There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
acer black screen blue screen blue screen of death boot computer connection crash css dell display driver drivers error firefox firefox 3 game hard drive internet internet explorer itunes laptop lcd linux malware monitor network networking outlook outlook 2003 outlook express partition password printer problem problems ram router security slow software sound sprtcmd.exe trojan usb virus vista windows windows xp wireless
Hardware
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Software & Hardware > Hardware >
Solved: strange noise from computer was Unknown Backdoor Trojan -


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

Closed Thread
 
Thread Tools
Holly3278's Avatar
Computer Specs
Senior Member with 946 posts.
 
Join Date: Jan 2003
Location: USA
Experience: Intermediate
04-Nov-2004, 06:58 AM #1
Exclamation Solved: Strange Clicking Noise coming from PC
Hi everyone. I seem to have gotten an "Unknown Backdoor Trojan" on my computer detected by an online Pest Patrol scan at http://www.pestpatrol.com/. None of my spyware scanners have detected this but the online scan did. It says that it goes by these aliases:

Backdoor.Lixy.h [Kaspersky]
Trojan.BAT.DeltreeY.bs [Kaspersky]
Trojan.Win32.Fynben.b [Kaspersky]
Trojan.Win32.TalkStocks.a [Kaspersky]

I had detected this trojan on my computer yesterday after doing a scan and then had to format my computer and reinstall everything to get rid of it. I updated everything and installed two firewalls plus Windows firewall and two anti-viruses (Norton and AVG) and I still have the trojan! Last night I scanned with Pest Patrol after the format and it wasn't there. Then my computer started acting up this morning and I scanned again and the trojan was back. I have now idea how I am getting this trojan! I use Webroot Spysweeper, Spybot Search and Destroy, Adaware (Spybot and Adaware are not yet downloaded and installed again), and Spyware Blaster. How on earth am I getting this thing?! What can I do to prevent it from coming back? I have 1 year of computer networking training and as far as I know I am not doing anything risky that would make me get this. Please help!

Here's a link to the page that Pest Patrol gave me about all this:

http://pestpatrol.com/pestinfo/U/Unk...0and%20Removal
__________________
Holly
Op Sys: Windows XP Professional SP3
RAM: 512 mb
HD Total Space: 80 gigs
Processor: Intel Pentium 4 2.53 ghz
Video Card: NVidia Geforce FX 5500 256 mb DDR RAM

Last edited by Holly3278 : 04-Nov-2004 09:43 AM.
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 07:09 AM #2
It is some sort of spyware application that has piggybacked on a supposedly good one and you have obviously re-installed it along with something else

go to http://www.thespykiller.co.uk/files/HijackThis.exe and download 'Hijack This!'.
make sure it is placed into it's own folder, not a temporary folder. Then doubleclick the Hijackthis.exe.
Click the "Scan" button, when the scan is finished the scan button will become "Save Log" click that and save the log.
Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.
It will possibly show issues deserving our attention, but most of what it lists will be harmless or even required,
so do NOT fix anything yet.
Someone here will be happy to help you analyze the results.
__________________
Derek
Microsoft MVP/Windows - Security
For help with spyware or hijackers thespykiller

please help me by donating to help keep the Hedgehog Rescue Centre running
We Care about Animals and the Environment
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 07:13 AM #3
But Pest patrol is known for false positives and the online scanner is NOT the most reliable of scanners
Holly3278's Avatar
Computer Specs
Senior Member with 946 posts.
 
Join Date: Jan 2003
Location: USA
Experience: Intermediate
04-Nov-2004, 07:17 AM #4
Quote:
Originally Posted by dvk01
But Pest patrol is known for false positives and the online scanner is NOT the most reliable of scanners
I kind of thought that. But this still worries me. Is there any way to confirm whether or not I have a trojan?
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 07:17 AM #5
I just did the PP online scan to check my "CLEAN" system

it finds an unknown BHO that should be removed according to it

The unknown BHO is M$ money viewer which I use daily

Never do a format & install or delete anything on the advice of one online scanner always ask for advice first

I am 99% sure that it is one of the usual PP false positives
__________________
Derek
Microsoft MVP/Windows - Security
For help with spyware or hijackers thespykiller

please help me by donating to help keep the Hedgehog Rescue Centre running
We Care about Animals and the Environment
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 07:19 AM #6
Quote:
Originally Posted by Holly3278
I kind of thought that. But this still worries me. Is there any way to confirm whether or not I have a trojan?

Post your hijackthis log and we'll check

all the aliases you quoted are totally different beasts and there is no way that ONE suspct is known by all those names especially from one Antivirus company Kapersky
Holly3278's Avatar
Computer Specs
Senior Member with 946 posts.
 
Join Date: Jan 2003
Location: USA
Experience: Intermediate
04-Nov-2004, 07:20 AM #7
Logfile of HijackThis v1.98.2
Scan saved at 7:19:56 AM, on 11/4/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Intel\Intel(R) Active Monitor\imonnt.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Juno6\qs\exec.exe
C:\Program Files\Juno6\qs\exec.exe
C:\Hijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.juno.com/s/search?r=minisearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://my.juno.com/z4/resetpassword_redirect.html
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\JUSearch\SearchEnh1.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [IMONTRAY] C:\Program Files\Intel\Intel(R) Active Monitor\imontray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [spc_w] "C:\Program Files\JUSearch\hcm.exe" -w
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Trillian.lnk = ?
O8 - Extra context menu item: Show All Original Images - "res://C:\Program Files\Juno6\qsacc\appres.dll/228"
O8 - Extra context menu item: Show Original Image - "res://C:\Program Files\Juno6\qsacc\appres.dll/227"
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3913E765-0708-488D-A140-D18EA27A0EAC}: NameServer = 64.136.20.121 64.136.28.121
O17 - HKLM\System\CS1\Services\Tcpip\..\{3913E765-0708-488D-A140-D18EA27A0EAC}: NameServer = 64.136.20.121 64.136.28.121
__________________
Holly
Op Sys: Windows XP Professional SP3
RAM: 512 mb
HD Total Space: 80 gigs
Processor: Intel Pentium 4 2.53 ghz
Video Card: NVidia Geforce FX 5500 256 mb DDR RAM
Holly3278's Avatar
Computer Specs
Senior Member with 946 posts.
 
Join Date: Jan 2003
Location: USA
Experience: Intermediate
04-Nov-2004, 07:31 AM #8
Quote:
Originally Posted by dvk01
I just did the PP online scan to check my "CLEAN" system

it finds an unknown BHO that should be removed according to it

The unknown BHO is M$ money viewer which I use daily

Never do a format & install or delete anything on the advice of one online scanner always ask for advice first

I am 99% sure that it is one of the usual PP false positives
Oh well the format and reinstall was no big deal for me. I do one approximately every 3 months. Besides, my computer had a couple of issues that I wanted to fix and simply felt like formatting it instead of spending many more hours fixing. Basically it was some kind of problem with SP2 or Internet Explorer. I don't have much stuff to have to backup so it was no big deal. In fact, I didn't back up anything because it had only been about 2 weeks since my last format which was because of something else that skips my mind at this point.
__________________
Holly
Op Sys: Windows XP Professional SP3
RAM: 512 mb
HD Total Space: 80 gigs
Processor: Intel Pentium 4 2.53 ghz
Video Card: NVidia Geforce FX 5500 256 mb DDR RAM
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 07:32 AM #9
I can see absolutely nothing wrong there

I would assume that PP is giving a FP on the juno search entries which is quite a common occurrence with several so called malware removal programs
Holly3278's Avatar
Computer Specs
Senior Member with 946 posts.
 
Join Date: Jan 2003
Location: USA
Experience: Intermediate
04-Nov-2004, 07:37 AM #10
Quote:
Originally Posted by dvk01
I can see absolutely nothing wrong there

I would assume that PP is giving a FP on the juno search entries which is quite a common occurrence with several so called malware removal programs
Hmm, glad to hear that. Is there anything else I should do? Also, a trojan wouldn't cause my computer's system speaker or something to click when I type would it? My computer makes this clicking noise when I type and sometimes when I'm just at the computer. I think what's happening is the desk is moving a little or something and something is rattling. I am wondering if it might be my case fan cause it's pretty dirty. I took an air can to it a few weeks ago but it didn't help much. Thing is, the clicking just started this past weekend. Either that or I just started noticing it then. I hope this isn't a dumb question.
__________________
Holly
Op Sys: Windows XP Professional SP3
RAM: 512 mb
HD Total Space: 80 gigs
Processor: Intel Pentium 4 2.53 ghz
Video Card: NVidia Geforce FX 5500 256 mb DDR RAM
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 07:40 AM #11
have you got a microphone or headset laying on the desk that might be switched on
Holly3278's Avatar
Computer Specs
Senior Member with 946 posts.
 
Join Date: Jan 2003
Location: USA
Experience: Intermediate
04-Nov-2004, 07:49 AM #12
Quote:
Originally Posted by dvk01
have you got a microphone or headset laying on the desk that might be switched on
No, the only microphone I have is built into my webcam. However, I know that I only started noticing the problem after I installed new speakers for my computer. One of the old ones went dead.
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 07:59 AM #13
Quote:
Originally Posted by Holly3278
No, the only microphone I have is built into my webcam. However, I know that I only started noticing the problem after I installed new speakers for my computer. One of the old ones went dead.
Is that turned on ?

Possibly the new speakers are more sensitive than the old ones and picking up the webcam input at a lower volume
Holly3278's Avatar
Computer Specs
Senior Member with 946 posts.
 
Join Date: Jan 2003
Location: USA
Experience: Intermediate
04-Nov-2004, 08:12 AM #14
Quote:
Originally Posted by dvk01
Is that turned on ?

Possibly the new speakers are more sensitive than the old ones and picking up the webcam input at a lower volume
Hmmm, as far as I know it's not turned on. It's plugged into the USB port though. Let's see here. I unplugged the cam and it's still making that noise so I don't think it's the mic in the cam.
dvk01's Avatar
Moderator with 24,777 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
04-Nov-2004, 08:20 AM #15
Pass

I'll move this to hardware now where someone else might have a better idea
Closed Thread

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who help people like you solve computer problems. See our Welcome Guide to get started.



Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 05:47 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.