Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] I had Troj/Spywad-I now i cant change my desktop back

[Fixed] Hijackthis! Logs - [Fixed] I had Troj/Spywad-I now i cant change my desktop back posted in the Security & Safety forums; Hi, I had Troj/Spywad-I, I ran Ewido and got rid of this. Some details fo the trojan are given here: http://www.sophos.com/virusinfo/anal...ojspywadi.html . I tried to download the Sophos software but ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 12-27-2005
davidwilcock's Avatar
Bronze Member
 
Join Date: Dec 2005
Posts: 26
davidwilcock - See this Members User comments on their Profile page
Default [Fixed] I had Troj/Spywad-I now i cant change my desktop back

Hi,
I had Troj/Spywad-I, I ran Ewido and got rid of this. Some details fo the trojan are given here: http://www.sophos.com/virusinfo/anal...ojspywadi.html.

I tried to download the Sophos software but it wouldnt recognise my OS. Thats not the problem however, my problem now is that I cannot change the background on my desktop. the trojan changes it to something about 'computer infected' (see the link). I deleted this by searching for desktop/html on my computer, but now i cant change it to my old background. i can got to the place where you change it but clicking the buttons just doesnt work and i cant scroll up and down the different pictures.

Any ideas?

thanks,
dave


  #2  
Old 12-27-2005
btalman's Avatar
Elite Member
 
Join Date: Nov 2005
Posts: 504
btalman - See this Members User comments on their Profile page
Default

Hi davidwilcock and welcome to PCHF,
Please make a hijackthislog and post it to the hijackthissection of this site. The experts over there will analyze the log and try to remove any traces left by the trojan.
Bram


__________________
  #3  
Old 12-27-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looks like you have a Spysherrif infection , we should get rid of that pretty easy after you post a hjt log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 12-27-2005
davidwilcock's Avatar
Bronze Member
 
Join Date: Dec 2005
Posts: 26
davidwilcock - See this Members User comments on their Profile page
Default the log

Edited, log placed as an attachment by mod: please read the hjtposting rules before posting a log
Edited by mod: please place hjt logs in the appripriate section, moved the post
Attached Files
File Type: txt log.txt (3.3 KB, 3 views)



Last edited by btalman; 12-27-2005 at 08:16 PM.
  #5  
Old 12-27-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I would uninstall EmpirePoker , royalvegasMPP and PartyPoker in add/remove programs if you don't want/use them.


Before fixing things with HijackThis Please Do the Following:


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.

Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.

Please download CCleaner


Then boot in safe mode (hit f8 when booting up) and fix these with hjt:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\WINDOWS\System32\search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\System32\search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\System32\search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = C:\WINDOWS\System32\search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\System32\search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\System32\search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\search.html
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://www.miniclip.com/bestfriends/...GameLoader.dll
Delete the file in bold and run Ccleaner.

Then reboot and download and run this fix:

http://users.telenet.be/marcvn/regfi...desktopfix.zip



After that please upload this file:

C:\WINDOWS\SYSTEM32\htproc32.dll

To these sites and report back the results:

http://www.virustotal.com/flash/index_en.html

http://virusscan.jotti.org/


Also i see you have no firewall and no AV , to prevent problems like this you really should have those. Have a look in our download section for some free versions.

And you have also no service packs installed but we'll get to that when youre clean.

Last , please post a new hjt log to check.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 12-28-2005
davidwilcock's Avatar
Bronze Member
 
Join Date: Dec 2005
Posts: 26
davidwilcock - See this Members User comments on their Profile page
Default

Hi, thies are the results of the scans





AntiVir
Found nothing
ArcaVir Found Trojan.Psw.Lineage.Sk
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found Trojan.PWS.Lineage
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found Trojan-PSW.Win32.Lineage.sk
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found nothing
.................................................. .................................................. .

AntivirusVersionUpdateResultAntiVir6.33.0.7012.28. 2005no virus found
Avast4.6.695.012.27.2005no virus found
AVG71812.27.2005no virus found
Avira6.33.0.7012.28.2005no virus found
BitDefender7.212.28.2005no virus found
CAT-QuickHeal8.0012.27.2005no virus found
ClamAVdevel-2005110812.26.2005no virus found
DrWeb4.3312.28.2005Trojan.PWS.LineageeTrust-
Iris7.1.194.012.27.2005no virus founde
Trust-Vet12.4.1.012.28.2005no virus found
Ewido3.512.28.2005Trojan.Lineage.sk
Fortinet2.54.0.012.27.2005no virus found
F-Prot3.16c12.28.2005no virus found
Ikarus0.2.59.012.27.2005no virus found
Kaspersky4.0.2.2412.28.2005Trojan-PSW.Win32.Lineage.sk
McAfee466012.27.2005no virus found
NOD32v21.134112.27.2005no virus found
Norman5.70.1012.28.2005no virus found
Panda8.02.0012.27.2005no virus found
Sophos4.01.012.28.2005no virus found
Symantec8.012.28.2005no virus found
TheHacker5.9.1.06212.27.2005no virus found
UNA1.8312.28.2005no virus found
VBA323.10.512.27.2005no virus found




The box with all the wallpapers in is now useable but it still doesnt let me change them, when I click apply nothing happens. Also if I press ctrl alt del a message pops up saying 'task manager has been disabled by the administrator.'

thanks for the help,
David



Last edited by davidwilcock; 12-28-2005 at 01:50 PM.

Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Answered] Question about my desktop. gtboi604 Graphics 6 11-18-2005 05:26 AM
[Answered]change back from ntfs to fat 32 hows it done? dino89 Windows XP/2000 11 08-20-2005 01:18 PM
Keyboard shortcut heaven. joe5 Windows Tutorials 4 07-11-2005 10:27 PM
[Pending] Mysterious Add New Hardware Wizard appearance with no desktop superdee Windows 95, 98 & ME 5 07-08-2005 08:07 PM
[Answered] Registry Change at Startup Kezal Network Help 1 02-22-2005 10:54 PM


All times are GMT +1. The time now is 12:09 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top