Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: Diddy on November 11, 2012, 01:55:08 AM

Title: Resolved: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 11, 2012, 01:55:08 AM
HI I was wondering if I could ask a question you see we have two computers in the house and I look after the security of them.  My mom told me that the computer that has Windows 7 on it was really slow when I got back home I did a quick scan last night and avast 7 free lased version when finished found one infected file so after I put the trojan in the virus chest it was successfully put in the chest then I was asked to do a boot time scan to do a full clean up so I ran the boot time scan and while the boot time scan was running it found some files that were infected with funweb and my websearch.  My question is this should I worry about the files that are infected with funweb Pup and my web search.  So today after avast 7 free was updated I did a full scan with avast and it got done and said no threat found does this mean that the trojan is no longer on this computer.  I was just wanting some help
the name of the virus is win32: $R9HF5.exe Lockerscreen-MU (TRJ) severty High
Ps: I sent the virus to the virus lab

Thanks and have a great day

 
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: mikaelrask on November 11, 2012, 09:31:21 AM
hey i suggest you follow this guide and attach your logs.

http://forum.avast.com/index.php?topic=53253.0

a malware expert will guide you from there.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 11, 2012, 09:45:21 AM
HI I should mention that I installed and ran malwarebytes free on the second computer witch is Windows 7 and it did not find any threats at all.

Thanks
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: mikaelrask on November 11, 2012, 02:32:37 PM
hey you should follow this guide on the computer avast found the Trojan.

the malware expert needs those logs to be able to help you with your problem.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: TheHulk on November 11, 2012, 03:42:46 PM
Thats why i dont install those softwares as junk on my computer.. all i do use google.co.uk for search
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: mikaelrask on November 11, 2012, 08:07:05 PM
hey thehulk this guide is safe to use and will be needed for the malware expert to be able to help the users with there malware problem.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: TheHulk on November 11, 2012, 08:14:40 PM
hey thehulk this guide is safe to use and will be needed for the malware expert to be able to help the users with there malware problem.

not the guide i mean installed with funweb and my websearch
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 11, 2012, 10:30:14 PM
HI I am scared to do something wrong because the computer I am talking about is my step dad's computer when I found all the funweb stuff and my web search it was only during the boot time scan and it put all that stuff in the virus chest anyways.  I am not an advanced user at all and I am worried about messing something up that I won't be able to fix if I delete the wrong file do you understand.

Thanks for your help everyone

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: DJBone on November 11, 2012, 10:45:01 PM
If you want to be sure (safe) then follow this guide: http://forum.avast.com/index.php?topic=53253.0
You can ask if you don't know something.

DJBone
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 11, 2012, 11:36:39 PM
HI If I install adwcleaner on my Windows Vista computer or the second computer can I just do a scan and safe the results in the program to make sure I am deleting the right stuff and not messing something up is this possible with adwcleaner at all.

Thanks

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 11, 2012, 11:52:37 PM
AdwCleaner will only remove browser/toolbar crap    ;)

if not run, Essexboy will remove the same crap when he see it in the OTL log, but it saves him lots of time and work when creating the OTL fix as he then dont have to include this   ;)
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 01:32:32 AM
hI I was wondering if I could ask what does otl do by oldtimer what does it do exactly and what do I do after the scan is complete what do I do with the log how do I save it and put it on the virus and worms section.

Thanks

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 12, 2012, 01:35:12 AM
it does not do anything until Essexboy instruct it to do so, based on the diagnostic log it produce when you run it first (surf the virus and worms topics and see)

Quote
do I save it and put it on the virus and worms section.
you can save it here as you have already started this topic

Quote
what do I do with the log how
all instructions are in the guide you got link to

Essexboy need the following logs

AdwCleaner
Malwarebytes
OTL
aswMBR


Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 08:00:25 AM
HI I was wanting to ask another question do all these programs in the malware guide work on Windows Vista systems fine.

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Asyn on November 12, 2012, 08:03:50 AM
HI I was wanting to ask another question do all these programs in the malware guide work on Windows Vista systems fine.

Yes.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 08:51:53 AM
HI with Otl do I just simply push run scan button and let it scan do I paste anything in the custom box below or is that after Essboy has had a look at the otl scan log is it just one otl log I put i nmy reply.

Thanks for the help
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: CraigB on November 12, 2012, 08:54:03 AM
You just run the scan and attach the log produced for the experts to examine.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: user_1000 on November 12, 2012, 09:02:39 AM
This is offtopic, but your signature says...

Quote
Windows Vista Home Basic
Ram: 138 GB
Avast free 7.0.1474

Are you sure that you have 138 GB of RAM with Windows Vista Home Basic? Even x64 version of Windows Vista Home Basic can only handle up to 8 GB of RAM.

64-bit Vista Business, Enterprise and Ultimate can handle up to 128 GB of RAM.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 09:08:13 AM
HI I was wondering can some one explain to me please how many logs are their with olt to put in my reply and can someone also explain to me please what do I do when I open olt do I just push the run scan button or the quick scan button and do I do anything else.  I should remind you that have the logs for Windows Vista not windows 7 should I start a new topic for Windows vista and my logs.
I should also mention that I am new at this kind of thing

Thanks very much
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: CraigB on November 12, 2012, 09:14:37 AM
Diddy please go back to this thread http://forum.avast.com/index.php?topic=53253.msg451454#msg451454 and read thoroughly, everything is explained there clearly with detailed instructions and pictures.

Stick with one system at a time otherwise confusion is bound to happen.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 09:53:11 AM
HI I was wanting to ask another question when I run aswmbr should I disable avast free

thanks
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: mchain on November 12, 2012, 09:55:29 AM
hi Diddy,

Here's how it works:

Without the logs nothing can be done.  The user should never attempt to use these programs to fix anything on their own (AdwCleaner is ok); that is why essexboy is fully certified in malware removal.   Just attach the log for AdwCleaner after scanning or deleting bad items.

Never delete an infected file; always quarantine it if possible.
HI I was wanting to ask another question when I run aswmbr should I disable avast free

thanks
EDIT:  Yes, disable Avast! Free temporarily by selecting disable until reboot option.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Asyn on November 12, 2012, 09:57:46 AM
HI I was wanting to ask another question when I run aswmbr should I disable avast free

thanks

No.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 12, 2012, 10:21:47 AM
HI I was wondering can some one explain to me please how many logs are their with olt to put in my reply and can someone also explain to me please what do I do when I open olt do I just push the run scan button or the quick scan button and do I do anything else.  I should remind you that have the logs for Windows Vista not windows 7 should I start a new topic for Windows vista and my logs.
I should also mention that I am new at this kind of thing

Thanks very much
No do not start a new topic.....you have started this, so we dont want you to post all over the forum..
also essexboy is notified about this topic

in essexboys guide, there is a picture of OTL....read instructions above....and under the picture
there is a small scipt you copy and past in the program before you run it


Title: Re: Found one Trojan horse on Windows 7 computer
Post by: TheHulk on November 12, 2012, 10:23:02 AM
in my way.. if my laptop infected, i would wipe off everything and do the fresh install of windows than worrying becoming infected again
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 12, 2012, 10:29:05 AM
in my way.. if my laptop infected, i would wipe off everything and do the fresh install of windows than worrying becoming infected again
thats your way.....but we dont know if it is still infected or if avast saved the day 

so we leave this to those who know.  ;)
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: TheHulk on November 12, 2012, 10:34:22 AM
in my way.. if my laptop infected, i would wipe off everything and do the fresh install of windows than worrying becoming infected again
thats your way.....but we dont know if it is still infected or if avast saved the day 

so we leave this to those who know.  ;)

i know its my way which is quicker way to sort this mess like backup your files on extra hard drive, fresh install windows, install service pack and catch up updates = 2-3hrs
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 12, 2012, 10:38:27 AM
and if its not infected....we dont know yet....then no time at all

please dont derail the topic
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 10:46:26 AM
hI hear are the logs for the four programs and let me remind everyone that the logs are just for Windows Vista home basic only.

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 10:53:38 AM
Sorry I forgot to put the other logs in their
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 10:55:53 AM
HI please let me now if I got everything right sorry any goof ups I am new at this sort of thing I am sorry in advance.

Thanks again

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: mchain on November 12, 2012, 10:56:49 AM
+1

And now we wait....  essexboy will let you know if you actually still have an active infection or if Avast! killed it.

Please be patient.  All looks good from here (posting the logs I mean).
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 11:01:06 AM
hI Thanks Mchain thanks for your help of you I was a bit nervous but now I feel better that all of you on this community are so helpful to put me at ez.
Thanks again every one for your time and help

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 12, 2012, 07:48:28 PM
Hi just to put you mind at rest :

AdwCleaner can do a scan function only if you wish and will still produce a log for me to see
OTL is a diagnostic tool that I can use to remove any bad entries, sometimes it will not be strong enough and I may need to use a stronger tool.  But, I will tell you
AswMBR is again a diagnostic tool, but do not press any button apart from save log  :D
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 12, 2012, 11:45:50 PM
HI Esseyboy So What is it you want me to do with Aswmbr Do you want me to just do a quick scan with it and then save the log file again that correct

Thanks I should mention Esseyboy that I am new to this kind of thing please be patient with me

Thanks again.

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 13, 2012, 12:08:09 AM
the logs are okay posted

guess Essexboy did not see them since they are in reply 29

he is probably in bed now so check back tomorrow
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 13, 2012, 05:29:45 AM
HI Essexboy I just thought I would tell you that if you go to the second page of this topic the logs you need are at the bottom of the second page.  Just letting you now.

Have a good day
ps: the logs are for Windows Vista home Basic only.

thanks
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 13, 2012, 07:14:50 AM
HI I was wondering if someone could please tell me more about Essexboy is he a certified malware expert?  How long has he been cleaning computers of malware infections for?

He will not wreck my computer right he only gets rid of the bad stuff on your computer for you and at the end of this cleaning off the bad stuff my computer will still work right.  Just curious that is all I just want more information that is all.

Thanks very much for your time and help.

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Asyn on November 13, 2012, 07:24:54 AM
1. HI I was wondering if someone could please tell me more about Essexboy is he a certified malware expert?
2. He will not wreck my computer right he only gets rid of the bad stuff on your computer for you and at the end of this cleaning off the bad stuff my computer will still work right.

1. Yes.
2. Right.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 13, 2012, 04:06:29 PM
I am an instructor at GeekstoGo Malware school, but it is only right that you should know who is asking you to run programmes on your system  ;D

Ok this run with OTL will remove the active search bars etc.. that are not considered to be effective or useful as they will only send you where they want as opposed to where you really want to go
I will also remove some redundant elements.
I will also empty all the temporary files/folders on the computer
Prior to all of this OTL will create a restore point for you.

From the logs posted there is no apparent malware just the advertising stuff which will slow down your computer.

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/howfytdl/{3547C6A4-562D-4EA9-B769-7DAD07F1971C}
IE - HKLM\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
IE - HKLM\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://search.speedbit.com/search.aspx?s=CAUe0&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/?s=CAUe0
IE - HKLM\..\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}: "URL" = http://search.imgag.com/?appid=egtb&c=&sbs=2&sc=2&f=web&vernum=3.2&uid=&did=%7bee129ccc-e08f-4afb-a60c-3691dd268bb8%7d&component=&q={searchTerms}
IE - HKCU\..\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}: "URL" = http://search.imgag.com/?appid=egtb&c=&sbs=2&sc=2&f=web&vernum=3.2&uid=&did=%7bee129ccc-e08f-4afb-a60c-3691dd268bb8%7d&component=&q={searchTerms}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=113480&tt=060612_5_&babsrc=SP_ss&mntrId=0c02ff50000000000000001aa072ac13
IE - HKCU\..\SearchScopes\{271DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://jixey.com/?q={searchTerms}&id={8C4D5522-344D-4970-9F3A-48B060C913A8}&src=chr&ver=2.2.5
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://search.speedbit.com/search.aspx?s=CAUe0&q={searchTerms}
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/howfytdl/{3547C6A4-562D-4EA9-B769-7DAD07F1971C}?q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Speedbit Search"
FF - prefs.js..browser.search.defaulturl: "http://search.speedbit.com/search.aspx?s=CAUe0&q="
FF - prefs.js..browser.search.order.1: "Speedbit Search"
FF - prefs.js..keyword.URL: "http://search.speedbit.com/search.aspx?s=CAUe0&q="
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\searchpredict@speedbit.com:
[2011/08/07 18:40:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Clint\AppData\Roaming\Mozilla\Firefox\Profiles\f146a7vj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2012/06/18 22:55:15 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7792546F-70AE-4ABC-B2B6-BE68E9410002} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CF745ACA-6FA6-45ED-AB49-E10A0D1870C5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [Wisdom-soft ScreenHunter 5.1 Free] 0 File not found
O4 - HKCU..\Run: [Wisdom-soft ScreenHunter 6.0 Free] 0 File not found
[2012/10/30 00:01:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeedBit
[2012/10/30 00:01:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Speedbit
[2012/10/30 00:01:29 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedBit
[2012/10/30 00:01:28 | 000,172,032 | ---- | C] (Jin Hui E-mail: jinhui@jcomsoft.com Web: http://www.jcomsoft.com) -- C:\Windows\System32\AniGIF.ocx

:Commands
[resethosts]
[emptytemp]
[Reboot]
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 13, 2012, 09:56:54 PM
HI Essexboy I was wanting to ask some thing when I did the otl log I forgot to put some stuff in the customfix box I am talking about the stuff under the otl in the guide should I re do the scan and put the following stuff in the custom box of otl

Thanks

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 13, 2012, 10:37:27 PM
HI Essexboy I was wanting to ask a question should I have put the following when I did the first scan without the following stuff stuff below does it make a difference in the logs here is the stuff I am talking about below:
    Select All Users
    Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%\*.exe
/md5start
services.*
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
winsock.*
/md5stop

I am  sorry if I forgot to put this stuff in the otl's custom fix box the first time Essexboy.

Let me now if I should do a new scan with Otl Essexboy with stuff included
Sorry about that


CREATERESTOREPOINT
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 14, 2012, 08:06:44 AM
HI Essexboy I followed the directions better and did all the directions right this time here is the otl log for windows Vista and I also copied and pasted everything that was in the guide to the letter this time here is the new otl log with everything that was included only in the guide.

Sorry for the mistake

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 14, 2012, 08:21:07 AM
Quote
here is the otl log for windows Vista
you dont have to tell him.....all tech info is displayed in the logs
and if he needed a new log he would have told you....as he can see how it was run   ;)


NOW follow the instructions and run the fix  in Essexboys reply #39
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 14, 2012, 11:05:32 AM
HI Essexboy I tried your fix and everything seemed fine when I put your fix in the Custom box of olt and pushed the fix button everything seemed to be fine then otl was not responding so I pushed the button to start my computer over again this time I made sure I had all my windows and folders closed and then I did the exact thing again and this time otl was not responding but before that avast free had just updated.  I was wondering Essexboy should I disable avast free before I start the fix with otl.

Thanks have a good day

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 14, 2012, 03:42:22 PM
No that is MBAM being pig awkward again.. On some systems it refuses to stop and blocks OTL

Run this fix and it will sail through

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bigseekpro.com/howfytdl/{3547C6A4-562D-4EA9-B769-7DAD07F1971C}
IE - HKLM\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
IE - HKLM\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://search.speedbit.com/search.aspx?s=CAUe0&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.speedbit.com/?s=CAUe0
IE - HKLM\..\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}: "URL" = http://search.imgag.com/?appid=egtb&c=&sbs=2&sc=2&f=web&vernum=3.2&uid=&did=%7bee129ccc-e08f-4afb-a60c-3691dd268bb8%7d&component=&q={searchTerms}
IE - HKCU\..\SearchScopes\{0BC6E3FA-78EF-4886-842C-5A1258C4455A}: "URL" = http://search.imgag.com/?appid=egtb&c=&sbs=2&sc=2&f=web&vernum=3.2&uid=&did=%7bee129ccc-e08f-4afb-a60c-3691dd268bb8%7d&component=&q={searchTerms}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&affID=113480&tt=060612_5_&babsrc=SP_ss&mntrId=0c02ff50000000000000001aa072ac13
IE - HKCU\..\SearchScopes\{271DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://jixey.com/?q={searchTerms}&id={8C4D5522-344D-4970-9F3A-48B060C913A8}&src=chr&ver=2.2.5
IE - HKCU\..\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}: "URL" = http://www.icq.com/search/results.php?q={searchTerms}&ch_id=osd
IE - HKCU\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://search.speedbit.com/search.aspx?s=CAUe0&q={searchTerms}
IE - HKCU\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://www.bigseekpro.com/search/browser/howfytdl/{3547C6A4-562D-4EA9-B769-7DAD07F1971C}?q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Speedbit Search"
FF - prefs.js..browser.search.defaulturl: "http://search.speedbit.com/search.aspx?s=CAUe0&q="
FF - prefs.js..browser.search.order.1: "Speedbit Search"
FF - prefs.js..keyword.URL: "http://search.speedbit.com/search.aspx?s=CAUe0&q="
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\searchpredict@speedbit.com:
[2011/08/07 18:40:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Clint\AppData\Roaming\Mozilla\Firefox\Profiles\f146a7vj.default\extensions\{5911488E-9D1E-40ec-8CBB-06B231CC153F}
[2012/06/18 22:55:15 | 000,000,000 | ---D | M] (Babylon) -- C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7792546F-70AE-4ABC-B2B6-BE68E9410002} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CF745ACA-6FA6-45ED-AB49-E10A0D1870C5} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKCU..\Run: [Wisdom-soft ScreenHunter 5.1 Free] 0 File not found
O4 - HKCU..\Run: [Wisdom-soft ScreenHunter 6.0 Free] 0 File not found
[2012/10/30 00:01:40 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeedBit
[2012/10/30 00:01:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Speedbit
[2012/10/30 00:01:29 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedBit
[2012/10/30 00:01:28 | 000,172,032 | ---- | C] (Jin Hui E-mail: jinhui@jcomsoft.com Web: http://www.jcomsoft.com) -- C:\Windows\System32\AniGIF.ocx

:Commands
[resethosts]
[emptyjava]
[Reboot]
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 14, 2012, 10:23:00 PM
HI Essexboy I have i am still having trouble otl starts go and then it gets stuck on firefox and it will not go any further.  I uninstalled malwarebytes free off of my computer.  so I put the fix back into otl and pushed on the fix button but again otl was not responding.  What can I do.

Thanks for the help

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 14, 2012, 11:26:03 PM
Unfortunately that means that there is a corrupt file/folder in firefox.   It appears that your computer is one of the few that gets a bit uppity with OTL, it happens I'm afraid.  The files etc that I am removing are easily handled by AdwCleaner so if you wish to run the scan on that and post the log I will highlight the ones to select for deletion 

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 14, 2012, 11:36:05 PM
HI here is the adwcleaner log you wish to have.

Thanks
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: TheHulk on November 15, 2012, 08:10:42 AM
boy! still having problems???? o.o

fresh install of windows will sort out the problems like I said before
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: SpeedyPC on November 15, 2012, 08:21:45 AM
Let Essexboy make that call TheHulk IF he need to reformat his HD and reinstall of windows will sort out the problems.

Essexboy is very good at this solving problem this way without reformatting his HD and reinstall of windows.
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 15, 2012, 08:25:39 AM
naaaa...Speedy.... firefox problems are easyer solved with a reinstall.  ;D
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: SpeedyPC on November 15, 2012, 08:28:42 AM
naaaa...Speedy.... firefox problems are easyer solved with a reinstall.  ;D

I know that Pondus ;) :P depend on how bad is this Trojan horse he has on his HD
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Pondus on November 15, 2012, 08:34:22 AM
he may have to buy a new computer.  ;)
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 15, 2012, 08:57:31 AM
HI everyone I am sorry I did not make things clear the first time this computer that I am using to type these messages for help under this topic is Windows Vista home basic I made a mistake though when I put on here as the topic title Windows 7.  This is not a Windows 7 operating system
my Windows Vista does not have a virus on it just a bunch of toolbars at least thats what Essexboy told me in a post any ways.

Thanks
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 15, 2012, 09:01:11 AM
hI Essexboy I was wondering I have uninstalled firefox off of my computer for now I was wondering what would happen if you removed the fix for firefox extensions would the fix and otl work fine then or would it be worthless try this solution.

Thanks

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 15, 2012, 03:03:33 PM
Everything shown in adwcleaner is stuff that you do not need on your computer, so you could run and select delete to remove them

Uninstall Firefox by all means but it will need to be a full uninstall http://support.mozilla.org/en-US/kb/uninstall-firefox-from-your-computer

It must be stated here that I have never been impressed with firefox and I stick to IE (currently running IE10) .. Watch the fireworks begin  ;D

After the Firefox uninstall then run the OTL fix as there may still be some FF related entries
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 16, 2012, 06:19:08 AM
HI Essexboy I have uninstalled Firefox fully from my computer and I have removed the mozilla firefox folders from my computer.  I was also going to ask another question Essexboy I would like to run adwcleaner but when it gets done scanning I am afraid that I will delete the wrong file and if windows needs that file then I cannot get that file back right I don't want to goof up my computer.  I re tried otl and the fix and again otl hung on me again so what should I do now.
please guide me what I should do

Thanks



Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 16, 2012, 08:20:45 AM
HI Essexboy I took your advice and used adwcleaner and deleted the toolbars and stuff off my computer and let adwcleaner reboot my computer then the log came back up but I made a mistake I looked at the long and closed it by accident without saving it first so I did another search and saved the file for you to look at sorry for the goof up.  I was wondering when adwcleaner produced the log the first time and I pushed the x to close the long the first time I noticed that adwcleaner was still open waiting for an action how many times does adwcleaner have to reboot my computer to clean out the toolbars and stuff off of my computer.
here is the log

ps: let me now if you want me to do anything else Essexboy

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: mchain on November 16, 2012, 08:31:37 AM
You are now good to go as far as attaching that log.  Now we wait for essexboy to come around and have a look-see...
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 16, 2012, 04:11:02 PM
No problem there as the last adw log came up clean so it had removed all the stuff that I was going to use OTL for

The main thing now is how is the computer behaving ?

Could you try one further OTL scan please - no script necessary this time
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 16, 2012, 09:50:18 PM
HI Essexboy I now what you mean to run one last otl for you to look at the log what do no mean no script this time I do not understand please explain.l
Do you want me to do a quck scan with otl this time as well.

have a good day

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 16, 2012, 09:56:27 PM
Yes just run OTL and press quick scan, there will be just one log 
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 17, 2012, 12:38:09 AM
HI Essexboy here the otl log you wanted.
Have a good day

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 17, 2012, 01:57:18 AM
HI Essexboy my computer is behaving well but internet Explorer 9 at times will freeze up on a website and I cannot exit back to the desktop I was wondering is their a tool that can repair internet Explorer or should I uninstall internet Explorer and reinstall it.

Thanks for your help Essexboy

Thanks again.

Title: Re: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 17, 2012, 01:56:50 PM
Download  Windows Repair (all in one)  from this site (http://www.tweaking.com/content/page/windows_repair_all_in_one.html)

Install the programme then run

(https://dl.dropbox.com/u/73555776/waio%20start.JPG)

Go to step 3 and allow it to run SFC
(https://dl.dropbox.com/u/73555776/waio%20step3.JPG)


On the start repairs tab click start
(https://dl.dropbox.com/u/73555776/waiostart%20rep.JPG)

Select the repair IE and tick restart system when finished
(https://dl.dropbox.com/u/73555776/waio%20rep%20list.JPG)
Title: Re: Found one Trojan horse on Windows 7 computer
Post by: Diddy on November 18, 2012, 10:15:12 AM
HI Essexboy The all in one Windows tool worked great my computer is much faster and Internet Explorer works much better as well.  The only problem I had was smaill when the tool was done the repair the security center came up in the tool bar security alerts and it could not find any virus program so uninstalled avast free off my computer and reinstalled avast free back on my computer and the Security alerts box went away off the tool bar.  That was an easy fix.

Thanks very much Essexboy for the help and your time and the programs if I have any problems or infections on any of my computers in the future I will get you to help me again.

Thanks Essexboy again for your help and time
Talk to you later.
Ps: Without you Essexboy I could not have done this without you so a big thanks.

Title: Re: Resolved: Found one Trojan horse on Windows 7 computer
Post by: essexboy on November 18, 2012, 01:22:58 PM
Glad to hear, you can uninstall Windows all in one via control panel (Unless you wish to keep it)
For AdwCleaner just run that and press the uninstall button
For OTL run it and press the cleanup button, that should remove all the tools we used