Trojan Horse Problem.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Moto Psycho, Aug 27, 2005.

  1. Moto Psycho

    Moto Psycho Private E-2

    Hi there. Well my program files that require internet access to use have been running at half speed, so i did a scan with AVG and it picked up 7 infected files deleted em and my computer was still the same so i ran a few anti-spyware applications Spybot and Lavasoft got rid of all the spyware that showed up. After that i was just browing around clicking on random files and AVG's resident sheild pick a file up as a virus but when i tryed to scan the file it kept saying no virus detected. So i downloaded HS remover from this site and it deleted 7 files then i downloaded HiJackThis and sent the log to a site that checks it and deleted all the recommendations but yet still my computer is the same. I'v tried clicking on random files to find it but i can't seem to locate it. Please help.
     
  2. Moto Psycho

    Moto Psycho Private E-2

    these were the names of the infected files. For the people who may be familiar with the virus.

    Trojan Horse downloader.small.46.T
    Trojan Horse downloader.small.42.AR (2 files)
    Trojan Horse downloader.Agent.R (3 files)
    and 1 other. can't remember it.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  4. Moto Psycho

    Moto Psycho Private E-2

    Hi, I followed all the steps and here is my log.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I see no evidence of the RAVantivirus online scanner being run.

    You also install HJT where requested not to do so:
    C:\Documents and Settings\HP_Owner\Desktop\hijackthis\HijackThis.exe

    You also have multiple antivirus applications installed (AVG and Symantec). You must run only one. Pick the one you prefer and uninstall the other. Then reboot.

    After correcting the above and installing HJT properly. Run HJT and have it fix the below lines (make sure all browsers are closed before fixing):
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vyonw.dll/sp.html#90144
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)

    Now exit HJT.

    Now reboot again and then get a new HJT log and post it.
     
  6. Moto Psycho

    Moto Psycho Private E-2

    Ok, iv done all that but the RAVantivirus will only let me scan files and not folders.
     
  7. Moto Psycho

    Moto Psycho Private E-2

    heres the log
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must not be selecting the right thing.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What problems if any are you still having?
     
  10. Moto Psycho

    Moto Psycho Private E-2

    I got Rav to work the problem was it does n't work with firefox browser. Rav deleted one virus infected file. Heres my log.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! But answer message # 9.
     
  12. Moto Psycho

    Moto Psycho Private E-2

    ok, well all program files that require internet to run are still playing up. File sharing programs running at 1 - 2kps while downloading off 3 sources with with dsl (i have 56K). Messanger is logging itself on when the box isi n't even checked for it to do so and connecting slow. Also my online games are also running at 1-2kps. This started when the Trojan invaded my computer.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what the below means!

    What file sharing programs?
     
  14. Moto Psycho

    Moto Psycho Private E-2

    By playing up i mean not working properly, alot slower. Im using Limiewire. It does n't seem to be affecting my internet browsers though or downloading off of sites.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you saying you have a DSL connection and your contract is for 56k?

    That would not be worth paying for since the bit rate is so low. That is less then the bitrate of a standard voice line (called a DS0) which has 64kbps (analog modems can only get a maximum of 33 to 51 kbps typical on this DS0).

    You slow rates are probably due to the place you are connecting to being slow.

    Note: Older versions of Limewire contain malware too.
     
  16. Moto Psycho

    Moto Psycho Private E-2

    oh no, sorry i was downloading a file off limewire and the people i was downloading off had a DSL modem, i have a 56k modem. Iv tried to download numerous files off there and get the same low speed all the time. Online games i have use to run perfectly and now totally unplayable cause of the slowness.
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just because the people you are downloading from have DSL, it does not mean you will get fast throughput. They could be limiting download rates, they could have many people downloading from them, the server could be slow, and you analog modem could have a lousy connect rate and could have noise on the line. You should check your connect rate and also the quality of your voice line, also check your modem settings (none of this is a malware topic for this forum).

    Online games via dial-up are probably never that quick.

    You could run the below to look for any possible other hidden background problems if desired but your log is clean:

    Follow the steps below.

    - First run CCleaner before doing the below.


    - Download this trial version of Ewido Security Suite

    • Install ewido security suite
    • Launch ewido, there should be an icon on your desktop double-click it.
    • The program will have a window come up. One of the buttons on the left is to Update. Click the Update button.and then Start the Update. The update will start and a progress bar will show the updates being installed.
    • After it completes the update, click the Scanner button

    Now exit Ewido. Now print the below instructions or save them locally because I want you do have no browsers opened and also have no connection to the internet (unplug your cable) while doing the below.

    Okay, reboot into safe mode and follow the steps below. (If you have any problems at all trying to get into safe mode to complete these steps, just run them in normal boot mode and make sure you tell me when you come back.)

    Open up Ewido and do the following:


    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.

    Once the scan has completed, there will be a button located on the bottom of the screen named Save report


    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    Reboot into normal mode and reconnect to the internet.

    Come back here and post the Ewido Scan Report. And tell me if you are still having any problems. This log could get quite large and you may need to compress it into a ZIP file to upload it.


    Post this Ewido log.
     
  18. Moto Psycho

    Moto Psycho Private E-2

    Heres the report from Ewido.

    Also i forgot to say i could n't do Rav's or Bitdefenders scans while in safe mode cause my computer won't connect in safe mode. Also with bitdefender its said it was going to scan 30 000 something files but stopped pritty much half way, i tried it a couple of times and got the same result. Is this normal?

    Also after i did the ewido scan in safe mode i re did it in normal and it found another CWS file.
     

    Attached Files:

  19. Moto Psycho

    Moto Psycho Private E-2

    ah, forgot to say im still having problems.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! That remove a few other minor problems. You still should look into what I said in my last message because I do not believe your problem is malware.

     
  21. Moto Psycho

    Moto Psycho Private E-2

    My computer tells me everytime i connect its around 50 - 53kps. I also reset my modem. Honestly i dont see how something could work so well for over a month then all of a sudden become unplayable. But i have rung my ISP and they say everything is working fine of there end. Also i did get an RAM upgrade so many i burnt it out or sometihng?
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you mean "so maybe"? If your RAM was bad, you would normally have more problems then just this. How much RAM do you have?

    And are you talking about a RAM upgrade for your PC?

    Did you install anything else on the PC? Did you have any storms recently?

    When you connect here on MG's, does it seem slow?

    Try reconfiguring the parameters that initialize your modem. Or you could try uninstalling and reinstalling the modem.

    Also you can try the below to see if we can find any other malware.

    -Uninstall Ewido.
    -Download install, update, and run a scan with Spy Sweeper save and post a log from it.
     
    Last edited: Aug 29, 2005
  23. Moto Psycho

    Moto Psycho Private E-2

    Yeah i ment so maybe. Yes i upgraded it 760mb RAM from 256 RAM. It's a no to your other questions too.

    Well iv deicided to talk my computer to an "expert" and to see if he can solve the problem. If he fixes the problem do you want me to report back with his findings?

    Side note- wow after all these scans i now have an extra 5GB.
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sure I would like to know what is found.

    You should try what I gave you though (uninstall Ewido and run Spy Sweeper) . It could possibly find some other issues.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds