Free PC Performance Scan

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] My computer is infected with troj_adload.s,troj_chophar.a and troj_dropper.up

[Fixed] Hijackthis! Logs - [Fixed] My computer is infected with troj_adload.s,troj_chophar.a and troj_dropper.up posted in the Security & Safety forums; Hi Joe, Both programs that you mentioned I am using ( solat + business plan ) I am attaching you both log files by active scan and spy sweeper for ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #8  
Old 01-18-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default

Hi Joe,

Both programs that you mentioned I am using ( solat + business plan )

I am attaching you both log files by active scan and spy sweeper for your perusal.

Thanks for all the help

madmal
Attached Files
File Type: txt Activescan.txt (5.0 KB, 2 views)
File Type: txt Spy Sweeper Session Log.txt (45.5 KB, 2 views)


  #9  
Old 01-19-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hmmm... that doesn't look good... looks like a rootkit..


Or are you "hiding" a bunch of pictures youreself on youre pc?





Download Smitrem to your desktop

http://noahdfear.geekstogo.com/click...click.php?id=1

Run the installer and then press Start to Extract the
files to the desktop, Do not run it yet.

Reboot into safe mode (Reboot and keep tapping F8 then
choose safe mode from the list)

Run SmitRem:

Open the SmitRem folder and double click the "RunThis.bat"
file to start the tool , Follow the prompts on
screen. Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of the drive that you ran the batch file on, eg; Local Disk C: or partition where your operating system is installed. Please attach this log to your next reply


And after youre repley we'll need to go rootkit hunting it seems..


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #10  
Old 01-19-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default

Hi Joe,

I do have a program that is called Lock Folder XP that I hide all my videos and pictures. Would this be the problem??

Should I still continue with what you had recommended and execute Smitren and get the results??


Thanks.

madmal


  #11  
Old 01-19-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Yup , still run the smitrem tool and post the log from it please.

And also download KillBox:

http://www.atribune.org/downloads/KillBox.exe


Double click on Killbox.exe and then check the delete on reboot button.
Enter the following filepath and filename into the Full path of file to delete box:

c:\windows\system32\msctl32.dll


Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)


And i think Spysweeper indeed sees Lock Folder XP as a possible rootkit , but that is a false positive then and nothing to worry about.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #12  
Old 01-19-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default

Hi Joe,

I am just adding the smitfiles text file as per requested anyway for your deliberation.

madmal
Attached Files
File Type: txt smitfiles.txt (1.4 KB, 2 views)


  #13  
Old 01-19-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Did you also delete that file with killbox?

And delete these files manually please:

C:\WINDOWS\tool1.exe
C:\WINDOWS\tool2.exe
C:\secure32.html


Is there still mail being send out?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #14  
Old 01-20-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default

Hi Joe,

Yes, I have deleted the fill with Kill Box plus deleting manually the files that you told me too. So far I don't see anymore mails being sent out without my consent. I hope my system is clean now.

madmal



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 05:40 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top