Im using Avast and I have these 3 trojans that wont go away Win32:Trojan-gen, VBS:Malware-gen and Win32:Agent-ZQG [Trj]
This is my hijack log:
Logfile of HijackThis v1.99.1 Scan saved at 19:28:45, on 06/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Important-> Temporarily disable your anti-virus, real-time protection before performing a scan. They can interfere with combofix or remove some of its embedded files which may cause "unpredictable results".
Go to Start->Run and copy/paste: ComboFix /snapshot and hit OK. It should run Combofix.
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
When finished, it will produce a logfile located at C:\combofix.txt.
Post the contents of that log in your next reply with a new hijackthis log.
Please copy and paste your log files. DO NOT add it as an attachment
NB. If you are using any P2P (file sharing) programs, please remove them before we clean your computer.. We do not clean logs that have P2P applications installed as this can cause reinfection during your cleaning.
ComboFix 08-07-05.1 - Adam 2008-07-06 23:35:25.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1524 [GMT -7:00] Running from: C:\Documents and Settings\Adam\Desktop\ComboFix.exe * Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 23:57:56, on 06/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal
I turned on my computer this morning, and the viruses hit again. They changed my wallpaper to a blue screen with a message in the middle saying "Warning, Spyware detected on your conputer, Install and antivirus or spyware remover to clean you computer" This message is part of the wallpaper, its not an error message. And I also get the blue screen that says "A problem has been detected in windows and needs to be shut down to prevent damage to your computer" but windows doesn't actually restart. There are three files in the windows system32 folder that are the virus and keep reappearing if they get deleted by an antivirus or spyware. They are a screensaver file called blphc9gwj0ep6p.scr, a bmp image phc9gwj0ep6p.bmp, and an application lphc9gwj0ep6p.exe. Here is also my Avast log where the viruses are always found, not sure if this will help.
06/07/2008 17:30:37 Adam 1280 Sign of "BV:Malware-gen" has been found in "C:\a.bat" file. 06/07/2008 17:30:38 Adam 1280 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt4.tmp.vbs" file. 06/07/2008 17:30:38 Adam 1280 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt4.tmp.vbs" file. 06/07/2008 17:30:46 Adam 1280 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt7.tmp" file. 06/07/2008 17:42:14 Adam 1280 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.ttE.tmp" file. 06/07/2008 17:52:27 Adam 1280 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt1F.tmp" file. 06/07/2008 19:10:05 Adam 1328 Sign of "BV:Malware-gen" has been found in "C:\a.bat" file. 06/07/2008 19:10:25 Adam 1328 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt3.tmp.vbs" file. 06/07/2008 19:10:50 Adam 1328 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt6.tmp" file. 06/07/2008 19:11:02 Adam 1328 Sign of "Win32:Agent-ZQG [Trj]" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\9YA6YNE6\td_maintor.exe\[UPX]" file. 06/07/2008 19:19:36 Adam 1328 Sign of "Win32:Agent-ZQG [Trj]" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\td_maintor.exe\[UPX]" file. 06/07/2008 19:19:43 Adam 1328 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\J1MVY3RP\l1eem.exe" file. 06/07/2008 19:19:45 Adam 1328 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\l1eem.exe" file. 06/07/2008 19:19:55 Adam 1328 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\ZEFKSM0I\syswcc32.exe" file. 06/07/2008 19:19:58 Adam 1328 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\syswcc32.exe" file. 06/07/2008 19:21:10 Adam 1328 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.ttE.tmp" file. 06/07/2008 19:21:41 Adam 1328 Sign of "Win32:Delf-KNW [Trj]" has been found in "C:\Documents and Settings\Adam\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.BIN" file. 06/07/2008 19:31:25 Adam 1328 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt14.tmp" file. 06/07/2008 20:03:55 Adam 1352 Sign of "BV:Malware-gen" has been found in "C:\a.bat" file. 06/07/2008 20:03:55 Adam 1352 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt4.tmp.vbs" file. 06/07/2008 20:03:55 Adam 1352 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt4.tmp.vbs" file. 06/07/2008 20:04:03 Adam 1352 Sign of "Win32:Delf-KNW [Trj]" has been found in "C:\Documents and Settings\Adam\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.BIN" file. 06/07/2008 20:04:18 Adam 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt7.tmp" file. 06/07/2008 20:14:31 Adam 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt1A.tmp" file. 06/07/2008 20:24:44 Adam 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt20.tmp" file. 06/07/2008 20:35:06 Adam 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt3C.tmp" file. 06/07/2008 20:45:17 Adam 1352 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt46.tmp" file. 06/07/2008 22:03:52 Adam 1380 Sign of "BV:Malware-gen" has been found in "C:\a.bat" file. 06/07/2008 22:03:52 Adam 1380 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt4.tmp.vbs" file. 06/07/2008 22:03:52 Adam 1380 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt4.tmp.vbs" file. 06/07/2008 22:04:13 Adam 1380 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt8.tmp" file. 06/07/2008 22:04:17 Adam 1380 Sign of "Win32:Delf-KNW [Trj]" has been found in "C:\Documents and Settings\Adam\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\PROCESSLIST.BIN" file. 06/07/2008 23:09:58 Adam 1376 Sign of "BV:Malware-gen" has been found in "C:\a.bat" file. 06/07/2008 23:10:14 Adam 1376 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt6.tmp.vbs" file. 06/07/2008 23:10:34 Adam 1376 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt9.tmp" file. 06/07/2008 23:10:47 Adam 1376 Sign of "Win32:Agent-ZQG [Trj]" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\td_maintor.exe\[UPX]" file. 06/07/2008 23:10:55 Adam 1376 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\ZEFKSM0I\l1eem.exe" file. 06/07/2008 23:10:58 Adam 1376 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\l1eem.exe" file. 06/07/2008 23:11:07 Adam 1376 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\J1MVY3RP\syswcc32.exe" file. 06/07/2008 23:11:10 Adam 1376 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\syswcc32.exe" file. 06/07/2008 23:20:50 Adam 1376 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.ttF.tmp" file. 06/07/2008 23:31:11 Adam 1376 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt18.tmp" file. 07/07/2008 08:23:41 Adam 1392 Sign of "BV:Malware-gen" has been found in "C:\a.bat" file. 07/07/2008 08:24:03 Adam 1392 Sign of "VBS:Malware-gen" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt3.tmp.vbs" file. 07/07/2008 08:24:38 Adam 1392 Sign of "Win32:Agent-ZQG [Trj]" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\0206GSRK\td_maintor.exe\[UPX]" file. 07/07/2008 08:24:49 Adam 1392 Sign of "Win32:Agent-ZQG [Trj]" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\td_maintor.exe\[UPX]" file. 07/07/2008 08:24:56 Adam 1392 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\9YA6YNE6\l1eem.exe" file. 07/07/2008 08:24:59 Adam 1392 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\l1eem.exe" file. 07/07/2008 08:25:04 Adam 1392 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\Adam\Local Settings\Temp\.tt6.tmp" file. 07/07/2008 08:25:24 Adam 1392 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\Documents and Settings\Adam\Local Settings\Temporary Internet Files\Content.IE5\ZEFKSM0I\syswcc32.exe" file. 07/07/2008 08:25:31 Adam 1392 Sign of "Win32:Adware-gen [Adw]" has been found in "C:\DOCUME~1\Adam\LOCALS~1\Temp\syswcc32.exe" file.
And this is another hikack log from when I turned on my computer this morning, not sure if it helps.
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 08:38:09, on 07/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal
Double click ATF-Cleaner.exe to run the program. Check the boxes to the left of: Windows Temp Current User Temp All Users Temp Temporary Internet Files Prefetch (Windows XP) only. Java Cache
Recycle Bin
NB. It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Loader technology (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Microsoft Loader technology (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Loader technology (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Windows Fax Viewer (Backdoor.Bot) -> Quarantined and deleted successfully.
Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected: (No malicious items detected)
Files Infected: C:\WINDOWS\system32\winloadtech32.exe (Backdoor.Bot) -> Delete on reboot.
And also I ran another Hijack but changed the name of the hijack.exe in case the trojans were avoiding and not showing up in the hijack log. But here it is again:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:55:18, on 07/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal
Currently it is Friday, September 05, 2008 7:15 PM (GMT +2) There are a total of 61.804 posts in 15.428 threads. In the last 3 days there were 19 new threads and 61 reply posts. View Active Threads
Who's Online
This forum has 26353 registered members. Please welcome our newest member, mysterious_. 40 Guest(s), 0 Registered Member(s) are currently online. Details