Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old March 9th, 2005, 03:14 PM
lvb lvb is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2005
Posts: 1 lvb User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 37 m 44 sec
Reputation Power: 0
Exclamation Problem with Trojan/Viruses, Malware that I can't clean off

I am having a problem with a Windows XP machine. I am unable to open up My Computer and the Control Panel. When I double click on the icon, I get an hour glass then after about 20 seconds I received a message from Dr. Watson saying there was a problem and do I want to report it. When I select “don’t report it” after about 10 more seconds, my desktop flashes and comes back but never opens up what I tried to open. There is also a problem when I start Internet explorer but I’m able to get around that my not answering the Dr. Watson message.

I have found the following Trojans on the PC…

C:\windows\system32\addqz32.exe TROJ_AGENT.RK-Uncleanable
C:\windows\system32\apipv.dll TROJ_AGENT.EL – Uncleanable
C:\windows\system32\apiwy32.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\appfg.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\appki.exe TROJ_AGENT.MP - Uncleanable
C:\windows\system32\appmi.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\appwb.exe TROJ_AGENT.RK - Uncleanable
C:\windows\system32\appyw32.exe TROJ_AGENT.SA - Uncleanable
C:\windows\system32\atlay.exe TROJ_AGENT.EL - Uncleanable
C:\windows\system32\atljj.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\amlmi32.exe TROJ_AGENT.MP - Uncleanable
C:\windows\system32\crdm.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\crdn.exe TROJ_AGENT.RK - Uncleanable
C:\windows\system32\croq.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\d3cf32.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\iebk.dll TROJ_AGENT.MP - Uncleanable
C:\windows\system32\iemn32.exe TROJ_AGENT.RK Uncleanable
C:\windows\system32\jayaay.exe TROJ_SMALL.SA Uncleanable
C:\windows\system32\javahc32.exe TROJ_AGENT.KT Uncleanable
C:\windows\system32\javaic.exe TROJ_AGENT.KT Uncleanable
C:\windows\system32\javair.exe TROJ_AGENT.KT Uncleanable
C:\windows\system32\javaik.exe TROJ_AGENT.MP Uncleanable
C:\windows\system32\javath.exe TROJ_SMALL.SA Uncleanable
C:\windows\system32\javauj32.exe TROJ_AGENT.MP Uncleanable
C:\windows\system32\javaze.exe TROJ_SMALL.SA Uncleanable
C:\windows\system32\majm32.dll TROJ_AGENT.EL Uncleanable
C:\windows\system32\netdk32.exe TROJ_AGENT.KT Uncleanable
C:\windows\system32\nethd.dll TROJ_AGENT.MP Uncleanable
C:\windows\system32\netjg32.exe TROJ_AGENT.RK Uncleanable
C:\windows\system32\netgf.dll TROJ_AGENT.EL Uncleanable
C:\windows\system32\ntjl32.exe TROJ_AGENT.MP Uncleanable
C:\windows\system32\ntrg32.dll TROJ_AGENT.MP Uncleanable
C:\windows\system32\ntue32.dll TROJ_AGENT.EL Uncleanable
C:\windows\system32\syskk.dll TROJ_AGENT.MP Uncleanable
C:\windows\system32\sysll.exe TROJ_AGENT.KT Uncleanable
C:\windows\system32\sysph32.dll TROJ_AGENT.MP Uncleanable
C:\windows\system32\winbt.exe TROJ_AGENT.RK Uncleanable
C:\windows\system32\winfr.exe TROJ_AGENT.ALL Uncleanable
C:\windows\system32\winux32.exe TROJ_AGENT.BQ Uncleanable
C:\windows\system32\winvy32.exe TROJ_AGENT.BQ Uncleanable
C:\windows\system32\winyt32.dll TROJ_AGENT.MP Uncleanable
C:\windows\system32\winzm.dll TROJ_AGENT.EL Uncleanable
C:\windows\system32\1.tmp TROJ_HIDEPROC.B . Uncleanable


Can someone tell me if my problem (which is stated above) is from the Trojans or not?

I have tried the following Norton, Trend Micro, Trojan Hunter (which flags the virus as a threat but as you can see above, they are unable to clean them)

I updated all the programs to the most current virus defs. before running.

I have to run all the programs from Safe mode since I can’t use any explorer in windows to run the programs. I have tried to manually delete the registry entries for a couple of these trojans (recommended on Trend Micro web site - followed the directions and always UNABLE to end the process) but I just receive a message saying that I am not able to delete the entry.

Can anyone out there help with my problem? What program, process, "THING" should I try next, if any?

Please advise and thank you in advance!!!!!

Reply With Quote
  #2  
Old March 9th, 2005, 04:39 PM
AsymptoticCoder AsymptoticCoder is offline
Information and Data Junkie
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2004
Location: Southern California, USA
Posts: 108 AsymptoticCoder User rank is Private First Class (20 - 50 Reputation Level)AsymptoticCoder User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 17 h 13 m 2 sec
Reputation Power: 5
Facebook
These are a pain.

My guess is that the trojans have done some damage, or may be hanging things up. Boot in safe mode and try running your antivirus progs again. Most likely the trojans are hiding in memory.

I myself am having a terrible Spyware and Trojan problem with my home system. The buggers keep reinstalling themselves!!!

Reply With Quote
  #3  
Old March 30th, 2005, 07:47 AM
davebehave davebehave is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Mar 2005
Posts: 1 davebehave User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 3 m 53 sec
Reputation Power: 0
Smile

Quote:
Originally Posted by AsymptoticCoder
These are a pain.

My guess is that the trojans have done some damage, or may be hanging things up. Boot in safe mode and try running your antivirus progs again. Most likely the trojans are hiding in memory.

I myself am having a terrible Spyware and Trojan problem with my home system. The buggers keep reinstalling themselves!!!




well have u tried the program a2squared it is very good of getting rid of trojans http://www.emsisoft.com/en/software/free/ its free

Reply With Quote
  #4  
Old April 7th, 2005, 08:30 AM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Hi lvb,

If you still need help...

Please download HijackThis. Make sure you install HijackThis to a permanent folder such as C:\HJT as it creates backups of what we will fix.

Run the program, click the button at the top "Do a system scan and save a logfile". Save the log to a convenient place such as C:\HJT Notepad will open, copy and paste the entire log into your post. Do not fix anything yet, most of what's in the log is needed!

http://www.majorgeeks.com/download3155.html

Tom
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > Problem with Trogans/Virues, Malware that I can't clean off


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 1 hosted by Hostway
Stay green...Green IT