| | |
Trojan Horse - HELP PLEASE
Thread Solved |
Looks Much better!
We still have few things to do.
Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.
Step #1
You can go ahead and remove the tools we used.
Please download the OTMoveIt.
Step #2
Please open HiJackThis and scan. Check the boxes next to all the entries listed below
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [msci] "C:\DOCUME~1\Owner\LOCALS~1\Temp\2007423112541_mcinfo.exe" /insfin
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis
Step #3
Download CCleaner If you don't want the Yahoo toolbar, be sure to UNcheck that option when installing the software or update.
Instructions for using CCleaner:
Step #4
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.2. Restart your computer.
3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
System Restore will now be active again.
Step #5
Please run Panda's ActiveScan You will need to use Internet Explorer to run it.
o It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
o When download is complete, click on My Computer to start the scan
o When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the ActiveScan report
Let me know how thins are running now
We still have few things to do.
Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.
Step #1
You can go ahead and remove the tools we used.
Please download the OTMoveIt.
- Save it to your desktop.
- Please double-click OTMoveIt.exe to run it.
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
C:\WINDOWS\System32\ps.exe
C:\WINDOWS\pss
C:\WINDOWS\System32\idleserv.exe
C:\WINDOWS\System32\yrdqldwv.exe
C:\WINDOWS\System32\xxruegba.exe
C:\WINDOWS\System32\msdtc_32.exe
C:\WINDOWS\System32\user_32.dll - Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
- Click the red Moveit! button.
- Copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on your next reply.
- Close OTMoveIt
Step #2
Please open HiJackThis and scan. Check the boxes next to all the entries listed below
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [msci] "C:\DOCUME~1\Owner\LOCALS~1\Temp\2007423112541_mcinfo.exe" /insfin
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis
Step #3
Download CCleaner If you don't want the Yahoo toolbar, be sure to UNcheck that option when installing the software or update.
Instructions for using CCleaner:
- Launch CCleaner and under Options > Advanced > UNcheck "Only delete files in Windows Temp folder older than 48 hours".
- A pop up box will appear advising this process will permanently delete files from your system.
- To protect logon cookies that you wish to retain, under Options > Cookies. Select and using the arrow move those cookies to the "Cookies to keep" column.
- Then select the items you wish to clean up.
- In the Windows Tab:
- Clean all entries in the "Internet Explorer" section.
- Clean all the entries in the "Windows Explorer" section.
- Clean all entries in the "System" section.
- Clean all entries in the "Advanced" section.
- Clean any others that you choose.
- In the Applications Tab:
- Clean all in the Firefox/Mozilla section if you use it.
- Clean all in the Opera section if you use it.
- Clean Sun Java in the Internet Section.
- Please UNcheck "Utilities" (i.e., Ad-Aware, ewido and other security program logs.)
- In the Windows Tab:
- Click the "Run Cleaner" button and it will scan and clean your system.
- Click exit.
- Shutdown/restart the computer.
Step #4
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.2. Restart your computer.
3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
System Restore will now be active again.
Step #5
Please run Panda's ActiveScan You will need to use Internet Explorer to run it.
- Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
o It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
o When download is complete, click on My Computer to start the scan
o When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the ActiveScan report
Let me know how thins are running now
I also get this message from McAfee every time I reboot, not in SAFE MODE. I allow it. Should I block it?
SysemGuard Description: Monitors changes to your internet Explorer preset URLS to preven spyware or other potentially unwanted programs from changing your browser settings without your permission
Process: C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Process Name: Spy Sweeper Engine
Process Publisher: Webroot Software, Inc.
Affected Items: HKEY_USERS\S-1-5-21-194725168-951468696-4177962848-1003\Software\Microsoft\Internet Explorer\SearchUrl\
If you did not expect his change, McAfee recommends that you block it. If you expected change, allow it.
SysemGuard Description: Monitors changes to your internet Explorer preset URLS to preven spyware or other potentially unwanted programs from changing your browser settings without your permission
Process: C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Process Name: Spy Sweeper Engine
Process Publisher: Webroot Software, Inc.
Affected Items: HKEY_USERS\S-1-5-21-194725168-951468696-4177962848-1003\Software\Microsoft\Internet Explorer\SearchUrl\
If you did not expect his change, McAfee recommends that you block it. If you expected change, allow it.
I did everything up to Panda's Active Scan. I have NOT been able to do that because I cannot access Internet Explorer. I get "SErver Cannot be found." I cannot get online with Mozilla Firefox either. I CAN get online to AOL via dialup but cannot use Internet Explorer once online. For example, I type www.daniweb.com (page cannot be found). Then I tried www.daniweb.com/index (I got onto your site, but got message DANI WEB IT Discussion Community 404 Error. This page does not exist on our server.) So, it's doing something, but not quite getting there. Google, Yahoo do not come up either. BUT I clicked on "Favorites" and got a website.
I have been doing all the repair work, accessing the info via another computer, copying the files to a flash drive, then copying them onto the infected computer, and running the software and processes.
Should I copy Internet Explorer onto the infected computer? I don't want to do anything to screw up this great communication and process we've had, so I'd really appreciate your thoughts and reply. Thanks!
I have been doing all the repair work, accessing the info via another computer, copying the files to a flash drive, then copying them onto the infected computer, and running the software and processes.
Should I copy Internet Explorer onto the infected computer? I don't want to do anything to screw up this great communication and process we've had, so I'd really appreciate your thoughts and reply. Thanks!
![]() |
Similar Threads
- Trojan Horse (Viruses, Spyware and other Nasties)
- Trojan horse Downloader.VB.R (Viruses, Spyware and other Nasties)
- Help me remove Trojan horse TR/Scagent.DLL.C (Viruses, Spyware and other Nasties)
- Trojan Horse Downloader. Keenval.N (Viruses, Spyware and other Nasties)
- trojan horse backdoor. dumador. w/ HJT log (Viruses, Spyware and other Nasties)
- Trojan Horse,Download.Trojan not repaired by Norton;network doesn't function (Viruses, Spyware and other Nasties)
- trojan horse dropper.small.4.ag virus help (Viruses, Spyware and other Nasties)
- Trojan Horse Downloader.Swizzor.AA (Viruses, Spyware and other Nasties)
Other Threads in the Viruses, Spyware and other Nasties Forum
- Previous Thread: Grey area in back of Desktop Icon text!
- Next Thread: Hello
| Thread Tools | Search this Thread |
Tag cloud for Viruses, Spyware and other Nasties
acrobat adobe adware anti-malware anti-virussitesaccessissue antivirus apple attack avg backtoschoolspeech bar blackhat botnet botnets censorship china combofix commercial conficker connect control cybercrime cyberwarfare ddos education email europe exam exploit facebook fake fancheckvirus gaming gtaiv halloween herss.exe hijack hosting internet iphone logfiles malware mcafee messagelabs microsoft mobile msn nazi news obama onlinethreats paedophile panel parents patch pdf police policeprovirusmba-mblockedinternetaccess president privacy pro redirect redirecting report research rogueantivirus rootkit samhain sans scareware search security seopoisoning sites software spam spyware spywareexternalwindows7adminstratortrojans sqlinjection symantec system teen threat translate trojan unabletoaccessanti-virussites unwanted update usa virus viruses vista vulnerability war warning windows worm yahoo zero-day zeroday





