trojan removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by baseball43v3r, May 29, 2006.

  1. baseball43v3r

    baseball43v3r Private E-2

    my computer was acting up and when i checked the task manager it showed iexplore.exe using insanely high amounts of cpu and mem usage and so i figured i had a virus since i dont use internet explorer and so i ran spybot and nothing came up and then i ran avg antivirus and it told me i had a trojan "proxy.bh" but it couldn't get rid of it. i came to visit here and i read the sticky and ran some of the other programs and the virus didn't show up on them. i included the hijack this file as i already ran through pretty much everything else, i restarted in safe mode and ran a few of the viral removal programs but still no luck and i cant do a system restore as everytime i try as it gives me an exception has occured error. any advice and help would be greatly appreciated
     

    Attached Files:

  2. baseball43v3r

    baseball43v3r Private E-2

    ps. before you post the link to the guide i followed the steps in that as well. the internet searches turned up nothing. in fact, the internet searching removal tools did nothing at all... it ran most of it then all of a sudden cut out. the only programs i didn't run out of the guide were the ones for wins 95/98. i have a relatively new computer (albeit the files are old) and if you need any more information just ask. also another sympton i just noticed is an iexplorer browser opening at random.
     
  3. baseball43v3r

    baseball43v3r Private E-2

    ran adaware and found out it was win32.p2p-worm.alcan.a. i used the bfu as suggested in another website with the p2pnetwork.somethingorother and still no luck basically all this worm is doing is hogging resources and i can't figure out how to fix it. any help is appreciated.
     
  4. baseball43v3r

    baseball43v3r Private E-2

    ok the p2pnetwork.bfu isn't on any sites and i realized the script just simply didn't run. if anyone has any fresh idea's i'd appreciate it. i also have the winPFind file id anyone needs it as well.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry but you HJT log indicates you did not run ALL of the READ & RUN ME.

    You did not run Windows Defender and you did not run the two online scanners based upon your HJT log. You also did not uninstall Viewpoint Toolbar as per step 0.

    I find it unlikely that Panda found nothing. It almost always reports something, even though it could just be reporting cookies. Please attach the two logs that shows what they found.

    You also did not follow the directions in step 7 for installing HijackThis correctly. You have it here:
    C:\Documents and Settings\john cashion\Local Settings\Temp\wzbf26\HijackThis.exe

    That is exactly where step 7 specifies not to install it.


    Also if you clicked on the links as requested in the READ & RUN ME you would have seen Alcan.a Removal in the Special Removal procedures link. If you have Alcan.a problems you should run this.


    So please do the below in the order listed.
    - run step 0 of the READ ME
    - run Windows Defenfer
    - run the online scans and attach the two logs
    - install HijackThis properly and attach a new log.
     
    Last edited: May 30, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds