Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 





Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > HijackThis Log Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read

HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
Thread Tools
Old 04-18-2007, 07:23 PM   #1 (permalink)
Registered User
 
Join Date: Apr 2007
Location: Central Montana
Posts: 19
OS: XP SP2

My System

Cannot remove.Win32:lroffer-002[trj]/Win32:Delf-RR[trj]

Have Avast Home. Archive files are infected with lrofer, Delf, Trojano. files cannot be repaired, or moved to chest. If I scan without scanning archives. No viruses are found, only scanning archives. This was the initial scan when received used computer. All that is left is the three listed above. You help would be appreciated. Thank you.
Initialization of Chest files
------------------------------------------------------------------------------------------
Program will try to load all Chest files from the following server: (null)
FileID: 0000000001 Original file name: C:\WINDOWS\system32\kernel32.dll File category: 0
FileID: 0000000002 Original file name: C:\WINDOWS\system32\winsock.dll File category: 0
FileID: 0000000003 Original file name: C:\WINDOWS\system32\wsock32.dll File category: 0
FileID: 0000000004 Original file name: c:\explorer.exe File category: 1
FileID: 0000000005 Original file name: c:\program files\media gateway\mediagateway.exe File category: 1
FileID: 0000000006 Original file name: C:\Documents and Settings\Family Computer\bootctrl.exe File category: 1
FileID: 0000000007 Original file name: C:\Documents and Settings\Family Computer\Local Settings\Temp\tsinstall_4_0_3_7.exe File category: 1
FileID: 0000000008 Original file name: C:\Documents and Settings\Family Computer\windows.exe\HIDDEN32.exe File category: 1
FileID: 0000000009 Original file name: C:\Documents and Settings\Owner.RONDA-FZ2RDRR2S\Local Settings\Temp\Del5B7.tmp File category: 1
FileID: 0000000010 Original file name: C:\Documents and Settings\Owner.RONDA-FZ2RDRR2S\Local Settings\Temp\resFA.tmp File category: 1
FileID: 0000000011 Original file name: C:\HideRun.exe File category: 1
FileID: 0000000012 Original file name: C:\iexpIerer.exe File category: 1
FileID: 0000000013 Original file name: C:\iexplerer.exe File category: 1
FileID: 0000000014 Original file name: C:\iexplorer.exe File category: 1
FileID: 0000000015 Original file name: C:\iksswm.exe File category: 1
FileID: 0000000016 Original file name: C:\Program Files\BullsEye Network\bin\adv.exe File category: 1
FileID: 0000000017 Original file name: C:\Program Files\BullsEye Network\bin\adx.exe File category: 1
FileID: 0000000018 Original file name: C:\Program Files\Common Files\tsa\rainbow\classify.dll File category: 1
FileID: 0000000019 Original file name: C:\Program Files\Common Files\tsa\ts2.exe File category: 1
FileID: 0000000020 Original file name: C:\Program Files\Common Files\tsa\tsl.exe File category: 1
FileID: 0000000021 Original file name: C:\Program Files\Common Files\tsa\tsl2.exe File category: 1
FileID: 0000000022 Original file name: C:\Program Files\Common Files\tsa\tsm2.exe File category: 1
FileID: 0000000023 Original file name: C:\Program Files\Common Files\tsa\tsp2.exe File category: 1
FileID: 0000000024 Original file name: C:\Program Files\Common Files\tsa\tsuninst.exe File category: 1
FileID: 0000000025 Original file name: C:\Program Files\Common Files\update\HIDDEN32.exe File category: 1
FileID: 0000000026 Original file name: C:\Program Files\Common Files\updates\2.rar\lsass.exe File category: 1
FileID: 0000000027 Original file name: C:\Program Files\Common Files\updates\2.rar\svchost.exe File category: 1
FileID: 0000000028 Original file name: C:\Program Files\Common Files\updates\HIDDEN32.exe File category: 1
FileID: 0000000029 Original file name: C:\Program Files\Internet Optimizer\optimize.exe File category: 1
FileID: 0000000030 Original file name: C:\Program Files\Media Gateway\trz17.tmp File category: 1
FileID: 0000000031 Original file name: C:\Program Files\mt.html File category: 1
FileID: 0000000032 Original file name: C:\Program Files\ProSiteFinder\j7h4v0hf.DLL File category: 1
FileID: 0000000033 Original file name: C:\Program Files\ProSiteFinder\prositefinder.exe File category: 1
FileID: 0000000034 Original file name: C:\Program Files\Web_Rebates\WebRebates0.exe File category: 1
FileID: 0000000035 Original file name: C:\Program Files\Windows AdControl\WinAdAlt.exe File category: 1
FileID: 0000000036 Original file name: C:\Program Files\Windows AdControl\WinAdCtl.exe File category: 1
FileID: 0000000037 Original file name: C:\Program Files\Windows AdControl\WinAdShift.dll File category: 1
FileID: 0000000038 Original file name: C:\re11.REG File category: 1
FileID: 0000000039 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP536\A0021470.exe File category: 1
FileID: 0000000040 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP536\A0021472.exe File category: 1
FileID: 0000000041 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP536\A0021473.dll File category: 1
FileID: 0000000042 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023065.exe File category: 1
FileID: 0000000043 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023066.exe File category: 1
FileID: 0000000044 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023068.exe File category: 1
FileID: 0000000045 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023069.exe File category: 1
FileID: 0000000046 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023070.exe\HIDDEN32.exe File category: 1
FileID: 0000000047 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023071.exe File category: 1
FileID: 0000000048 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023072.exe File category: 1
FileID: 0000000049 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023073.exe File category: 1
FileID: 0000000050 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023074.exe File category: 1
FileID: 0000000051 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023075.exe File category: 1
FileID: 0000000052 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023076.exe File category: 1
FileID: 0000000053 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023077.exe File category: 1
FileID: 0000000054 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023078.dll File category: 1
FileID: 0000000055 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023079.exe File category: 1
FileID: 0000000056 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023080.exe File category: 1
FileID: 0000000057 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023081.exe File category: 1
FileID: 0000000058 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023082.exe File category: 1
FileID: 0000000059 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023083.exe File category: 1
FileID: 0000000060 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023084.exe File category: 1
FileID: 0000000061 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023085.exe File category: 1
FileID: 0000000062 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023086.exe File category: 1
FileID: 0000000063 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023087.exe File category: 1
FileID: 0000000064 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023088.DLL File category: 1
FileID: 0000000065 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023089.exe File category: 1
FileID: 0000000066 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023090.exe File category: 1
FileID: 0000000067 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023091.exe File category: 1
FileID: 0000000068 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023092.exe File category: 1
FileID: 0000000069 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023093.dll File category: 1
FileID: 0000000070 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023094.REG File category: 1
FileID: 0000000071 Original file name: C:\temp\Installer2.exe File category: 1
FileID: 0000000072 Original file name: C:\temp\NCasePackage.exe File category: 1
FileID: 0000000073 Original file name: C:\temp\optimize.exe File category: 1
FileID: 0000000074 Original file name: C:\temp\pootz_58.exe File category: 1
FileID: 0000000075 Original file name: C:\temp\salm.exe File category: 1
FileID: 0000000076 Original file name: C:\temp\salmhook.dll File category: 1
FileID: 0000000077 Original file name: C:\temp\WebRebates_CDT_InstallSilent.exe File category: 1
FileID: 0000000078 Original file name: C:\temp\ZCWEDowST3.exe File category: 1
FileID: 0000000079 Original file name: C:\winnt\system32\spool\driver\colors\2.rar\lsass.exe File category: 1
FileID: 0000000080 Original file name: C:\winnt\system32\spool\driver\colors\2.rar\svchost.exe File category: 1
FileID: 0000000081 Original file name: C:\winnt\system32\spool\driver\colors\HIDDEN32.exe File category: 1
FileID: 0000000082 Original file name: C:\winnt\system32\spool\driver\colors\lsass.exe File category: 1
FileID: 0000000083 Original file name: C:\winnt\system32\spool\driver\colors\svchost.exe File category: 1
FileID: 0000000084 Original file name: C:\winnt\vcfen.exe File category: 1
FileID: 0000000085 Original file name: C:\Program Files\Media Gateway\trz2E.tmp File category: 1
FileID: 0000000086 Original file name: C:\System Volume Information\_restore{A5A75108-845B-4018-82DC-3112624ED9BB}\RP558\A0023099.exe File category: 1
FileID: 0000000087 Original file name: C:\WINDOWS\Temp\_avast4_\unp13584960.tmp File category: 1
------------------------------------------------------------------------------------------
Action was completed successfully!
yogohuntr is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -7. The time now is 02:13 AM.



Copyright 2001 - 2008, Tech Support Forum

Search Engine Friendly URLs by vBSEO

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82