Welcome! Register for a free account (or login) > How does it work?
|
|


Jan 21 2008, 04:11 PM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 9 Joined: 21-January 08 Member No.: 76,180 Operating System: windows xp |
hi, a couple of weeks ago i got infected with trogan dropper agent .git by a zip file that was sent by msn messenger making it look like it was an innocent message from my friend. after doing several avg scans i have lots of infected files and lots of programs wont work inc avg...i turned off my computer for a while because trying to find a cure was stressing me too much, but now is the time to sort things out! can anyone give me a helping hand?
the viruses i have (according to avg virus vault) are: trojan horse dropper agent .git trojan horse backdoor.ircbot.CQZ trojan horse backdoor.agent.pta trojan horse generic9.amqn the files/programs infected are: java, msn messenger,itunes, sony erricsson, nero, quicktime, adobe acrobat, avg, broadband medic, cyberlink power dvd, a few system 32 files because they didnt work, i've now uninstalled some of these, however kontiki\khost.exe which runs 4oD refuses to either uninstall or reinstall because it needs to use the file that avg has put in the virus vault! i have been able to reinstall avg once which seemed to make it work again, but now it says that the email scanner and resident shield isnt working, and it doesnt want to complete any updates, so i'm guessing its stll infected. it has also infected system restore files so i cant restore to before it was infected. i have done a hijack this log....posted below. i'd be very greatful for any help you can give as i'm really stuck and need to get on with my uni work! many thanks caroline Logfile of HijackThis v1.99.1 Scan saved at 21:23:46, on 21/01/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Hijackthis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5118DC72-BFD4-44AC-A0A9-421C191DBE39} - C:\WINDOWS\system32\wvuttqn.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O2 - BHO: (no name) - {F69196B4-ACB1-466C-BDBC-F0595E06F2C9} - C:\WINDOWS\system32\mljjh.dll (file missing) O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [4oD] "C:\Program Files\Kontiki\KHost.exe" -all O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.co.uk/SnapfishUKActivia.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab O16 - DPF: {A7ECD556-D6F6-4F41-8C6B-14AB246801A0} (Secure Delivery) - http://www.kontiki.ioko.com/bbcfn/kdx.cab O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab O16 - DPF: {BF6BBE9A-0656-4598-A0CD-32DAC03959B5} (Image Uploader 3.0 Control) - http://www.bootsphoto.com/wpp/boots/app/opcuploader.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O20 - Winlogon Notify: wvuttqn - C:\WINDOWS\SYSTEM32\wvuttqn.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing) O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe |
|
|
|
![]() |
Jan 27 2008, 03:24 PM
Post
#2
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,153 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate |
Your welcome Caroline and good luck in the future. Regards, Dave |
|
|
|
caz86 [Resolved] Help! i'm infected with trojan dropper agent . Jan 21 2008, 04:11 PM
IndiGenus Hi caz86 and welcome to the forums.
My name is Da... Jan 23 2008, 07:30 PM
caz86 Hi Dave,
thank you for your reply, and agreeing t... Jan 24 2008, 06:12 PM
IndiGenus Hi,
Yes, you are (and hopefully soon were) very i... Jan 24 2008, 06:37 PM
caz86 Hi, i have done the cfscript task. and the combofi... Jan 25 2008, 12:36 PM
IndiGenus QUOTE however, an avg scan revealed more viruses c... Jan 25 2008, 01:11 PM
caz86 Hi,
i have done the scans you suggested....logs ... Jan 26 2008, 11:28 AM
IndiGenus C:\QooBox is combofix's quarantine folder... Jan 26 2008, 11:44 AM
caz86 Hi,
i have installed the java that you suggested ... Jan 27 2008, 08:27 AM
caz86 oh yeah, and i've done an avg full scan which ... Jan 27 2008, 08:29 AM
IndiGenus Hi,
Glad to hear it's running better Caroline... Jan 27 2008, 10:46 AM
caz86 Hi, i've got as far as spybot and something ha... Jan 27 2008, 02:07 PM
IndiGenus QUOTE --- Search result list ---
Microsoft.Windows... Jan 27 2008, 02:34 PM
caz86 yup, that makes sense! thanks
adaware was cle... Jan 27 2008, 02:42 PM
caz86 hi,
i have downloaded all the suggested programs ... Jan 27 2008, 03:11 PM
IndiGenus Since this issue appears to be resolved ... this T... Jan 28 2008, 11:54 AM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
14 | Marm | 184 | Yesterday, 09:29 PM Last post by: CatByte |
|||
![]() |
8 | pacificjade | 101 | Yesterday, 08:21 PM Last post by: pacificjade |
|||
![]() |
22 | HHHisthegame | 289 | Yesterday, 08:14 PM Last post by: HHHisthegame |
|||
![]() |
29 | Stormicats | 1,205 | Yesterday, 03:58 PM Last post by: extremeboy |
|||
|
Time is now: 18th March 2010 - 12:44 AM |