Author Topic: I Have Tro Jans HELP  (Read 18439 times)

0 Members and 1 Guest are viewing this topic.

Tom2Die

  • Guest
Re: I Have Tro Jans HELP
« Reply #30 on: June 25, 2007, 04:15:15 AM »
Here is my Winpfind3u log (attached)

Tom2Die

  • Guest
Re: I Have Tro Jans HELP
« Reply #31 on: June 25, 2007, 04:17:19 AM »
for mauserme:

File/Folder C:\WINDOWS\system32\cgdncaox.dll not found.
 
Created on 06/24/2007 22:16:16

i think u told me to quarantine it or something maybe?

mauserme

  • Guest
Re: I Have Tro Jans HELP
« Reply #32 on: June 25, 2007, 01:13:44 PM »
AVG Antispyware may have removed a lot of the problems.

Have you run the registry fix yet?  Don't forget to do that.

EDIT:  I see only one or two suspicious items in winpfind but we're going to wait for essexboy on this.   I don't have enough experience with it yet.
« Last Edit: June 25, 2007, 01:19:05 PM by mauserme »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I Have Tro Jans HELP
« Reply #33 on: June 25, 2007, 10:20:10 PM »
Speak and I appear.  Okey Dokey lets get rid of the hidden initiators now

Start WinPFind3U. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

Quote
[Win32 Services - Non-Microsoft Only]
YY -> (AppServer9PE) SunJavaSystemAppserver9PE [Win32_Own | Disabled | Stopped] ->
YY -> (DomainService) DomainService [Win32_Own | Auto | Stopped] -> %System32%\xdknteve.exe
[Registry - Non-Microsoft Only]
< Default Protocols [HKLM] - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
YN -> shell -> shell protocol not assigned
< Default Protocols [HKCU] - Select to Repair > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProtocolDefaults
YN -> shell -> shell protocol not assigned
[Files/Folders - Created Within 30 days]
NY -> bayhisqg.ini -> %System32%\bayhisqg.ini
NY -> cekvbjpr.ini -> %System32%\cekvbjpr.ini
NY -> dlyriahh.ini -> %System32%\dlyriahh.ini
NY -> ephaausc.ini -> %System32%\ephaausc.ini
NY -> fbksrfbj -> %System32%\fbksrfbj
NY -> gqjqrehn.ini -> %System32%\gqjqrehn.ini
NY -> hqnbppfe.ini -> %System32%\hqnbppfe.ini
NY -> installer_s.exe -> %System32%\installer_s.exe
NY -> kdghobop.ini -> %System32%\kdghobop.ini
NY -> khnrvepx.ini -> %System32%\khnrvepx.ini
NY -> ksamqaju.ini -> %System32%\ksamqaju.ini
NY -> oennmuok.ini -> %System32%\oennmuok.ini
NY -> polidkmx.ini -> %System32%\polidkmx.ini
NY -> seinlptb.ini -> %System32%\seinlptb.ini
NY -> ueugexcr.ini -> %System32%\ueugexcr.ini
[Files/Folders - Modified Within 30 days]
NY -> gc_701.cnf -> %SystemRoot%\gc_701.cnf
NY -> gf1002.cnf -> %SystemRoot%\gf1002.cnf
NY -> gf1002.cnf2 -> %SystemRoot%\gf1002.cnf2
NY -> gsc_701.cnf -> %SystemRoot%\gsc_701.cnf
NY -> imsins.BAK -> %SystemRoot%\imsins.BAK
NY -> dlyriahh.ini -> %System32%\dlyriahh.ini
NY -> ephaausc.ini -> %System32%\ephaausc.ini
NY -> fbksrfbj -> %System32%\fbksrfbj
NY -> gqjqrehn.ini -> %System32%\gqjqrehn.ini
NY -> hqnbppfe.ini -> %System32%\hqnbppfe.ini
NY -> installer_s.exe -> %System32%\installer_s.exe
NY -> kdghobop.ini -> %System32%\kdghobop.ini
NY -> khnrvepx.ini -> %System32%\khnrvepx.ini
NY -> ksamqaju.ini -> %System32%\ksamqaju.ini
NY -> mcrh.tmp -> %System32%\mcrh.tmp
NY -> oennmuok.ini -> %System32%\oennmuok.ini
NY -> polidkmx.ini -> %System32%\polidkmx.ini
NY -> seinlptb.ini -> %System32%\seinlptb.ini
NY -> ueugexcr.ini -> %System32%\ueugexcr.ini
[File String Scan - Non-Microsoft Only]
NY -> UPX! , UPX0 , -> %System32%\installer_s.exe


The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new WinPFind3u scan.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

I await your reply plus an update on how the system is running

mauserme

  • Guest
Re: I Have Tro Jans HELP
« Reply #34 on: June 26, 2007, 04:38:57 AM »
Speak and I appear. 
Well, I do have the consolation of knowing the two I spotted are in your rather lengthy list ...  ;D

I've PM'd you - the learning curve is very steep for me on this tool.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: I Have Tro Jans HELP
« Reply #35 on: June 26, 2007, 08:00:08 PM »
Learning is never ending  ???

mauserme

  • Guest
Re: I Have Tro Jans HELP
« Reply #36 on: June 26, 2007, 08:18:34 PM »
Learning is never ending  ???
No it isn't - and I don't want it to.  But looking at this for essentially the first time is a bit duanting.

Well, I'm sure I'll get there - I have with other tools.   I just wish there was a tutorial for winpfind3a