Member Panel


Sponsors and Ads

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Fixed] Troj/Killav-DQ

[Fixed] Hijackthis! Logs - [Fixed] Troj/Killav-DQ posted in the Security & Safety forums; Hi, I had found a Kb16 file (MS-DOS) in system 32 that looked suspicious that is recent, must have come in about the last 2 weeks max. there are also ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 06-30-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 321
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default [Fixed] Troj/Killav-DQ

Hi,
I had found a Kb16 file (MS-DOS) in system 32 that looked suspicious that is recent, must have come in about the last 2 weeks max. there are also a lot (20+) of other files symilar to it named kb & kd things. An example is "Kbdcr.dll" "Kbdir.dll" etc.
So I scanned with windows defender, and didn't find anthing. Had recently stopped using spysweeper, tried a scan with that and it found a "Troj/Killav-DQ" that it says is a self replicating program that can infect computer code, documents, or applications and that it can replicate uncontollably inhibiting system performance, its risk rating is 5 of 5 bars. Spysweeper quarantined it for now, however im not sure that it can delete it with an expired trial version.

I havn't seen anything different inm security task maneger, or any startup programs. I have attached a hjt, also a spysweeper logfile. the virus/trojan is here on Troj/Killav-DQ - Trojan - Sophos threat analysis

nothing seems to be different yet, startup may be slightly slower, and I havn't seen any new processes.

help would be greatly appreciated.

thanks, jake
Attached Files
File Type: txt new hjt on 30.6.07.txt (6.8 KB, 4 views)
File Type: txt Spy Sweeper Session Log 30.6.txt (37.3 KB, 6 views)


__________________
Prework works!


  #2  
Old 06-30-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 321
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default

I have also shredded sectaskman in the location using avgantispyware
C:\Documents and Settings\All Users\Application Data\SecTaskMan
after googling it and finding bad results, also it had a whole range of files that I searched and were known to be bad
"_entreelist" was one of them.
sectaskman - Google Search

services.exe and lsass.exe also seem to be using low cpu.

any suggestions or help would be very appreciated

thanks, jake


  #3  
Old 06-30-2007
elpmek's Avatar
Silver Member
 
Join Date: Feb 2006
Location: Gloucestershire
Posts: 185
PC Experience: Experienced
elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page elpmek - See this Members User comments on their Profile page
Question

chiaz: Comment removed. Malware removal can be a dangerous thing for untrained personnel. For users' safety, we only allow trusted helper groups here to assist in malware removal. Thank you for your understanding. If you would like to be part of the team, please check out:
http://www.pchelpforum.com/hijackthi...tructions.html



Last edited by chiaz; 07-01-2007 at 01:19 AM.
  #4  
Old 07-01-2007
chiaz's Avatar
Senior Security Analyst
 
Join Date: Jun 2006
Location: Singapore
Posts: 2,511
PC Experience: PC Guru
chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page chiaz - See this Members User comments on their Profile page
Default

Hello Jake, your HijackThis log doesn't show much.

Can you please run SUPERAntiSpyware and AVG Anti-Spyware in the Prework (link is in my signature). Attach the new logs in your next reply, and we'll take it from there.


  #5  
Old 07-01-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 321
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default

ok thanks,
a SecTaskMan folder keeps getting created and I keep deleting it for now, the system is going slower. I will post logs soon.

thanks, jake


__________________
Prework works!


  #6  
Old 07-01-2007
jakedude182's Avatar
Gold Member
My PC
 
Join Date: Oct 2006
Posts: 321
PC Experience: Some Experience
jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page jakedude182 - See this Members User comments on their Profile page
Default

ok,
I have attached an avg antispyware log and a new hjt created on normal logon. I didn't have time to do a sas scan, will post another time. The Troj/Killav-DQ is in the spysweeper quarantine, should I delete it?
The computer is performing ok, but services and lsass.exe somtimes use more cpu than normal.

thanks, jake
Attached Files
File Type: txt scanned in safe mode.txt (506 Bytes, 2 views)
File Type: txt hjt on 1.7.07 safe mode.txt (6.7 KB, 3 views)


__________________
Prework works!



Reply
New! Norton Internet Security 2008 – Download Now Click Here

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 03:17 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top