Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
help evil name changing trojan that wont die!
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > help evil name changing trojan that wont die!  
Forum Quick Jump
 
New Topic Post reply to : help evil name changing trojan that wont die! Printable version of : help evil name changing trojan that wont die!
[ << Previous Thread | Next Thread >> ]

mrcellophane
New Member


Date Joined Nov 2004
Total Posts : 2
 
   Posted 11-11-2004 7:04 (GMT +1)    Quote: help evil name changing trojan that wont die!Alert an admin about: help evil name changing trojan that wont die!
Hi, i think ive got a trojan on my pc. every time i start a new program ad-aware opens a window to say my start section is changing and blocks it. the name of the exe involved randomly changes q0491.exe, h10np.exe, bwtu5.exe, etc. I find and delete the programmes from the system 32 folder, and have deleted the RunOnce keys from local machine and current user in the registry, and have run updated versions of spybot, adaware, zone alarm antivirus, and trojan hunter. all of which say im clean. the programs open a new version with every programme i run, eg internet explorer, but doesnt seem to do anything. zone alarm stops them from connecting, but its driving me MAD.
please help!!!
 
below is a log from hijack this that i think im supposed to include? i have no idea if this is the right thing.
thanks in advance
 
Logfile of HijackThis v1.98.2
Scan saved at 18:02:44, on 11/11/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ZoneLabs\isafe.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Accessories\ZAP\ZoneAlarm\zlclient.exe
C:\Program Files\Accessories\Ad-aware 6\Ad-watch.exe
C:\Program Files\accessories\ati\rage3d\rage3dtweak\gameutil.exe
C:\Program Files\Accessories\Wireless Lan\WLANPRO.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Accessories\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.firenet.uk.net/search.asp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.firenet.uk.net/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Accessories\Adobe\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\ACCESS~2\Spybot\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {A3E9059A-4253-4912-9585-878782F24B80} - C:\WINDOWS\system32\ijm1m.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Accessories\ZAP\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [Ad-watch] C:\Program Files\Accessories\Ad-aware 6\Ad-watch.exe
O4 - Global Startup: gameutil.exe.lnk = ?
O4 - Global Startup: X-Micro WLAN 11g Adapter Configuration Utility.lnk = ?
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Accessories\yahoo\yhexbmes0411.dll (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Accessories\yahoo\yhexbmes0411.dll (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.firenet.uk.net/
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.133/dl/adv68/x.chm::/load.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} - file://c:\explorer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B4BFD54C-16A4-43E5-B85E-2C9246A1CEFE}: NameServer = 192.168.1.1
O21 - SSODL: System - {367E58EF-B2B0-4140-8D59-EB1A4F46D8E0} - C:\WINDOWS\system32\system32.dll
Back to Top
 

mrcellophane
New Member


Date Joined Nov 2004
Total Posts : 2
 
   Posted 11-12-2004 11:53 (GMT +1)    Quote: help evil name changing trojan that wont die!Alert an admin about: help evil name changing trojan that wont die!
Ive run CWshredder and it found some cws things and deleted them, but the problem is still there. can nobody help please? confused
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 13594
 
   Posted 11-12-2004 12:26 (GMT +1)    Quote: help evil name changing trojan that wont die!Alert an admin about: help evil name changing trojan that wont die!
Heysmilewinkgrin
Disable DCOM: http://grc.com/dcom/
 
Scan with Hijacktis, close all other windows, put a checkmark to these, and fix:
O2 - BHO: (no name) - {A3E9059A-4253-4912-9585-878782F24B80} - C:\WINDOWS\system32\ijm1m.dll
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.133/dl/adv68/x.chm::/load.exe
O16 - DPF: {11111111-1111-1111-1111-111111113457} -
file://c:\explorer.cab
O21 - SSODL: System - {367E58EF-B2B0-4140-8D59-EB1A4F46D8E0} - C:\WINDOWS\system32\system32.dll
 
Reboot into Safe Mode (hit F8 key until menu shows up).
Find and delete:
C:\WINDOWS\system32\ijm1m.dll
C:\WINDOWS\system32\system32.dll
Reboot.
Check for updates for Windows and Internet Explorer . Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/
Post  new log. Improvements?


Touch
Back to Top
 
New Topic Post reply to : help evil name changing trojan that wont die! Printable version of : help evil name changing trojan that wont die!
 
Forum Information
Currently it is Thursday, November 20, 2008 5:12 PM (GMT +1)
There are a total of 63.934 posts in 15.821 threads.
In the last 3 days there were 33 new threads and 157 reply posts. View Active Threads
Who's Online
This forum has 27177 registered members. Please welcome our newest member, fillon.
58 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Malware.Trace / Trojan.Vundo - PLEASE HELP CAN'T REMOVE!! (4)20-11-2008 15:38:00 (patel121)
Redirecting problems (4)20-11-2008 15:20:37 (james115511)
Performance dive (8)20-11-2008 13:25:02 (Mort)
Win 32-trojan-gen (13)20-11-2008 12:16:45 (Touch)
Generic.PWS.WoW.B7078E0 (12)20-11-2008 11:22:12 (Behram)