trojan help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by cskingapp, Sep 5, 2008.

  1. cskingapp

    cskingapp Private E-2

    Hello

    I got a trojan horse and i am trying to remove it but i think its still there

    when i run FIXIDDEF here is my log

    ********************************************************************************
    * *
    * FixIEDef Log *
    * Version 1.5.6.6088 *
    * *
    ********************************************************************************

    Created at 20:24:54 on Friday, September 05, 2008

    Time Zone : (GMT) Greenwich Mean Time : Dublin, Edinburgh, Lisbon, London

    Logged On User : ad

    Operating System : Microsoft® Windows Vista™ Home Premium
    OS Version : 6.0.6000
    System Langauge : English (United States)
    Keyboard Layout : English (United States)
    Processor : X86 Intel(R) Core(TM)2 Duo CPU T5450 @ 1.66GHz

    System Drive : C:\
    Windows Directory : C:\Windows
    System Directory : C:\Windows\system32

    Total Physical Memory : 2086720 KB
    Free Physical Memory : 1079256 KB
    Total Virtual Memory : 2097024 KB
    Free Virtual Memory : 2014364 KB

    Boot State : Normal boot

    --------------------------------------------------------------------------------

    !!! Files that have been deleted !!!

    C:\Program Files\Codec Pack - All In 1\DivXconfig.exe
    C:\Program Files\Codec Pack - All In 1\ac3filter.ico
    C:\Program Files\Codec Pack - All In 1\DivXSetup.ico
    C:\Program Files\Codec Pack - All In 1\dvobsub.ico
    C:\Program Files\Codec Pack - All In 1\ffdshow.ico
    C:\Program Files\Codec Pack - All In 1\g400.ico
    C:\Program Files\Codec Pack - All In 1\ie.ico
    C:\Program Files\Codec Pack - All In 1\irunin.bmp
    C:\Program Files\Codec Pack - All In 1\irunin.dat
    C:\Program Files\Codec Pack - All In 1\irunin.ini
    C:\Program Files\Codec Pack - All In 1\irunin.lng
    C:\Program Files\Codec Pack - All In 1\verze.txt
    C:\Program Files\Codec Pack - All In 1\xvid.ico
    C:\Windows\system32\tbs.dll

    --------------------------------------------------------------------------------

    !!! Directories that have been removed !!!

    C:\Program Files\Codec Pack - All In 1

    --------------------------------------------------------------------------------

    !!! Registry entries that have been removed !!!

    No malicious Registry entries found

    ================================================================================

    All Done :)

    ShadowPuterDude

    Safe Surfing!!!




    Then i ran hijackthis and here is my logg

    Logfile of HijackThis v1.99.1
    Scan saved at 20:33:08, on 05/09/2008
    Platform: Unknown Windows (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16711)

    Edit by chaslang: Inline HJT log removed. READ & RUN ME sticky not followed.


    I get messages saying win 32 trojan horse and generic 11.qtj am realy stuck, your help will be appreciated

    thanks
     
    Last edited by a moderator: Sep 5, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can run steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds