Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
Solved: Trojan Horse - Downloader.Generic4.DEM (New)

Reply  
Thread Tools
morpheus63's Avatar
Computer Specs
Member with 68 posts.
 
Join Date: Apr 2007
Experience: Advanced
22-Apr-2007, 08:07 PM #31
Its running okay, but this is what happened last time. It ran okay for a few days and then it went crazy again, so I believe there is something still lurking within the system.

I'm still getting the occasional pop up from SuperAntiSpyware warning me of infections. There is something still lurking because IE occasionally pops up and something is still trying to redirect it. I'm still getting Vundo and having to kill it every few days.....there is something definately still lurking that we need to get rid of.
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
22-Apr-2007, 08:38 PM #32
I can understand that. And honestly, I don't think all of the baddies are gone. The amount of infection in your WinPFind log was enormous. I couldn't enter all of them into Avenger. It was 5 posts worth. I do feel a full format and reinstall is the best option.
__________________
Microsoft MVP - Consumer Security
If we've helped you, please donate to TSG!
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
22-Apr-2007, 08:59 PM #33
I'd really like us to try to avoid that though. Let's try a different route.

Download WinPFind3U.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
    • In the Processes group click ALL
    • In the Win32 Services group click ALL
    • In the Driver Services group click ALL
    • In the Registry group click ALL
    • In the Files Created Within group click 60 days Make sure Non-Microsoft only is UNCHECKED
    • In the Files Modified Within group select 30 days Make sure Non-Microsoft only is UNCHECKED
    • In the File String Search group select ALL
    in the Additional scans sections please press select ALL
  • Now click the Run Scan button on the toolbar.
  • The program will be scanning huge amounts of data so depending on your system it could take a long time to complete. Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Save that notepad file but click on the "Format" menu and make sure that "word wrap" is not checked. If it is then click on it to uncheck it.
Upload the report as an attachment please.
__________________
Microsoft MVP - Consumer Security
If we've helped you, please donate to TSG!
morpheus63's Avatar
Computer Specs
Member with 68 posts.
 
Join Date: Apr 2007
Experience: Advanced
23-Apr-2007, 01:21 AM #34
Hi Moderator,

Thanks, I would rather not ahve to reload everything and reformat....thats my worst nightmare.

Please find attached logfile for WinPFind3U.
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
23-Apr-2007, 07:09 PM #35
I'll be back later with the fix, I have to go through all the items.
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
23-Apr-2007, 08:00 PM #36
Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program. Copy and paste the information in the quote box below into the pane where it says "Paste fix here" and then click the Run Fix button. Then reboot and post a new HijackThis log please.

Quote:
[Files/Folders - Created Within 60 days]
NY -> geeef.dll -> %System32%\geeef.dll
NY -> feeeg.ini -> %System32%\feeeg.ini
NY -> oifrkxgj.dll -> %System32%\oifrkxgj.dll
NY -> yabxx.dll -> %System32%\yabxx.dll
NY -> ggfhk.ini -> %System32%\ggfhk.ini
NY -> xxbay.ini -> %System32%\xxbay.ini
NY -> syqnoieb.dll -> %System32%\syqnoieb.dll
NY -> eghflojg.dll -> %System32%\eghflojg.dll
NY -> oqrqr.ini -> %System32%\oqrqr.ini
NY -> ehkkj.ini -> %System32%\ehkkj.ini
[Files/Folders - Modified Within 30 days]
NY -> geeef.dll -> %System32%\geeef.dll
NY -> feeeg.ini -> %System32%\feeeg.ini
NY -> oifrkxgj.dll -> %System32%\oifrkxgj.dll
NY -> yabxx.dll -> %System32%\yabxx.dll
NY -> ggfhk.ini -> %System32%\ggfhk.ini
NY -> xxbay.ini -> %System32%\xxbay.ini
NY -> syqnoieb.dll -> %System32%\syqnoieb.dll
NY -> eghflojg.dll -> %System32%\eghflojg.dll
NY -> oqrqr.ini -> %System32%\oqrqr.ini
NY -> ehkkj.ini -> %System32%\ehkkj.ini
[File String Scan - All]
NY -> UPX! , UPX0 , -> %System32%\geeef.dll
NY -> UPX! , UPX0 , -> %System32%\yabxx.dll
morpheus63's Avatar
Computer Specs
Member with 68 posts.
 
Join Date: Apr 2007
Experience: Advanced
24-Apr-2007, 04:15 AM #37
Logfile of HijackThis v1.99.1
Scan saved at 5:13:41 PM, on 24/04/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZONELABS\vsmon.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Evidence Eliminator\ee.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\OLYMPUS\CAMEDIA Master 4.2\CM_camera.exe
C:\Program Files\Qlock\qlock.exe
C:\Program Files\HijackThis\HijackThis.exe

O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: qlock.lnk = C:\Program Files\Qlock\qlock.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: CAMEDIA Master.lnk = C:\Program Files\OLYMPUS\CAMEDIA Master 4.2\CM_camera.exe
O8 - Extra context menu item: Open Image in New Window - res://C:\Program Files\PopUpCop\popupcop.dll/imagenew
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted IP range: 206.161.125.149
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab30149.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1171625914356
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {F0230524-9D39-4E84-8452-41C592961EA7} (Installer Class) - http://www.tradeexit.com/Config.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: CLSID - C:\WINNT\
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINNT\system32\ZONELABS\vsmon.exe
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
24-Apr-2007, 02:11 PM #38
Rescan with Hijack This.
Close all browser windows except Hijack This.
Put a check mark beside these entries and click "Fix Checked".

O20 - Winlogon Notify: CLSID - C:\WINNT\

Reboot. How are things now?
morpheus63's Avatar
Computer Specs
Member with 68 posts.
 
Join Date: Apr 2007
Experience: Advanced
25-Apr-2007, 10:36 AM #39
Hi Moderator,

All looks good....it has now been stable for a few days and no pops or redirections.

I scanned again with both AVG Anti Spyware and SuperAntiSpyware and they both produced good results. They both brought up some tracking cookies but nothing serious or malicious.

Thanks...fingers and toes crossed.
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
25-Apr-2007, 05:37 PM #40
Great


Read here on How to tighten your computer's security settings: http://forums.techguy.org/t208517.html

Security Help Tools: http://forums.techguy.org/security/1...elp-tools.html

You can mark your thread "Solved" from the Thread Tools drop down menu.
morpheus63's Avatar
Computer Specs
Member with 68 posts.
 
Join Date: Apr 2007
Experience: Advanced
27-Apr-2007, 08:42 AM #41
Hi Moderator,

Great job! I've been monitoring the system now for a few days and all is going well.

Thanks again. Well done!
Cheeseball81's Avatar
Moderator & Malware Removal Specialist with 80,168 posts.
 
Join Date: Mar 2004
Location: Long Island, NY
Experience: Advanced
28-Apr-2007, 03:27 PM #42
My pleasure. You too!
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:32 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.