View Single Post
Old 06-28-2007, 05:24 PM   #5 (permalink)
forhockey
Analyst, Security Team
 
forhockey's Avatar
 
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,928
OS: Windows 7 Ultimate


Re: Hijack this Log(Trojan) please help

Hi sbpleecniadl,

Starting to look much better, but I'd like to have a sample of a few files for inspection.

---------------------------------------------------------------------------------------------

Please save these instructions to Notepad as the internet will not be available to you at certain points of the removal process.
Please ensure that there aren't any opened browsers when you are carrying out the procedures below.
Make sure to work through all the Steps in the exact order in which they are listed below.
If there's anything that you don't understand, ask your question(s) before moving on with the fixes.


---------------------------------------------------------------------------------------------

Open notepad and copy/paste the text in the quotebox below into it:

Code:
@echo off
for %%g in (
"C:\WINDOWS\system32\qpfudpgs.dll"
"C:\WINDOWS\system32\qphnydqe.dll"
) do catchme -l nul -k %%g >nul
echo.Please submit the file, catchme.zip located on Desktop
pause
exit
Save this as Submit.bat Choose to "Save type as - All Files"
It should look like this:
Double click on Submit.bat & allow it to run

This will generate a archive on your desktop, catchme.zip
Please submit it to this site → http://www.bleepingcomputer.com/subm....php?channel=4
Please include a link to this topic in the message.

---------------------------------------------------------------------------------------------

Click > Start > Control Panel > Add / Remove Programs and uninstall the following programs (if they exist):

Easy SpyRemover - This is a rogue ware program and we highly recommend that you uninstall it. Rogue/Suspect means that these products are of unknown, questionable, or dubious value as anti-spyware protection.


---------------------------------------------------------------------------------------------

Open notepad and copy/paste the text in the quotebox below into it:

Quote:
File::
C:\WINDOWS\system32\scchk32.exe
C:\DOCUME~1\ALLUSE~1\APPLIC~1\xiladgte.exe
C:\WINDOWS\system32\qpfudpgs.dll
C:\WINDOWS\system32\qphnydqe.dll

Folder::
C:\WINDOWS\system32\nkwncvkg
C:\Program Files\Easy SpyRemover

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"xiladgte.exe"=-
"Easy SpyRemover"=-
Save this as ComboFix-Do.txt




Refering to the picture above, drag ComboFix-Do.txt into ComboFix.exe

Follow the prompts, and post the resulting log, C:\ComboFix.txt

Warning:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

---------------------------------------------------------------------------------------------

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Please reply back with the Kaspersky results, and a fresh HijackThis Log

---------------------------------------------------------------------------------------------

Please include the following in your next reply:

C:\ComboFix.txt
Kaspersky Results
Fresh HijackThis Log
__________________


Proud Member of ASAP
Proud Member of UNITE

Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support.

Donation link for Tech Support Forum
forhockey is offline