Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Tired of the Trojan-gen UPX virus
   
BullGuard Antivirus Forum > Virus > Alerts & New Threats > Tired of the Trojan-gen UPX virus  
Forum Quick Jump
 
New Topic Post reply to : Tired of the Trojan-gen UPX virus Printable version of : Tired of the Trojan-gen UPX virus
[ << Previous Thread | Next Thread >> ]

mufika
New Member


Date Joined Mar 2005
Total Posts : 1
 
   Posted 3-25-2005 9:46 (GMT +2)    Quote: Tired of the Trojan-gen UPX virusAlert an admin about: Tired of the Trojan-gen UPX virus
Haz there my name is Marinka and Im from Slovenia...
.... i wrote this topic with the hope, that somebody can helps me.

I got a lot of problems with the win32Trojan-gen wirus. The wirus has been already discused.
There are thise files that are cosing truble Dload.exe and 125788.exe-links to a webside.
I tried anzthin i could find on this forum but with no succes.If i remove those files they apear again!!!

Hire is mY hijack this log!
Logfile of HijackThis v1.99.1
Scan saved at 20:43:30, on 25.3.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\pd7.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\SECURITy\FIRE FOX\firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\SECURITy\HJT\hijackthis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL
O2 - BHO: IEPlus Filter - {C97EAD04-D1D3-4580-BDAC-EB13B6CB176E} - C:\WINDOWS\fonts\font.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{EEA8C539-852E-4FC7-9528-6C9B352707E6}: NameServer = 213.161.0.10,213.161.0.20
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe"
/service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)

Can somebody help me
Best regards from Slovenia
Back to Top
 

Andrei M
Senior Member




Date Joined Jan 2005
Total Posts : 570
 
   Posted 3-28-2005 8:35 (GMT +2)    Quote: Tired of the Trojan-gen UPX virusAlert an admin about: Tired of the Trojan-gen UPX virus
Hello Marinka,


I have examined your HIJACKTHIS log and this is what you need to do in order to remove the threats on your computer:

Disable System Restore, >instructions here on how to do that<

Go to the following web addresses and download:

Dr Delete >from here< and extract it into a folder of your choice.

TDS3 >from here<, and update it by following the instructions >here<

Spybot S&D >from here<, also update it.

-------------------
After downloading these, please restart your computer in Safe Mode: if you do not know how to do that, please follow the >instructions available online here<.


Open My Computer >Tools >Folder Options >View >CHECK "Show hidden files and folders",
UNCHECK "Hide protected operating system files" and then click Ok.


Then run HIJACKTHIS again, press the Do a system scan only button and place a checkmark next to the following infected items, to fix them later:

O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL
O2 - BHO: IEPlus Filter - {C97EAD04-D1D3-4580-BDAC-EB13B6CB176E} - C:\WINDOWS\fonts\font.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)


After you have checked all of these items, please press the FIX CHECKED button in HIJACKTHIS, to fix these infected entries.

Open Dr Delete which you have downloaded and use it to find and remove the following infected files:

C:\WINDOWS\system32\pd7.exe
C:\PROGRA~1\INSTAF~1\instaf~1.dll
Dload.exe
125788.exe

The last two you can be usually found in C:\Windows\System, but just to be sure of their location, you can perform a manual search on these files. Please delete them with Dr Delete when you find them.

Now remove completely this folder:
C:\PROGRA~1\INSTAF~1\ (C:\Program Files\Instafinder\)

Now run the scanners:

TDS-3 - Please start TDS-3, wait until it has fully initialised, press the System Testing button, then choose Full System Scan.
Spybot S&D - click on the Immunize button. Then "Scan System" button. Next, close all Internet Explorer windows, and click - Check for Problems. Once the scan is complete, have SpyBot remove all it finds marked in RED.

Open My Computer >Tools >Folder Options >View >CHECK "Do not show hidden files and folders",
CHECK "Hide protected operating system files" and then click Ok.

Restart your computer to exit the Safe Mode, visit >windows update< to see if you need any critical windows security updates, and tell me how are things going now?

If all is OK, you can re-enable System Restore. If my advices have not helped in any way, please post a fresh HIJACKTHIS log and we will continue with the disinfection.


Best regards,

Andrei Marius Cristof
BullGuard Support Team
support@bullguard.com
>BullGuard Website<


Suspect any spyware/adware? Download >hijackthis< and post the log file it creates.
Also don't forget to test >the free 60days Bullguard trial<.

Post Edited (Andrei) : 3/28/2005 6:43:34 AM GMT

Back to Top
 
New Topic Post reply to : Tired of the Trojan-gen UPX virus Printable version of : Tired of the Trojan-gen UPX virus
 
Forum Information
Currently it is Monday, May 21, 2012 11:42 PM (GMT +2)
There are a total of 82.921 posts in 18.688 threads.
In the last 3 days there were 2 new threads and 3 reply posts. View Active Threads
Who's Online
This forum has 33970 registered members. Please welcome our newest member, JohnKWagner.
33 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
BullGuard Support Hijacked :) (0)21-05-2012 19:36:34 (Andreea-Luciana Ostache)
Empty tmp folders (14)21-05-2012 19:31:13 (Andreea-Luciana Ostache)
Bogus BullGuard Websites (0)21-05-2012 14:37:08 (Robert Mateescu)
Multiple Virus Issues (7)19-05-2012 15:44:59 (Touch)