Results 1 to 16 of 16

Thread: HELP!!! Trojan alert

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Basileos Leandros I's Avatar Writing is an art
    Join Date
    May 2005
    Location
    High up in the mountains, in my own fortress
    Posts
    7,586

    Icon4 HELP!!! Trojan alert

    This thing kinda shocked me, since it's definitely a totally unpleasant surprise.
    I barely started Windows, and in about 1 minute, my NOD32 pops in, saying it found a trojan:

    Win32/TrojanDropper.Agent.NDN Trojan

    5 files have been deleted by me. It says this occured while accessing: WINDOWS/Explorer.exe(1) and YahooMessenger.exe(4).

    Now, the thing which shocked me, was when I found 5 minutes later that one of my friends got his mobo fried because of another trojan.

    NDM.Trojanb

    Now, what action should I take? How dangerous are these trojans?

    *later*
    I received another 4 messages, and "Insert XP Professional Disc" - something to recognise some files.

    Yelp!! Help pleasE?
    Ja mata, TosaInu. Forever remembered.

    Total War Org - https://forums.totalwar.org/vb/

    Swords Made of Letters - 1938. The war is looming over France - and Alexandre Reythier does not have much time left to protect his country. A finished novel, published on TWC.

    Visit ROMANIA! A land of beauty and culture!

  2. #2
    KALI's Avatar Senator
    Join Date
    Feb 2005
    Location
    Here and there
    Posts
    1,054

    Default Re: HELP!!! Trojan alert

    Try doing a search on the web for more info on the specific Trojan you've identified. There will be advice on how lethal it is, how to get rid of it and how to prevent similar attacks. But as usual be wary when downloading anything even from a site claiming to offer anti virus programmes. Try to use legit sites.
    Btw not all trojans are motherboard busters, some simply install browser trackers and other spyware. But you don't really want those on your system either. I've had many Trojans attempt to instal programmes or succesfully instal themselves....but have successfully removed all to date.
    A cold re-boot followed by lots of different anti spyware tests usually reveals the culprit.
    Last edited by KALI; December 29, 2006 at 05:33 AM.
    I came, I saw, I went away again.


  3. #3

    Default Re: HELP!!! Trojan alert

    Try http://www.pctools.com/spyware-docto...=google_trojan.

    Do you have McAfee or Norton, or anything? Also, a System Restore could probably help - bring back your deleted files and take away the trojan.

  4. #4
    Civitate
    Join Date
    Jul 2005
    Location
    Scotland
    Posts
    13,565

    Default Re: HELP!!! Trojan alert

    Do a HighKackThis scan, and post the log file here. DO NOT DO A SYSTEM RESTORE! Run Hijackthis, post the log file here (and prefereably some tech/anti virus forum), then read that log file, read it again, make sure you know what everything is, google ANYTHING that you dont recognise! Also, some malware will use trick names, such as schost, scvhost etc, they look liek they say svchost which is prefectly legit and on all computers. double check that all the important system tasks are spelt right, this is a common way of decieving the user into clicking them or ignoring them.
    Under the patronage of Rhah and brother of eventhorizen.

  5. #5

    Default Re: HELP!!! Trojan alert

    Why not do a system restore? It worked for me when I got a crazy virus.

  6. #6
    Primicerius
    Join Date
    Apr 2006
    Location
    60,11 N 24,55 E
    Posts
    3,575

    Default Re: HELP!!! Trojan alert

    Yea, I deleted a trojan yesterday with system restore.

  7. #7
    Civitate
    Join Date
    Jul 2005
    Location
    Scotland
    Posts
    13,565

    Default Re: HELP!!! Trojan alert

    Often a system restore does more long term damage than good. You are far better off just deleting the malware outright.
    Under the patronage of Rhah and brother of eventhorizen.

  8. #8

    Default Re: HELP!!! Trojan alert

    Quote Originally Posted by Shaun View Post
    Often a system restore does more long term damage than good. You are far better off just deleting the malware outright.
    What would this be?

  9. #9
    Basileos Leandros I's Avatar Writing is an art
    Join Date
    May 2005
    Location
    High up in the mountains, in my own fortress
    Posts
    7,586

    Default Re: HELP!!! Trojan alert

    I downloaded HijackThis and I'm doing a system scan now, with SpyBot. After, I'm gonna do with Spyware Doctor. Then, going with HijackThis and I'll see what's wrong.

    Here are my security settings:

    NOD32 + Zone Alarm Firewall(set on maximum security settings) + Ad Aware + SpyBot + Windows Updates.

    I update almost every component daily, and everything is on maximum. I can't believe this. And ironically, I wanted to set my proxies too that day.
    Ja mata, TosaInu. Forever remembered.

    Total War Org - https://forums.totalwar.org/vb/

    Swords Made of Letters - 1938. The war is looming over France - and Alexandre Reythier does not have much time left to protect his country. A finished novel, published on TWC.

    Visit ROMANIA! A land of beauty and culture!

  10. #10
    Basileos Leandros I's Avatar Writing is an art
    Join Date
    May 2005
    Location
    High up in the mountains, in my own fortress
    Posts
    7,586

    Default Re: HELP!!! Trojan alert

    Rip off this Spyware Doctor. Found 33 problems(weird, Ad Aware and SpyBot won't find them...) but it won't remove them. I have to register. Stupid!!!

    Now, doing an Ad Aware, then HijackThis.
    Ja mata, TosaInu. Forever remembered.

    Total War Org - https://forums.totalwar.org/vb/

    Swords Made of Letters - 1938. The war is looming over France - and Alexandre Reythier does not have much time left to protect his country. A finished novel, published on TWC.

    Visit ROMANIA! A land of beauty and culture!

  11. #11

    Default Re: HELP!!! Trojan alert

    Have you tried ewido spyware? It works well for me.

  12. #12
    Basileos Leandros I's Avatar Writing is an art
    Join Date
    May 2005
    Location
    High up in the mountains, in my own fortress
    Posts
    7,586

    Default Re: HELP!!! Trojan alert

    Noup. Never heard of it. Will give it a try.
    Here's the HijackThis log:

    Logfile of HijackThis v1.99.1
    Scan saved at 3:18:09 PM, on 12/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\ATKKBService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\Program Files\Eset\nod32krn.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Media Player\WMPNetwk.exe
    C:\WINDOWS\system32\RunDll32.exe
    C:\Program Files\Eset\nod32kui.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\System32\alg.exe
    C:\program files\steam\steam.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\PROGRA~1\SPYWAR~1\swdoctor.exe
    C:\Program Files\Azureus\Azureus.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\Documents and Settings\user\My Documents\Software\HijackThis.exe
    C:\WINDOWS\system32\HPBPRO.EXE

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ro/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
    O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
    O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
    O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
    O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {20B845BF-450F-4C1E-AF60-3CC380CDE328} (get_atlcom Class) - http://apps.corel.com/nos_dl_manager...luginNOSSO.ocx
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1150448044203
    O17 - HKLM\System\CCS\Services\Tcpip\..\{6DD57C16-25BD-4BBD-A70D-5EFFE4DD6ED2}: NameServer = 193.226.128.1,193.226.128.129
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    Nothing suspect to me. :hmmm:
    Ja mata, TosaInu. Forever remembered.

    Total War Org - https://forums.totalwar.org/vb/

    Swords Made of Letters - 1938. The war is looming over France - and Alexandre Reythier does not have much time left to protect his country. A finished novel, published on TWC.

    Visit ROMANIA! A land of beauty and culture!

  13. #13

    Default Re: HELP!!! Trojan alert

    About ewido : I just found 167 infected files, and more on the way, and I scanned a few weeks ago. It finds the most minor things, trust me, it'll help.

  14. #14
    Basileos Leandros I's Avatar Writing is an art
    Join Date
    May 2005
    Location
    High up in the mountains, in my own fortress
    Posts
    7,586

    Default Re: HELP!!! Trojan alert

    Ewido 4.0 is now AVG Anti Spyware 7.5. Downloading now...Let's hope it works.
    Ja mata, TosaInu. Forever remembered.

    Total War Org - https://forums.totalwar.org/vb/

    Swords Made of Letters - 1938. The war is looming over France - and Alexandre Reythier does not have much time left to protect his country. A finished novel, published on TWC.

    Visit ROMANIA! A land of beauty and culture!

  15. #15
    Civitate
    Join Date
    Jul 2005
    Location
    Scotland
    Posts
    13,565

    Default Re: HELP!!! Trojan alert

    Right then, have you had a good look through all of them? If you dont recognise them, google them.
    Under the patronage of Rhah and brother of eventhorizen.

  16. #16
    Basileos Leandros I's Avatar Writing is an art
    Join Date
    May 2005
    Location
    High up in the mountains, in my own fortress
    Posts
    7,586

    Default Re: HELP!!! Trojan alert

    I used the AVG Anti Spyware, found Adware of medium risk. Removed it, and so far, my system is (theoretically), back to normal.
    Ja mata, TosaInu. Forever remembered.

    Total War Org - https://forums.totalwar.org/vb/

    Swords Made of Letters - 1938. The war is looming over France - and Alexandre Reythier does not have much time left to protect his country. A finished novel, published on TWC.

    Visit ROMANIA! A land of beauty and culture!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •