Welcome, Guest. Please Login or Register.
Search
Members
Login
Register
   Mischel Internet Security Forum
   Malware
   Adware, Browser Hijackers and other Malware
(Moderators: Helena, Gavin_Coe, Magnus)
   TrojanDownloader i cAn not get this out
« Previous topic | Next topic »
Pages: 1 2 3  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: TrojanDownloader i cAn not get this out  (Read 3804 times)
Thomas
Full Member
***






   


Gender: male
Posts: 233
TrojanDownloader i cAn not get this out
« on: Jul 25th, 2008, 3:42pm »
Quote Quote  Modify Modify

my spyware doctor and trojanhunter will not pick up TrojanDownloader here is my hijackthis log
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:31:40 PM, on 7/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
 
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Registry Mechanic\RegMech.exe
C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US& amp;c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405&bd=presario&pf=desktop&parm1=seconduser
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_U S&c=Q405&bd=presario&pf=desktop&parm1=seconduser
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 5.0\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
O4 - HKCU\..\Run: [Y!TunnelPro] C:\Program Files\Digital Asphyxia\Y!TunnelPro 2.5\YTPro.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca, C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca, C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32 /activex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/cli ent/muweb_site.cab?1216907773656
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
 
--
End of file - 5878 bytes
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: TrojanDownloader i cAn not get this out
« Reply #1 on: Jul 25th, 2008, 10:55pm »
Quote Quote  Modify Modify

Your Hijackthis log is not showing any infection.
 
What is the name of the file that is being detected as a trojan?
 
What security program is flagging the above file as a trojan?
 
What is the name of the trojan that the above program is calling the file?
 
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: TrojanDownloader i cAn not get this out
« Reply #2 on: Sep 22nd, 2008, 4:35am »
Quote Quote  Modify Modify

on Jul 25th, 2008, 10:55pm, siliconman01 wrote:
Your Hijackthis log is not showing any infection.
 
What is the name of the file that is being detected as a trojan?
 
What security program is flagging the above file as a trojan?
 
What is the name of the trojan that the above program is calling the file?
 

 
http://img150.imageshack.us/my.php?image=78389579lf0.jpg
 
everytime i do a trojanhunter scan those come up everytime
 
and i thought it said trojandownloader but i was wrong
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: TrojanDownloader i cAn not get this out
« Reply #3 on: Sep 22nd, 2008, 5:50am »
Quote Quote  Modify Modify

It looks to me like there is some type of conflict going on between TrojanHunter and Spyware Doctor....probably during the time with TrojanHunter scanner is unpacking archives or compressed files.  Your Spyware Doctor pic is showing that 0 files are being quarantined which seems a bit strange.  
 
If you temporarily disable Spyware Doctor before doing the TrojanHunter scan, does TH detect any infections via its scanner?  
 
Also, reboot your computer into SAFE MODE and run a TrojanHunter FULL SCAN.  Let it quarantine anything it finds.
 
If you temporarily disable TrojanHunter Guard before doing a Spyware Doctor scan, does Spyware Doctor detect any infections during a Spyware Doctor scan.
« Last Edit: Sep 22nd, 2008, 5:53am by siliconman01 » IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: TrojanDownloader i cAn not get this out
« Reply #4 on: Sep 22nd, 2008, 7:52am »
Quote Quote  Modify Modify

on Sep 22nd, 2008, 5:50am, siliconman01 wrote:
It looks to me like there is some type of conflict going on between TrojanHunter and Spyware Doctor....probably during the time with TrojanHunter scanner is unpacking archives or compressed files.  Your Spyware Doctor pic is showing that 0 files are being quarantined which seems a bit strange.  
 
If you temporarily disable Spyware Doctor before doing the TrojanHunter scan, does TH detect any infections via its scanner?  
 
Also, reboot your computer into SAFE MODE and run a TrojanHunter FULL SCAN.  Let it quarantine anything it finds.
 
If you temporarily disable TrojanHunter Guard before doing a Spyware Doctor scan, does Spyware Doctor detect any infections during a Spyware Doctor scan.

 
yea cookies but that it
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: TrojanDownloader i cAn not get this out
« Reply #5 on: Sep 23rd, 2008, 12:51am »
Quote Quote  Modify Modify

Quote:
yea cookies but that it

 
I assume that you mean Spyware Doctor is only detecting cookies.  Correct?
 
TrojanHunter scans clean when you temporarily disable Spyware Doctor?  Correct?
 
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: TrojanDownloader i cAn not get this out
« Reply #6 on: Sep 23rd, 2008, 5:19am »
Quote Quote  Modify Modify

on Sep 23rd, 2008, 12:51am, siliconman01 wrote:

 
I assume that you mean Spyware Doctor is only detecting cookies.  Correct?
 
TrojanHunter scans clean when you temporarily disable Spyware Doctor?  Correct?
 

 
have not tryed it yet
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: TrojanDownloader i cAn not get this out
« Reply #7 on: Sep 25th, 2008, 8:01am »
Quote Quote  Modify Modify

on Sep 23rd, 2008, 12:51am, siliconman01 wrote:

 
I assume that you mean Spyware Doctor is only detecting cookies.  Correct?
 
TrojanHunter scans clean when you temporarily disable Spyware Doctor?  Correct?
 

 
i done a trojanhunter scan without spyware doctor install on my pc in safe mode i have no trojans and that
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: TrojanDownloader i cAn not get this out
« Reply #8 on: Sep 25th, 2008, 1:00pm »
Quote Quote  Modify Modify

Referencing your pic at the link below, can you tell me the file or files names that are getting flagged by Spyware Doctor when you scan with TrojanHunter?  The pic shows a name for the infection, but it does not show the actual file name that is supposed infected.
 
http://img150.imageshack.us/my.php?image=78389579lf0.jpg
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: TrojanDownloader i cAn not get this out
« Reply #9 on: Sep 26th, 2008, 2:52am »
Quote Quote  Modify Modify

on Sep 25th, 2008, 1:00pm, siliconman01 wrote:
Referencing your pic at the link below, can you tell me the file or files names that are getting flagged by Spyware Doctor when you scan with TrojanHunter?  The pic shows a name for the infection, but it does not show the actual file name that is supposed infected.
 
http://img150.imageshack.us/my.php?image=78389579lf0.jpg

 
those r it everytime i scan those pop up
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: TrojanDownloader i cAn not get this out
« Reply #10 on: Sep 26th, 2008, 3:35am »
Quote Quote  Modify Modify

But when the Spyware Doctor popup/alert window appears, does it show the file name that is supposedly infected?  
 
I assume that Spyware Doctor is asking your permission to quarantine or ignore when the popup window occurs.
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: TrojanDownloader i cAn not get this out
« Reply #11 on: Sep 26th, 2008, 11:53am »
Quote Quote  Modify Modify

on Sep 26th, 2008, 3:35am, siliconman01 wrote:
But when the Spyware Doctor popup/alert window appears, does it show the file name that is supposedly infected?  
 
I assume that Spyware Doctor is asking your permission to block or allow when the popup window occurs.

 
yes
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: TrojanDownloader i cAn not get this out
« Reply #12 on: Sep 27th, 2008, 12:10am »
Quote Quote  Modify Modify

Quote:
yes

 
Does "Yes" refer to the first part of the question?  Does the popup alert give the file name(s)?  If so, please post them back here so that I can see what files they are.
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Thomas
Full Member
***






   


Gender: male
Posts: 233
Re: TrojanDownloader i cAn not get this out
« Reply #13 on: Sep 27th, 2008, 1:14am »
Quote Quote  Modify Modify

on Sep 27th, 2008, 12:10am, siliconman01 wrote:

 
Does "Yes" refer to the first part of the question?  Does the popup alert give the file name(s)?  If so, please post them back here so that I can see what files they are.  

 
it on the screenshot
IP Logged

Windows 7 Home Premium (64 Bit)
Yahoo! Messenger Version 11.0.0 Build 2014
Y!TunnelPro Version 2.6 Build 736
YTK Enhanced Version 2.6 Build 108
Mozilla Firefox Version 8.0 (Beta)
Internet Explorer Version 9.0.8112.16421
TrojanHunter Version 5.3 Build 994
HijackThis Version 2.0 Build 4
Wireless
avast! Free Antivirus
Malwarebytes' Anti-Malware
SUPERAntiSpyware Professional
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 7358
Re: TrojanDownloader i cAn not get this out
« Reply #14 on: Sep 27th, 2008, 1:43am »
Quote Quote  Modify Modify

I see the "Threat Name" on the screen shot, but that is not the name of the program file that is supposedly infected with the "Threat Name".  
 
I am trying to obtain the name of the file on your computer that, according to Spyware Doctor, is infected with the "Threat Name".
IP Logged

______
TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
Pages: 1 2 3  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »