This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] trogan horse generic17. ber

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is very infected, very slow. When I click on my icons they will not open, I think it has took over my virus scanner maybe. I thought that it was working but then it just started tellin me it found stuff but would not let me clean the files. The trojan I put in the topic is one it kept throwing up but there was more I just can't remember the names, I know one said Virus. I tried so many times to put my hijack this log in this but it wouldn't let me post it, it keep bring up page not found everytime i tried even on the other forums same thing. Thanks for your time.
Hello and :welcome: Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise. This may cause a delay, but I will do my best to keep it as short as possible. I will post back shortly with instructions.
Hi,

I will be helping you on removing malwares on your computer. Log research takes time, so please be patient and I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Do not install/uninstall anything on your computer unless advised.
  • Do not run any other scanning tools other than those instructed for you to use.
  • Follow the instructions on the order they are given.
  • Stay with this thread until advised when your computer is clean. Absence of symptoms does not necessarily mean a clean computer.
  • If you are being helped regarding this problem on another forum please advice us so that we can close this thread.
  • If you do not reply within 3 days after my last response, I will be asking you whether you still need assistance and if you still don't reply within 24 hours then the topic will be closed.
  • And lastly, if you have any questions, please ask before proceeding with any of the advised fixes.

_________________________________________________


Are there any error messages when you are trying to clean up the infection? What security software is telling you about the infection?
Can you post what the message was when your security software is telling you that you have an infection?

–Next–

OTL:
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
–Next–

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


To post in your next reply:
1. Regarding the questions above.
2. OTL logs.
3. GMER log.
First off I want to say thank you so much for helping me! Ok No I'm not getting any error messages when I run my scans, it just runs and then says it never finds anything. I'm using AVG Internet Security and one of the trogans it throws up is the one in the topic, then there was this c:\windows\temp\9649747455.dll.dll. But the trogan horse generic17.ber pops up all the time over and over. There was another one in the c:\windows\system32 but I can't remember all of it.


OTL logfile created on: 3/17/2010 9:12:39 PM - Run 1
OTL by OldTimer - Version 3.1.37.2 Folder = C:\Documents and Settings\Christina\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 403.00 Mb Available Physical Memory | 45.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.40 Gb Total Space | 23.14 Gb Free Space | 33.34% Space Free | Partition Type: NTFS
Drive D: | 69.89 Gb Total Space | 69.78 Gb Free Space | 99.85% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: CHRISTINAS
Current User Name: Christina
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Christina\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgam.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSMonitor.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AOL 9.5\waol.exe (AOL, LLC.)
PRC - C:\Program Files\AOL 9.5\shellmon.exe (AOL, LLC.)
PRC - C:\Program Files\NetZero\exec.exe (NetZero, Inc.)
PRC - C:\Program Files\Common Files\AOL\1266810167\ee\aolsoftware.exe (AOL LLC)
PRC - C:\Program Files\NetZero\qsacc\X1Exec.exe (NetZero, Inc.)
PRC - C:\Program Files\PhotoJoy\Bin\PjApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\IncrediMail\bin\ImApp.exe (IncrediMail, Ltd.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe ()
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
PRC - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\WINDOWS\system32\lxdkcoms.exe ( )
PRC - C:\WINDOWS\system32\spool\drivers\w32x86\3\lxdkserv.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark 5300 Series\lxdkamon.exe ()
PRC - C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe (AOL LLC)
PRC - C:\Program Files\Common Files\Command Software\dvpapi.exe (Command Software Systems, Inc.)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Christina\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\IncrediMail\bin\B4ImApp.dll (Babylon Ltd.)


========== Win32 Services (SafeList) ==========

SRV - (ACDaemon) – File not found
SRV - (avgfws9) – C:\Program Files\AVG\AVG9\avgfws9.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe ()
SRV - (GameConsoleService) – C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (NTIBackupSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe (NewTech InfoSystems, Inc.)
SRV - (NTISchedulerSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe ()
SRV - (BUNAgentSvc) – C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe (NewTech Infosystems, Inc.)
SRV - (AgereModemAudio) – C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
SRV - (lxdk_device) – C:\WINDOWS\System32\lxdkcoms.exe ( )
SRV - (lxdkCATSCustConnectService) – C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdkserv.exe ()
SRV - (AOL ACS) – C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (AOL LLC)
SRV - (dvpapi) – C:\Program Files\Common Files\Command Software\dvpapi.exe (Command Software Systems, Inc.)
I'm trying at first I tried to put the who thing on there but when I click on post it said page could not be found so I was gonna try to separate it and send but it's not letting me it keeps saying page cannot be found everytime I try to post it.
========== Driver Services (SafeList) ==========

