Author Topic: trojano attack-- cant remove  (Read 24453 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33923
  • malware fighter
Re: trojano attack-- cant remove
« Reply #15 on: December 01, 2005, 08:29:31 AM »
Hi Storzek,

This is what I found: http://forum.clubedohardware.com.br/index.php?showtopic=291574. Wait for Tech's translation and explanation.

greets,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Spiritsongs

  • Guest
Re: trojano attack-- cant remove
« Reply #16 on: December 01, 2005, 09:19:35 AM »
 :) Give the good and FREE anti-trojan "Ewido", available at
    www.ewido.net/en a try .

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojano attack-- cant remove
« Reply #17 on: December 01, 2005, 12:18:43 PM »
This is what I found: http://forum.clubedohardware.com.br/index.php?showtopic=291574. Wait for Tech's translation and explanation.
Polonus, there isn't any other great deal there then running HijackThis (http://216.180.233.162/~merijn/files/HijackThis.exe), run and clean.
Besides, the user recommends scanning after booting in Safe Mode (pressing F8 while booting) and the use of CCleaner (http://www.filehippo.com/download_ccleaner.html) and on-line scanning with BitDefender (http://www.bitdefender.com/scan8/ie.html).
Nothing that different than any other cleaning and removal procedure we can see here.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89159
  • No support PMs thanks
Re: trojano attack-- cant remove
« Reply #18 on: December 01, 2005, 02:55:06 PM »
Also useful as a diagnostic tool - Download HiJackThis.zip - HJT Information HiJackThis Tutorial 1 or HiJackThis Tutorial 2
For an on-line analysis - HiJackThis Log file - On-line Analysis
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
OR HiJackThis Log file - On-line Analysis 2
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #19 on: December 01, 2005, 03:23:09 PM »
After 5 scans width avast , avast delete svchosts.dll and now is ok. I just nead to found were can I plagout popup windows.....

I found in Internet options -> Programs -> "manage adds" (or samthingh like thet (I have slovenian language instaled on W XP). There was edd HomePageBHO dat. mshtml.dll wich replace home page to sequriti center. I desable it and this is now OK.

Best regards from Slovenia

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89159
  • No support PMs thanks
Re: trojano attack-- cant remove
« Reply #20 on: December 01, 2005, 03:26:42 PM »
Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #21 on: December 01, 2005, 03:28:29 PM »
Oh SHIT !!!

Baluns width System Alart : Adwere and Spaywere was here again I think I beet them, SHITT...

Best regards from Slovenia

Have enybody Idea for this?

Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #22 on: December 01, 2005, 03:31:31 PM »
Hi Storzek,

This is what I found: http://forum.clubedohardware.com.br/index.php?showtopic=291574. Wait for Tech's translation and explanation.

greets,

polonus

I do not speak espaniol language!!!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89159
  • No support PMs thanks
Re: trojano attack-- cant remove
« Reply #23 on: December 01, 2005, 03:39:12 PM »
Try using HiJackThis as I mentioned in a previous post (you can post the contents here, see the tutorial links also) something has to be running in order for it to keep coming back or you are visiting the same sites and getting reinfected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #24 on: December 01, 2005, 04:11:38 PM »
Ok I'll try HiJackThis I we will see.

I thont check sides, becouse I was only on avast sites,...so this is all time on my competuter,,, oh...THENKS!!!

Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #25 on: December 01, 2005, 04:54:55 PM »
I think this is problem:
O2 - BHO: HomepageBHO - {3e9b951e-6f72-431b-82cf-4a9fbf2f53bc} - C:\WINDOWS\system32\hpFBF8.tmp

Bat I delete this in safe mode width HiJackThis and after reboot it is here again...

I do not know what to do...

Best regards from Boštjan - Slovenia

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojano attack-- cant remove
« Reply #26 on: December 01, 2005, 05:04:53 PM »
I do not speak espaniol language!!!
It's not spanish but Brazilian Portuguese.
Anyway, I've tried to translate the most important parts... Did you read what I've posted or it was useless...?
The best things in life are free.

Spiritsongs

  • Guest
Re: trojano attack-- cant remove
« Reply #27 on: December 01, 2005, 05:12:06 PM »
 :)  Sounds like you have SPYWARE on your computer, not a
      virus; best to ask the Experts on the forums of your
      antiSPYWARE provider or www.geekstogo.com .

Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #28 on: December 01, 2005, 05:40:26 PM »
Hello!

Jes it is adwere no virus..

I know thet is not eanglish or doutch so I do not speak this languageand I think thet is espanian, Sorry ...

Yes I try HijackThis, ccleaner, a'll now try scan8. To this time are nothing....

Ad-Aware ES do not recognise this .... UH....

Best regards from Slovenia

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: trojano attack-- cant remove
« Reply #29 on: December 01, 2005, 06:25:38 PM »
HomepageBHO

A variant of SmitFraud or PSGuard:

http://castlecops.com/tk23849-HomepageBHO.html

There is a removal tool for SmitFraud:

http://noahdfear.geekstogo.com/

PSGuard uses a rootkit to protect the registry key:

http://www3.ca.com/securityadvisor/pest/pest.aspx?id=453094829

If this is what you have, that could be why you can't delete it.

Again, Noahdfear's tool should remove it.

Good luck!

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog