Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Tired of the Trojan-gen UPX virus
   
BullGuard Antivirus Forum > Virus > Alerts & New Threats > Tired of the Trojan-gen UPX virus  
Forum Quick Jump
 
New Topic Post reply to : Tired of the Trojan-gen UPX virus Printable version of : Tired of the Trojan-gen UPX virus
[ << Previous Thread | Next Thread >> ]

mufika
New Member


Date Joined Mar 2005
Total Posts : 1
 
   Posted 3-25-2005 8:46 (GMT +1)    Quote: Tired of the Trojan-gen UPX virusAlert an admin about: Tired of the Trojan-gen UPX virus
Haz there my name is Marinka and Im from Slovenia...
.... i wrote this topic with the hope, that somebody can helps me.

I got a lot of problems with the win32Trojan-gen wirus. The wirus has been already discused.
There are thise files that are cosing truble Dload.exe and 125788.exe-links to a webside.
I tried anzthin i could find on this forum but with no succes.If i remove those files they apear again!!!

Hire is mY hijack this log!
Logfile of HijackThis v1.99.1
Scan saved at 20:43:30, on 25.3.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\pd7.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TightVNC\WinVNC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\SECURITy\FIRE FOX\firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\SECURITy\HJT\hijackthis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL
O2 - BHO: IEPlus Filter - {C97EAD04-D1D3-4580-BDAC-EB13B6CB176E} - C:\WINDOWS\fonts\font.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\TightVNC\WinVNC.exe" -servicehelper
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O17 - HKLM\System\CCS\Services\Tcpip\..\{EEA8C539-852E-4FC7-9528-6C9B352707E6}: NameServer = 213.161.0.10,213.161.0.20
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe"
/service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)

Can somebody help me
Best regards from Slovenia
Back to Top
 

Andrei M
Forum Moderator




Date Joined Jan 2005
Total Posts : 570
 
   Posted 3-28-2005 7:35 (GMT +1)    Quote: Tired of the Trojan-gen UPX virusAlert an admin about: Tired of the Trojan-gen UPX virus
Hello Marinka,


I have examined your HIJACKTHIS log and this is what you need to do in order to remove the threats on your computer:

Disable System Restore, >instructions here on how to do that<

Go to the following web addresses and download:

Dr Delete >from here< and extract it into a folder of your choice.

TDS3 >from here<, and update it by following the instructions >here<

Spybot S&D >from here<, also update it.

-------------------
After downloading these, please restart your computer in Safe Mode: if you do not know how to do that, please follow the >instructions available online here<.


Open My Computer >Tools >Folder Options >View >CHECK "Show hidden files and folders",
UNCHECK "Hide protected operating system files" and then click Ok.


Then run HIJACKTHIS again, press the Do a system scan only button and place a checkmark next to the following infected items, to fix them later:

O2 - BHO: InstaFinderK - {4E7BD74F-2B8D-469E-90F0-F66AB581A933} - C:\PROGRA~1\INSTAF~1\INSTAF~1.DLL
O2 - BHO: IEPlus Filter - {C97EAD04-D1D3-4580-BDAC-EB13B6CB176E} - C:\WINDOWS\fonts\font.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [Windows Service] C:\WINDOWS\system32\pd7.exe
O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\TightVNC\WinVNC.exe" -service (file missing)


After you have checked all of these items, please press the FIX CHECKED button in HIJACKTHIS, to fix these infected entries.

Open Dr Delete which you have downloaded and use it to find and remove the following infected files:

C:\WINDOWS\system32\pd7.exe
C:\PROGRA~1\INSTAF~1\instaf~1.dll
Dload.exe
125788.exe

The last two you can be usually found in C:\Windows\System, but just to be sure of their location, you can perform a manual search on these files. Please delete them with Dr Delete when you find them.

Now remove completely this folder:
C:\PROGRA~1\INSTAF~1\ (C:\Program Files\Instafinder\)

Now run the scanners:

TDS-3 - Please start TDS-3, wait until it has fully initialised, press the System Testing button, then choose Full System Scan.
Spybot S&D - click on the Immunize button. Then "Scan System" button. Next, close all Internet Explorer windows, and click - Check for Problems. Once the scan is complete, have SpyBot remove all it finds marked in RED.

Open My Computer >Tools >Folder Options >View >CHECK "Do not show hidden files and folders",
CHECK "Hide protected operating system files" and then click Ok.

Restart your computer to exit the Safe Mode, visit >windows update< to see if you need any critical windows security updates, and tell me how are things going now?

If all is OK, you can re-enable System Restore. If my advices have not helped in any way, please post a fresh HIJACKTHIS log and we will continue with the disinfection.


Best regards,

Andrei Marius Cristof
BullGuard Support Team
support@bullguard.com
>BullGuard Website<


Suspect any spyware/adware? Download >hijackthis< and post the log file it creates.
Also don't forget to test >the free 60days Bullguard trial<.

Post Edited (Andrei) : 3/28/2005 6:43:34 AM GMT

Back to Top
 
New Topic Post reply to : Tired of the Trojan-gen UPX virus Printable version of : Tired of the Trojan-gen UPX virus
 
Forum Information
Currently it is Tuesday, December 02, 2008 3:07 PM (GMT +1)
There are a total of 64.504 posts in 15.907 threads.
In the last 3 days there were 18 new threads and 101 reply posts. View Active Threads
Who's Online
This forum has 27320 registered members. Please welcome our newest member, ribnitz.
48 Guest(s), 2 Registered Member(s) are currently online.  Details
Jade71, Nick-Brough
5 Latest Threads
How to get rid of this? (0)02-12-2008 13:41:46 (ah ying)
Need help with virus (10)02-12-2008 13:09:29 (Jade71)
Please help Trojan.SystemDriver found (5)02-12-2008 12:29:26 (Hilary)
Cannot connect to the internet (8)02-12-2008 12:08:33 (Nick Brough)
Need virus removal help - malwarebytes etc (4)02-12-2008 09:44:31 (Jonathan_ll)