Virus shut off and in minutes trojans got in

Discussion in 'Malware Help (A Specialist Will Reply)' started by zephra, May 15, 2005.

  1. zephra

    zephra Private First Class

    I think trojans are getting in??
    Norton... which i will not buy again shut off in the middle of autoscanning a document.I got a ccappl error.(Norton error).Which shut down autodetect.
    As soon as that happened I got a Warning of a virus Bloodhound.exploit6(norton detected but could not remove)
    I also had a dummy class installer which removed and a Trojan Byte verify which would norton removed.
    Unplugged Cat5
    Disabled system restore
    Showed hidden files
    Booted in safe mode
    Ran Norton antivirus and nothing was found???
    Ran CW Shredder and CWS.msconf was found but it locked up cw shredder when it tried to remove it.
    Ran Adaware SE.Found 5 critical objects IE cache objects.Removed
    Ran Spybot nothing found
    Ran CW Shred again nothing was found this time.
    Booted normal back online no virus warnings as of yet
    Currently scanning with trend micro house call.
    Does this sound like a trojan???
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    After running the online scans and you still have this problem.

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. zephra

    zephra Private First Class

    Followed all of your steps.As I always do.
    Ok here is my log
     

    Attached Files:

  4. gkizzle3622

    gkizzle3622 Private E-2

    if u have a trojan, and are runnin xp try booting into safe mode with netowrkin support as the tutorial tells u to. then run http://housecall.trendmicro.com/housecall/start_corp.asp
    it found a ton of trojans and removed them for me.
    ur ebst bet is to follow the tutorial and then listen to the major geeks team guys and go from there
     
  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    zephra,

    This log appears to be from Safe Mode, If so please attach a fresh HJT log from normal mode.
     
  6. zephra

    zephra Private First Class

    Here is my log.
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HJT and have it fix the below entries, be sure you have ALL browsers closed before you click FIX.

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) -http://simcity.ea.com/play/classic/SimCityX.cab

    Your log is fairly clean, after you remove these above entries reboot and let me know what problems if any remain.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds