Got a problem...

I've posted here a couple of times before and everyone has always been very helpful. And I'll say everytime someone has helped me my pc was better than it was before. But I still have a some kinda nagging trojan that I can't get rid of.

It is listed as...

Trojan horse BackDoor.Generic*.G** which is linked to several different files...

.exe
eraseme_*****.exe

...and...

Trojan horse IRC/BackDoor.SdBot2.LF which is linked to mainly...

eraseme_*****.exe
dllmgr64.exe

...this is according to AVG (Free Edition).

AVG catches the files and knows that they are viruses, but they keep coming back, which implies there is something else on my pc that AVG doesn't see that is attemping to put them there.

Also I've looked at my hijackthis log enough times to know that the file...

...asus.exe

shouldn't be there, somehow I think all is related.

I would love to get this thing licked once and for all and again thank you guys for all your help.

Here's my hijackthis log...


Logfile of HijackThis v1.99.1
Scan saved at 5:08:20 PM, on 8/28/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\MWW32\MANAGER\MWMDMSVC.EXE
C:\WINNT\MWW32\MANAGER\MWSSW32.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\Explorer.exe
C:\WINNT\system32\asus.exe
C:\WINNT\system32\tp4mon.exe
C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HiJack This\hijackthis.exe

F2 - REG:system.ini: Shell=Explorer.exe asus.exe
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,asus.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Modem Update Reminder] C:\WINNT\MWW32\manager\mwremind.exe autorun
O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ScreenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe -startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunServices: [Asus MotherBoard Utility] asus.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
O4 - HKCU\..\RunServices: [Asus MotherBoard Utility] asus.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ThinkPad Modem Copyright.lnk = C:\WINNT\MWW32\manager\mwcpyrt.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Google AdSense Preview Tool - http://pagead2.googlesyndication.com/pagead/preview/en/preview.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: dllmgr64 - Unknown owner - C:\WINNT\dllmgr64.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ThinkPad Modem Service (ThinkPadModemService) - IBM Corporation - C:\WINNT\MWW32\MANAGER\MWMDMSVC.EXE

Dani AI

Generated

Brief expert summary and next steps (builds on 's suggested baseline): the behaviour described — AV removing visible droppers but the files returning — strongly indicates a persistent installer/process that runs early and re-creates the payload. Removing the visible files is necessary but not sufficient; locating and disabling every autostart/persistence point and checking for hidden/rootkit components is the reliable way to stop the reinstall cycle.

Recommended complementary actions and tools:

  • Enumerate every auto-start location (not just Run keys): use Autoruns to reveal services, scheduled tasks, Winlogon/AppInit and other hidden autostarts, then note suspicious entries before disabling them. (learn.microsoft.com)
  • If a file is locked or keeps respawning, use Process Explorer to find which process has the handle open, terminate it (carefully) and then remove the file. (learn.microsoft.com)

Scan offline and check for rootkits:

  • Boot the machine from trusted rescue media and run an offline scan so the active infection can’t protect or re-drop components while tools run; a current rescue ISO is appropriate for that task. (support.kaspersky.com)

File analysis and containment:

  • Collect the suspicious binaries’ hashes and cross-check/upload them to a multi-engine scanner (VirusTotal) to confirm detections and see how many engines flag each file. Use that information to prioritize cleanup and to avoid false positives. (cisa.gov)
  • Back up user data only (documents, pictures — avoid backing up executables or program folders), disconnect the PC from the network until cleaned, and assume exposed credentials may need changing.

When to consider reinstall:

  • If persistence cannot be eliminated with the above steps, a full OS reinstall (and moving to a supported Windows release; Windows 2000 is long out of support) is the only way to guarantee removal and reduce future risk. (learn.microsoft.com)

Useful diagnostic artifacts for further help: an updated HijackThis export, an Autoruns snapshot, a Process Explorer handle snapshot, and any rootkit-scan or rescue-disk logs. These make targeted advice far more effective.

Recommended Answers

All 2 Replies

I posted this thread about 3 days ago and I haven't heard anything... just wondering if I did something incorrectly.

Scan with HJT and have it fix the following entries:

F2 - REG:system.ini: Shell=Explorer.exe asus.exe
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,asus.exe
O4 - HKLM\..\RunServices: [Asus MotherBoard Utility] asus.exe
O4 - HKCU\..\RunServices: [Asus MotherBoard Utility] asus.exe
O23 - Service: dllmgr64 - Unknown owner - C:\WINNT\dllmgr64.exe

Close ALL open browser windows and hit 'Fix Checked.'

Do searchs for asus.exe and dllmgr64.exe and delete any instances found (if any cannot be deleted, try booting into Safe Mode first).

Boot into Safe Mode and do a complete system scan with Ewido, allowing it to fix whatever it finds.

Reboot and empty your Recycle Bin (or run CCleaner if you have it).

If you're still having problems, post the Ewido log and a new HJT log.

Worms:
W32/Tilebot-ET
W32/Tilebot-CP

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.