Scan your PC for Errors

Member Panel



Join the PC Help Forum Team

Join PC Help Forum on Facebook

Join the PCHF Distributed Computing Teams

Try the NEW PC Help Forum Dark style

Link to PCHF from other parts of the Internet
PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] SpyFalcon I guess

[Fixed] Hijackthis! Logs - [Resolved] SpyFalcon I guess posted in the Security & Safety forums; Long enough without a virus wasn't I? :P well this time I got an ever worse one (I think). Started an installer and then suddenly 10 IE windows poped up ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 11-19-2006
Stepes's Avatar
Gold Member
My PC
 
Join Date: Jul 2005
Posts: 276
PC Experience: Experienced
Stepes - See this Members User comments on their Profile page
Default [Resolved] SpyFalcon I guess

Long enough without a virus wasn't I? :P well this time I got an ever worse one (I think).

Started an installer and then suddenly 10 IE windows poped up I started blocking registry changes and connections. As a result, now I have an invisible icon down at the taskbar(near the clock) which says Mirc32 if I go over it. If I try to right click and exit it it just resurrects and pops up another 10 windows. Unfortunatelly I can't find it in task manager :/

So I checked my firewall where I found a Au_.exe file googled it and found its SpyFalcon trojan. Followed some instructions I found somewhere to clean all temp, use SmitfraudFix then AVG the Spybot. AVG found 2 trojans as can be seen in the attachment.

I also did a hijackthis! log fer you
but what I did doesnt seem to work. reboot and mirc32 and popups still there

regsupreme expired so no help from it either :/

PS: grrr I think I'm gonna switch permanently to linux, hope wine works well :P
Attached Files
File Type: txt Report-Scan-20061119-141759.txt (1.0 KB, 2 views)
File Type: log hijackthis.log (9.3 KB, 3 views)



Last edited by Stepes; 11-19-2006 at 02:05 PM.
  #2  
Old 11-19-2006
Stepes's Avatar
Gold Member
My PC
 
Join Date: Jul 2005
Posts: 276
PC Experience: Experienced
Stepes - See this Members User comments on their Profile page
Default

its kind of important to get rid of it soon :P anyone active here to help me?

edit: whoohooo, I did something kinda retarded propably :P I went in C:\Windows\system32\include and deleted the whole **** folder with killbox!! and the ******* trojan died diediediediedie **** malware. manual-steven-method vs annoying-trojan 1-0

Well now I have a new problem. When I get into windows it says can't find svchost bla bla. 1 of the files in this inculde dir was svchost.exe with mirc32 icon so I annihilated it >:] any way to clean the pc so that it doesnt try all the time to resurrect the trojan?

edit2: wow I swore a lot in this post! just now noticed seeing all those stars :P I was just too happy to beat it. Didn't expect it to give up so easilly without me ruining my windows folder or it changing location



Last edited by Stepes; 11-19-2006 at 06:33 PM.
  #3  
Old 11-21-2006
Stepes's Avatar
Gold Member
My PC
 
Join Date: Jul 2005
Posts: 276
PC Experience: Experienced
Stepes - See this Members User comments on their Profile page
Default

Noone can help me? Sorry for bumping but it would be nice to get rid of those virus remnants from my pc!


  #4  
Old 11-21-2006
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,580
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

im afraid we dont have many security members available atm so just hang on tightly and wait.


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #5  
Old 11-22-2006
Stepes's Avatar
Gold Member
My PC
 
Join Date: Jul 2005
Posts: 276
PC Experience: Experienced
Stepes - See this Members User comments on their Profile page
Default

oh ok then I just thought it was ingored because its in the wrong section I guess since its about malware and not anti-virus software. If you want move it
thanks


  #6  
Old 11-22-2006
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,866
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Sorry for the delay Stepes.

Can I see a new HijackThis and AVG Anti-spyware log please? It sounds though that you are dealing with remnants only.


  #7  
Old 11-22-2006
Stepes's Avatar
Gold Member
My PC
 
Join Date: Jul 2005
Posts: 276
PC Experience: Experienced
Stepes - See this Members User comments on their Profile page
Default

no prob a few posts higher I have the hijackthis! log from when the virus was still alive
here is the new one. you need a new avg log too(the old one is up a few posts)? don't think it'll find much but I'll run it in an hour or so cause I'm gonna go training and post it once I'm back

well all the side effects of the virus have vanished except the error messages that windows can't find and start the virus :P poor windows
Attached Files
File Type: log hijackthis.log (8.7 KB, 1 views)



Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 08:36 AM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top