Scan your PC for Errors

Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » Anti-Virus » trojen infection

Anti-Virus - trojen infection posted in the Security & Safety forums; Hi i seem to have a problem that norton or adware cannot fix, norton wont even reconise it and want $69 for there advice, and adware finds it but is ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-14-2006
Bronze Member
 
Join Date: May 2006
Posts: 17
wtdafk - See this Members User comments on their Profile page
Default trojen infection

Hi i seem to have a problem that norton or adware cannot fix, norton wont even reconise it and want $69 for there advice, and adware finds it but is unable to delete it.

when i run adaware it finds win32.trojandownloader.zlob(2 objects total)
and mru list(2 objects total)

when i ask it to remove it it says it cant remove c:\windows\system32/atmlk.exe
and C:\windows/system32\stdole3.tlb

the symtoms are it creating a flashing logo on my task bar sayin virus alert! i have a critacal error that may cause system failer, also it redirects my home page to a virus remover page what i think looks a bit suspicus.

i would be very greatful for assistance in this as im not to sure what to do,
cheers
stu


  #2  
Old 05-14-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hi there Wtdafk , welcome to PCHF.


Dont pay anything to them , we'll get rid of that for free. Sounds like you have a Spyware Quake infection.

Please run the Smitfraud fix , see link and instructions here:

http://siri.urz.free.fr/Fix/SmitfraudFix_En.php


After that post the log (C:\rapport.txt) it made , plus a Hijackthis log. For the last see link below in my sig.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Last edited by joe5; 05-14-2006 at 07:26 PM.
  #3  
Old 05-15-2006
Bronze Member
 
Join Date: May 2006
Posts: 17
wtdafk - See this Members User comments on their Profile page
Default

ok i tryed the smitfraud but it says process.exe absent an tellme me to unzip the arcive>??


  #4  
Old 05-15-2006
Bronze Member
 
Join Date: May 2006
Posts: 17
wtdafk - See this Members User comments on their Profile page
Default

ok and here is the hijackthis log file
Attached Files
File Type: log hijackthis.log (8.0 KB, 5 views)


  #5  
Old 05-15-2006
Bronze Member
 
Join Date: May 2006
Posts: 17
wtdafk - See this Members User comments on their Profile page
Default

will be great if i can get rid of it cheers for you help, im i right in thinking that i shouldent order anything off the net at this time because of this security risk? cheers


  #6  
Old 05-15-2006
Bronze Member
 
Join Date: May 2006
Posts: 17
wtdafk - See this Members User comments on their Profile page
Default

smit report
Attached Files
File Type: txt smit report.txt (2.1 KB, 3 views)


  #7  
Old 05-15-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Yup , just what i thought. A Spyware Quake infection , and it looks like the Smitfraud fix has removed it.


These can be fixed with hjt if still present:

O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hpF6BB.tmp
O4 - HKLM\..\Run: [LaunchApp] Alaunch
Then please post a new hijackthis log after that , and a discription of remaining problems , if any.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 09:41 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top