32.exe or hwclock.exe also were not there!!!

    everything else was exactly as u predicted.
    i dont know if previuos scans actions.had already removed these or if they are hiding somewhere else?

    i did do a search of ALL the pc as well to see if i could find them but i couldnt!

    i am now going to do a symantec online scan to see if it detects anything while you folks check my new log attached.

    many thanks again!!!
     

    Attached Files:

  14. adamf

    adamf Private E-2

    Re: trojan-virus infection

    still got big problems here!

    dont know what they are!

    to re-iterate what i said yesterday..........all this started when i did a full "destructive" restore on my system so i DO NOT have ANY microsoft updates as yet.

    when i try to go to microsoft it directs me to v5 (is this correct) this is a windows xp pc? it should be later than v5 shouldnt it? i dunno?

    should i go there and download all the updates?

    i cant run a symantec scan now as it says i need IE.5 or better?????

    yet i have run them earlier?

    do i still have an infection?

    i have AVG free version installed on the pc but i havent used this product b4 so i am unsure as to the level of protection it will give me when i have no msn updates?

    and is there anything i can do about the corrupt files in my backup reload disks (which are still in the hard drive partition)

    i know some of these questions maybe for a different forum of the majorgeeks but i dont know if these problems are inter related?


    i also keep getting pop ups saying my registry is corrupt? are these trojan activity or genuine pop ups? and if so what can i do about them?


    please persevere with me geeks i am doing my best i realise its not very good but it is my best.lol


    many thanks!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: trojan-virus infection

    You must use only one antivirus application. Pick which one you want (AVG7 or Symantec) and uninstall the other.

    After doing that see the below link and complete the steps in it. The first step is Microsoft update (yes you will see a V5). If you do not want WinXP SP2 at this time (you really do need it though), you should select Custom Install and do not select the SP2 update.

    Make sure you get one of the recommended firewalls install ASAP.

    When finished post a new HJT log and let me know your status.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds