Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Problems with a reported trojan

[Fixed] Hijackthis! Logs - [Resolved] Problems with a reported trojan posted in the Security & Safety forums; Hello I am experiencing the following trojan being reported by my Norton weekly sweep, both entries (same trojan repeated) cannot be quaratined or deleted by Norton:- regtr32.exe I have spy ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 05-27-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 9
phil0446 - See this Members User comments on their Profile page
Default [Resolved] Problems with a reported trojan

Hello

I am experiencing the following trojan being reported by my Norton weekly sweep, both entries (same trojan repeated) cannot be quaratined or deleted by Norton:-

regtr32.exe

I have spy sweeper as well running on my machine performing nightly sweeps, it does not pick the above up and reports my PC as clean.

I have performed the prework and attached the following reports:-

Hijack this log

Only problem being is when I save the ewido report (which was clean, honestly) on my desktop in safe mode, post restarting again I cannot find the file.....

Any help would be great

Thanks

Phil
Attached Files
File Type: log hijackthis.log (13.7 KB, 3 views)


  #2  
Old 05-27-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Hya Phil.


Download Pocket Killbox:
http://www.atribune.org/downloads/KillBox.exe


Then boot youre pc in safemode (hit f8 when booting up) and then fix these entrys with hjt:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {F06D8D0B-61B7-146A-E97C-6AF39C2314E1} - (no file)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O14 - IERESET.INF: START_PAGE_URL=http://www.wanadoo.co.uk

After that start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)

Copy this list into the windows clipboard:
(highlight the text , and select "copy")


C:\WINDOWS\regtr32.exe
C:\WINDOWS\Downloaded Installations\{825384D4-9CB9-44EA-86A2-E4025F3949AB}
C:\WINDOWS\Downloaded Installations\{5A715517-76F5-4865-AE58-B5FD61516D36}


Back in Killbox go > file > paste from clipboard,
Click the red highlighted X button and say yes to the prompt, then click OK.

Exit Killbox and restart your PC. See if Norton still detects anything , and post a new hjt log please.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #3  
Old 05-28-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 9
phil0446 - See this Members User comments on their Profile page
Default

Jo

Ran through your instructions, ran Norton again, problem remains!

Latest HJT file attached

Any ideas please?

Thanks

Phil
Attached Files
File Type: txt HJT Phil0446.txt (13.1 KB, 3 views)


  #4  
Old 05-28-2006
ladygreenwitch's Avatar
Elite Member
 
Join Date: Jul 2005
Location: Bay Area California
Posts: 4,643
ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page ladygreenwitch - See this Members User comments on their Profile page
Default

Hey Guys,

@Phill, did you also turn off Norton's Go Back before doing the fixes Joe suggested?

It may be that you need to disable System Restore, and Norton Go Back, and remove all files from the Norton Recycle Bin. That should remove any traces of the file that Norton is picking up. It will also make sure that you are not reinfected.

If prompted, you will want to remove all previous restore points, at this moment, they are all inftected anyway.

Your log checks out clean. However, you do have Windows Messenger enabled which leaves you open to popup attacks. Please download Shoot the Messenger from my signature, as well as RegSupremePro.

After disabling System Restore, and Norton Go Back, and deleting the protected recycled files. Reboot your computer. Then run Shoot the Messenger, it is very self explanatory.

Next run RegSupremePro.
It will want to create a backup of your cache, let it. Click on the Registry Cleaning tab, choose, Aggressive. When it has finished, click on Select, choose All. Click on Fix, and let it fix everything that it finds. Reboot your computer.

Now see if Nortons still locating traces of that file.

Look forward to your reply,

TTFN

LGW


  #5  
Old 05-28-2006
Bronze Member
 
Join Date: Dec 2005
Posts: 9
phil0446 - See this Members User comments on their Profile page
Default

Hi

Ran shoot the messenger (it was already disabled, but renabled and then disabled to be on the safe side)

Norton Goback is (prior to your reponse) disabled as I am about to do some disk partitioning with partitionmagic in irder to instal SUSE, gulp

Ran regsupreme pro, it picked up around 700 items, fixed or deleted by the programme as it deemed necessary.

Deleted out from Norton by Antivrius/reports = cleaned out reports and logs etc

Run a scan

Same as before issue remains

what next, is it a genuine issue or a quirk?

Thanks again

Phil


  #6  
Old 05-28-2006
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default

Im pretty sure it is a Win32.VB trojan , try this special removal tool:



Disinfection Utility

F-Secure Corporation provides the special disinfection utility to clean VB.bi infection from a computer. This disinfection utility is called F-Force and it can be downloaded from our web and ftp sites:

ftp://ftp.f-secure.com/anti-virus/tools/f-force.zip
http://www.f-secure.com/tools/f-force.zip

The utility is distributed only in a ZIP archive that contains the following files:
  • f-force.exe - the main executable file
  • eult.rtf - End User License Terms document
  • readme.rtf - Readme file in RTF format
  • readme.txt - Readme file in ASCII format
To unpack the archive please use the WinZip or similar archiver.

IMPORTANT! Please make sure that you read the End User License Terms document (Eult.rtf) and the Readme file (either Readme.txt or Readme.rtf) before using the F-Force utility!

The F-Force utility needs the archive with the latest updates in order to function properly. The archive's name is LATEST.ZIP and it should be downloaded and put into the same folder where the F-Force utility is located. This archive with the latest updates can be downloaded from one of these locations:

http://download.f-secure.com/latest/latest.zip
ftp://ftp.f-secure.com/anti-virus/updates/latest/latest.zip

Please note that the F-Force utility can disinfect only certain malicious programs. Besides the utility does not scan inside archives. So after cleaning a computer with the F-Force utility it is recommended to scan all hard drives with F-Secure Anti-Virus and the latest updates to make sure that no infected files remain there.




If that doesn't work then upload the regtr32.exe file to this site:

http://www.virustotal.com/en/indexf.html

And report back the scan result , that should tell for sure what it is.


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -


Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 06:33 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
MySpace Editor
MySpace Layouts, Myspace Editor and other great MySpace tools at MySpaceToolbox.com

Bad Credit Mortgage
Browse for bad credit / sub prime mortgages.

Personal Loans
Fast and easy personal loan comparison service from Money Expert. Compare the loans market to find the best deal for you.