unknown trojan on Pestpatrol problem, hijackthis

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by speedy187, Aug 16, 2004.

  1. speedy187

    speedy187 Private E-2

    scannin pest patrol yesterday, unknown trojan pops up, it stopped my regedit from opening but my task opens fine... so i renamed regedit, opened it up deleted all the registry files that pestpatrol said, tracked the main file - deleted it in safe mode, come back and its still there, deleted again, keeps comin back - not sure what to do =/ here's my hijackfiles

    hope someone can help, thanks.
     
    Last edited by a moderator: Aug 16, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to follow some guidelines. HijackThis is the last step not the first. See the stickies on the main page of the Spyware Forum.

    Please follow all the steps in this Sticky thread < READ ME FIRST: Basic Spyware, Trojan And Virus Removal > If you already have any of the programs linked in the tutorial please double check your version to make sure you have the latest one and that you have any/all updates for the programs.

    NOTE: In order to resolve the issues you are having it is very important that you at least try to perform all the steps as outlined. If you have any difficulty please post back letting us know what steps you have completed, what you found while doing the scans if anything and details about any problems you have encountered in completing the steps. The more details you can provide the better.

    NOTE: Per the tutorial in this Sticky thread < Hijack This Tutorial And How To Post Your Log File > your log file file has been removed.

    Update! Due to Hijack This logs destroying search engine and web site searches, we now ask you do not post your Hijack This log file unless requested by us. It is for advanced users, so if you do not understand how to use it, you do not need it....yet. Instead, please tell us in your post what symptoms you are experiencing so we can try and resolve it that way. When, and if, we ask you to post your log file, please attach it as a file. To do this save the log file and select manage attachments in a new thread to upload it. All running programs should be closed, including your web browser, e-mail, items in the tray, anything you can close... Close before running Hijack This!

    Do not to install Hijack This to the Desktop, a temp folder or choose run from the download. Place it in its own folder, for example C:\Program Files\HJT



    Make sure you have the proper versions for each program! Your HijackThis is out of date. It would also be more useful if you told us exactly what file it is that you are trying to delete.
     
    Last edited: Aug 16, 2004
  3. speedy187

    speedy187 Private E-2

    okay well, here's the main file name on pestpatrol - HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run|winsock2 driver
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So are you running the stuff from the links I gave to you?
     
  5. speedy187

    speedy187 Private E-2

    yah i downloaded all those different programs, ran em all and nothings been showing up but cookies - the only thing that detects the trojan is pestpatrol
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you see this process running:
    SDJOIJE.EXE

    Use Task Manager to look for it.
     
  7. speedy187

    speedy187 Private E-2

    nope, not there
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  9. speedy187

    speedy187 Private E-2

    its not letting me attach it because its a .log file says invalid -
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You must save the file as a .txt file or rename it to a .txt file. Then upload it.
     
  11. speedy187

    speedy187 Private E-2

    okay - that winsock2 driver was the same one pestpatrol told me to delete, which i did but it kept coming back.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you use AIM?
    If so, exactly where did you download it from? It appears to be the problem?
     
  13. speedy187

    speedy187 Private E-2

    I got it from the www.aim.com a while back... don't see why it would cause a problem now? This just came up on pestpatrol like 4 days ago, i've had aim on this computer for about 5 months...
     
  14. speedy187

    speedy187 Private E-2

    but i did notice under the registry when i renamed it, in the winsock2driver the name to the right is AIM - should i just try deleting aim, running it again then reinstalling?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Hmmm! Maybe there are two AIM's on your computer. A valid one and a bad one.

    Try this:

    - Make sure you do not have the real AIM running
    - run HijackThis and have it fix these lines:
    O4 - HKLM\..\Run: [Winsock2 driver] AIM.EXE
    O4 - HKCU\..\RunOnce: [Winsock2 driver] AIM.EXE
    Now boot in safe mode: http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam
    Enable viewing of hidden files and folders: http://forums.majorgeeks.com/showthread.php?t=37650

    Now use Windows Explorer to locate and delete:
    C:\WINDOWS\System32\AIM.EXE

    Now reboot normal and tell me how things are working.
     
  16. speedy187

    speedy187 Private E-2

    weird... i restart and it still shows up on pestpatrol... but now my regedit opens... aim still works but it still shows up under same winsock file in regedit, and the winsockdriver is still in the regedit, try rebooting in safemode and deleting the winsockdriver in the regedit?
     
  17. speedy187

    speedy187 Private E-2

    okay the aim file showed up again once i rebooted on hijack, i just deleted it while computer was on and ran pestpatrol again - let me reboot and see if it comes back
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Were you able to delete the c:\windows\system32\aim.exe file or did you get an error?

    Also have HijackThis fix these lines:
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://support.charter.com/sdccommon/download/tgctlcm.cab
    O16 - DPF: {11113111-1411-1611-8111-111111111413} - mhtml:file://c:\nul.mht!http://www.capital-systems.net//browser.exe
    O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} (SurferNETWORK Plugin) - http://rd1.surfernetwork.com/surferplugin.ocx
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} -
    O16 - DPF: {F5192746-22D6-41BD-9D2D-1E75D14FBD3C} - http://download.rfwnad.com/cab/crack.CAB

    Then give me a new HJT log attachment.
     
  19. speedy187

    speedy187 Private E-2

    well i just deleted it on the hijack again, the pestpatrol didn't show a trojan anymore - the registry opens, aim works and i deleted the file easily on safe mode, should i still delete those you just put on there in hijack?? thanks alot.
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, have HijackThis fix the O16 lines.

    Have you rebooted a couple time to make sure the bogus AIM.EXE is really gone?
     
  21. speedy187

    speedy187 Private E-2

    ya this was my 3rd reboot, and deleted the 016 everything looks good for now, if anything comes up i'll let you knoww - appreciate it
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problem! Happy surfing!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds