Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] My computer is infected with troj_adload.s,troj_chophar.a and troj_dropper.up

[Fixed] Hijackthis! Logs - [Fixed] My computer is infected with troj_adload.s,troj_chophar.a and troj_dropper.up posted in the Security & Safety forums; Hi guys, it seems that my notebook is infected Trend Micro alerts me that the uncleanable infected file is: c:\windows\inet20010\alg.exe Virus name: Troj_chophar.a, troj_adload.s and troj_dropper.up Trend Micro also alerts ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 01-15-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default [Fixed] My computer is infected with troj_adload.s,troj_chophar.a and troj_dropper.up

Hi guys, it seems that my notebook is infected

Trend Micro alerts me that the uncleanable infected file is: c:\windows\inet20010\alg.exe
Virus name: Troj_chophar.a, troj_adload.s and troj_dropper.up

Trend Micro also alerts me that outgoing mail is also being sent.

Winlogon.exe is constantly tryin to install a BHO.

My computer keeps restarting as well.. so before it does that again, here is my hijackthis log.

Thanks to anyone who can help.

**Admin Edit - please read the rules about posting logs**
Attached Files
File Type: txt log.txt (7.5 KB, 9 views)



Last edited by Hengis; 01-15-2006 at 11:18 AM.
  #2  
Old 01-15-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Madmal , welcome to PCHF.


First of , please dont start double topics , second , lets get rid of those buggers.



Before fixing things with HijackThis Please Do the Following:


Show hidden files and folders:

For XP:
  1. On the Tools menu in Windows Explorer, click Folder Options.
  2. Click the View tab.
  3. Under Hidden files and folders, click Show hidden files and folders.
  4. If you see a warning message, click Yes.
  5. Click Apply.
  6. Click OK.



Disable System Restore to prevent re-infection.
(If you have/use it. You can turn it back on when youre PC is clean).

How to disable system restore:

WinXP.
  1. Click the Start button.
  2. Right-click My Computer, and then click Properties.
  3. On the System Restore tab, check Turn off System Restore or Turn off System Restore on all drives.


Please download CCleaner




Please download Process Explorer by Systernals from HERE.

Also download KillBox by Option^Explicit from HERE.


I see you have Trend Micro Internet Security and AVG free AV installed , i would remove the AVG since two AV's can cause conficts and performence issues , and AVG is free and only an AV.



Then boot up in SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.

Unzip Process Explorer and double click on procexp.exe
In the top section of the Process Exlporer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

Once you see this screen click on each instance of msupdate32.dll once and then click the kill button.
After you have killed all of the msupdate32.dll 's under winlogon click OK.

Next In the top section of the Process Exlporer screen again , double click on explorer.exe and again click once on each instance of msupdate32.dll then click the kill button.
Once you have done that click OK again.


Next run HijackThis and place a check beside each of the following:


F3 - REG:win.ini: run=C:\WINDOWS\inet20010\services.exe
O2 - BHO: (no name) - {5321E378-FFAD-4999-8C62-03CA8155F0B3} - (no file)
O4 - HKLM\..\Run: [xp_system] C:\WINDOWS\inet20010\services.exe
O20 - Winlogon Notify: msupdate - C:\WINDOWS\SYSTEM32\msupdate32.dll
Now click fix checked and close HijackThis.

Delete the folder in bold , and run Ccleaner.


Double click on Killbox.exe and then check the delete on reboot button.

Enter the following filepath and filename into the Full path of file to delete box:

C:\WINDOWS\SYSTEM32\msupdate32.dll

Click the red circle with the white x and allow your computer to reboot.
(if killbox doesn't reboot on its own then please reboot manually)

After your computer has rebooted please run Hijackthis again and post a new Hijackthis log.


I would also disable the windows Messenger service:

Please download Shoot The Messenger

Download and run the small (22 kbyte) "ShootTheMessenger.exe" utility. It will display the current status of your system's Messenger Service. The button near the bottom of its window will allow you to set the service to whichever state ? running or disabled ? that you desire.

If, for any reason, you should ever choose to re-enable the Windows Messenger Service, simply re-run ShootTheMessenger to do so.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 01-16-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default New HJT log file

Hi Joe,

Thanks for the help. I am posting a new HJT log file for your view.

madmal


  #4  
Old 01-16-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default

Hi Joe,

Didnt manage to attach the HJT log file previously. Attaching it here. Thanks.

madmal
Attached Files
File Type: txt hijackthismadmal2.txt (6.3 KB, 1 views)


  #5  
Old 01-16-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Looking good. All the bad stuff is gone.

But i see you've kept AVG free AV and removed Trend Micro Internet Security instead , no prob if you want that ofcourse , but now you dont have a firewall anymore. Thats not a good thing.

You could have a look in our download section for free firewalls if you like.

And do you still have any problems with youre pc?


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #6  
Old 01-17-2006
Bronze Member
 
Join Date: Jan 2006
Posts: 9
madmal - See this Members User comments on their Profile page
Default

Hi Joe,

I have already removed AVG and installed norton anti virus. Strangely enough i am getting a lot of emails blocked by norton being sent out to email addresses that i have never seen. I think I am still infected.

As usual here is my latest HJT log file again.

Regards,

madmal
Attached Files
File Type: txt hijackthismadmal3.txt (9.1 KB, 4 views)


  #7  
Old 01-17-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,036
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

I dont see anything wrong in youre log anymore , but just to check , you know and use these two apps?

C:\Program Files\Waktu Solat\waktusolat.exe
O4 - HKCU\..\Run: [WaktuSolat] C:\Program Files\Waktu Solat\waktusolat.exe

C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe


And can you run a Panda active scan and post the log from it:

http://www.pandasoftware.com/product...ACHEHINT=Guest


And a spysweeper scan , and also post the log from it please:

Please download and install the trial version of Webroot SpySweeper.

http://www.webroot.com/shoppingcart/...011&vcode=DT02

When SpySweeper starts, please accept any prompts to update definitions.
Configure it as follows:
From the left pane, click Options
Select the Sweep Options tab & ensure the following are ticked:

*Sweep Memory
*Sweep Registry
*Sweep Cookies
*Sweep All Users accounts
*Do Not Sweep System Restore Folder
*Enable Direct Disk Sweeping
*Sweep contents of compressed files
*Sweep For Rootkits

-After that's done, select Sweep from the left pane & click on the Start button

Allow Spysweeper to reboot your machine to remove the infected files.
After rebooting, launch SpySweeper & select Results from the left pane
Click the 'Session Log' tab & choose Save to File to create a log.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 05:45 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top