DRV - (AvgRkx86) – C:\WINDOWS\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSErHrxpx) – C:\WINDOWS\System32\Drivers\AVGIDSxx.sys (AVG Technologies CZ, s.r.o. )
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSDriverxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSFilterxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys (AVG Technologies CZ, s.r.o. )
DRV - (AVGIDSShimxpx) – C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (AVG Technologies CZ, s.r.o. )
DRV - (Avgfwfd) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgfwdx) – C:\WINDOWS\system32\drivers\avgfwdx.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymIMMP) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (SymIM) – C:\WINDOWS\system32\drivers\SymIM.sys (Symantec Corporation)
DRV - (afwcore) – C:\WINDOWS\system32\drivers\afwcore.sys (Agnitum Ltd.)
DRV - (afw) – C:\WINDOWS\system32\drivers\afw.sys (Agnitum Ltd.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (UBHelper) – C:\WINDOWS\system32\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (NTIDrvr) – C:\WINDOWS\system32\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (MRESP50) – C:\Program Files\Common Files\Motive\MRESP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (MREMP50) – C:\Program Files\Common Files\Motive\MREMP50.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (RT73) – C:\WINDOWS\system32\drivers\rt73.sys (Ralink Technology, Corp.)
DRV - (CSS DVP) – C:\WINDOWS\system32\drivers\css-dvp.sys (Command Software Systems, Inc.)
DRV - (wanatw) WAN Miniport (ATW) – C:\WINDOWS\system32\drivers\wanatw4.sys (America Online, Inc.)
DRV - (PRISM_USB) – C:\WINDOWS\system32\drivers\ExpsUSB.sys (Intersil Americas Inc.)
Hi, Can you attach it instead? If that won't work then please continue on posting it the way you are doing now. Be sure not to miss anything. Thanks.
When I put simple stuff like this in here it goes thur fine, I swear it's like it knows what I'm doing?? I will keep trying to put the OTL log and extras log in here but I tried to run the Gmer like 6 times and everytime it opened up my computer froze and wouldn't do nothing I had to unplugg it everytime to get it back up and running.
Hi,

Have you tried running GMER in safe mode?
To do this,
  • Restart your computer.
  • Keep on tapping f8 when windows starts to boot. Do this before you see the windows screen.
  • When a list of menu appears, scroll to Safe Mode using the arrow keys then press Enter.
Try running GMER and uncheck "Files" on the right hand column by clicking on the box beside it.
Hi,

Does this happen in both IE and firefox?

Have you modified your hosts file recently?

You may need to print this out.


While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent our tools from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click Advanced mode if not already selected.
  • Choose Yes at the Warning prompt.
  • Expand the Tools menu.
  • Click Resident.
  • Uncheck the Resident TeaTimer (Protection of overall system settings) active. box.
  • In the File menu click Exit to exit Spybot Search & Destroy.
  • Reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.)

–Next–

The next procedure will reset your hosts file to the MS default.

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
    O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - C:\WINDOWS\Temp\9649747455.dll ()
    [2009/12/21 15:14:06 | 003,113,248 | —- | C] () – C:\WINDOWS\System32\dosyerr.dll
    [2009/12/21 15:14:06 | 003,058,841 | —- | C] () – C:\WINDOWS\System32\arexasy.dll
    [2009/12/21 15:14:06 | 002,101,951 | —- | C] () – C:\WINDOWS\System32\craesex.dll
    O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\WINDOWS\system32\craesex.dll ()
    [2010/03/15 00:09:03 | 000,003,748 | —- | M] () – C:\WINDOWS\System32\craesex.dat
    [2009/12/21 15:14:06 | 001,672,908 | —- | C] () – C:\WINDOWS\System32\upuppoh.dll
    [2010/03/14 20:23:51 | 000,003,748 | —- | M] () – C:\WINDOWS\System32\uperrscra.dat
    O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range -  5)
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = searchap.untd.com;127.0.0.1;localhost;*microsoft.com;*windowsupdate.com;*wustat.
    windows.com;*test-speed.com;liveupdate.symantecliveupdate.com;*symantec.com;*.nai.com;*.networkass
    ociates.com;cf.netzero.net;qs.netzero.net;*.quicken.com;*.pogo.com;
    
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered, reboot when it is done.
  • Then post the result and a new OTL log in your next reply. ( don't check the boxes beside LOP Check or Purity this time )
–Next–

Download and run HAMeb_check.exe
Post the contents of the resulting log.

–Next–

Please go to the site below to scan the following files:
VirSCAN

Click on Browse, and upload the following file for analysis or copy/paste the text below into the browse box:
C:\Documents and Settings\Christina\Local Settings\Application Data\5OIKNf5X358gef0x3ob3

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"

Repeat the procedure with the following file:
C:\Documents and Settings\Christina\Local Settings\Application Data\UYxp8qC
C:\WINDOWS\System32\NTIMP3.dll
C:\WINDOWS\System32\NTIOFM4.dll
C:\WINDOWS\System32\NTIBUN5.dll
C:\WINDOWS\System32\NTIMPEG2.dll
C:\WINDOWS\System32\NTIMP3.dll


Please post the results in your next reply.

To post in your next reply:
1. Regarding your hosts file and if this problem happens in both IE and Firefox.
2. OTL fix log.
3. HAMeb_check log.
4. VirSCAN log.
5. GMER log.
Yes it happens in IE and Firefox and as far as the modifying my hosts file I don't even know what that means so no. Ok I did everything you told me, and when I got to the Virscan part I went to the site and first I tried to copy and paste them into the browse box but it wouldn't let me. I tried pasting from edit and the ctrl & v still wouldn't work. So then I tried to upload them but I looked in c:\documents and settings, then christinas but after that I couldn't find local settings so I couldn't find either of those. Then I went to c:\windows\system32 and looked for the others and none of them were in there. I finally got the gmer to run last night but it took like four hours and it was still scanning so I just went to bed and said I would just save the file when I got up but it just disappeared after it finished because it wasn't on my screen when I woke up. I had to work all day today so I couldn't run it again, so I'm gonna try again in the morning and watch it the whole time I guess so I can catch it when it ends and save the log. I'm attaching the other logs. And thanks again for helping me.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI