Author Topic: trojan for me  (Read 15274 times)

0 Members and 1 Guest are viewing this topic.

mantra

  • Guest
trojan for me
« on: April 04, 2005, 07:05:00 PM »
Backdoor.Win32.VB.ye

can somebody tell the damage that it did to my  pc?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: trojan for me
« Reply #1 on: April 04, 2005, 07:18:05 PM »
Have you tried a google search for this?

A search for 'Backdoor.Win32.VB' returns many hits.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Wight

  • Guest
Re: trojan for me
« Reply #2 on: April 04, 2005, 07:25:24 PM »
Backdoors in general allowes unauthorized entry to infected computers so it is very hard if not impossible to say what damage it has done.

Post your hijackthis log here and we will see what we can do.

Anyway to prevent further damage done by other malicious programs, visit windows update and apply all patches, update avast! definitions and scan your computer in safe mode(press F8 during boot).

mantra

  • Guest
Re: trojan for me
« Reply #3 on: April 04, 2005, 07:40:41 PM »
Logfile of HijackThis v1.97.7
Scan saved at 19.39.38, on 04/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Agnitum\Outpost Firewall\outpost.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
G:\Programmi\foobar2000\foobar2000.exe
C:\Programmi\DC++\DCPlusPlus.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
D:\backup cd\SICUREZZA\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jus.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: RAID Manager.lnk = C:\Programmi\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O9 - Extra button: Trashcan (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan (HKCU)
O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED15160C-A60E-40CA-91F2-D7396DA10D15}: NameServer = 193.70.192.25,195.70.156.25

mantra

  • Guest
Re: trojan for me
« Reply #4 on: April 04, 2005, 07:43:21 PM »
have u this file? csrss.exe

Offline xistenz

  • Poster
  • *
  • Posts: 632
« Last Edit: April 04, 2005, 07:53:51 PM by xistenz »

whocares

  • Guest
Re: trojan for me
« Reply #6 on: April 04, 2005, 07:56:02 PM »
Hi mantra,

- please update to HJT 1.99.1, via internal updater, or via links found here in the board..
and then edit or post a new HJT-log

- where exactly was the trojan found (full path/folder/Filename.) ?


CSRSS.exe should be ok, if found here:
C:\WINDOWS\system32\CSRSS.EXE

->  http://www.liutilities.com/products/wintaskspro/processlibrary/csrss/



 ;)
« Last Edit: April 04, 2005, 07:57:53 PM by whocares »

mantra

  • Guest
Re: trojan for me
« Reply #7 on: April 04, 2005, 08:01:20 PM »
Logfile of HijackThis v1.99.1
Scan saved at 20.00.05, on 04/04/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Agnitum\Outpost Firewall\outpost.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
G:\Programmi\foobar2000\foobar2000.exe
C:\Programmi\DC++\DCPlusPlus.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Outlook Express\msimn.exe
D:\backup cd\SICUREZZA\HijackThis\HijackThis.exe
C:\DOCUME~1\Mantra\IMPOST~1\Temp\Rar$EX00.953\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jus.it/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: RAID Manager.lnk = C:\Programmi\ITE\ITE IT8212 ATA RAID Controller\RaidMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra button: Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1\TRASH.EXE (HKCU)
O9 - Extra 'Tools' menuitem: Show Trashcan - {072F3B8A-2DA2-40e2-B841-88899F240200} - C:\PROGRA~1\Agnitum\OUTPOS~1\TRASH.EXE (HKCU)
O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED15160C-A60E-40CA-91F2-D7396DA10D15}: NameServer = 193.70.192.25,195.70.156.25
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

mantra

  • Guest

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojan for me
« Reply #9 on: April 04, 2005, 08:14:00 PM »
Mantra, if you try an on-line analisys of your Hijackthis log file, will it help?
Try here http://hijackthis.de/index.php
The best things in life are free.

lee16

  • Guest
Re: trojan for me
« Reply #10 on: April 04, 2005, 09:24:42 PM »
Hi mantra,

About your log, if you do not recognize this address, then delete it from hijackthis:

O17 - HKLM\System\CCS\Services\Tcpip\..\{ED15160C-A60E-40CA-91F2-D7396DA10D15}: NameServer = 193.70.192.25,195.70.156.25

Other then that, its clean.


Quote
http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453089442

If your sure thats the virus you have, then follow the removal instructions on that page.

--lee

mantra

  • Guest
Re: trojan for me
« Reply #11 on: April 05, 2005, 08:22:13 AM »
Quote
O17 - HKLM\System\CCS\Services\Tcpip\..\{ED15160C-A60E-40CA-91F2-D7396DA10D15}: NameServer = 193.70.192.25,195.70.156.25


i don't know what is it?

lee16

  • Guest
Re: trojan for me
« Reply #12 on: April 05, 2005, 12:24:51 PM »
Well it can belong to one of three things:

Your Company
Your ISP (who you pay your Internet bill to)
Malware provier


Without knowing more about it, i can't know exactly whether you can remove it, thats why i was hoping you would know.

You could try these:

If your on a company network, ask your Admin about it.

If your at home with the internet, phone your ISP and ask them about it.

If none of them know, use hijackthis to remove the entry.

--lee

mantra

  • Guest
Re: trojan for me
« Reply #13 on: April 05, 2005, 03:38:16 PM »
Quote
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

what is it pml driver???

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: trojan for me
« Reply #14 on: April 05, 2005, 03:42:52 PM »
Quote
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

what is it pml driver???

What is a Google search for HPZipm12.exe - http://www.liutilities.com/products/wintaskspro/processlibrary/hpzipm12/ the tools are there to help you learn to use them. Once you find out what it is you can then decide if it is something that should be on your system.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security