GeekPolice
Would you like to react to this message? Create an account in a few clicks or log in to continue.

GeekPoliceLog in

 


descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Hi, soooo this has been going on for a while since 19/06/09 to be exact, at first I didn't know what it was so I gave up on my desktop and started to use my laptop BUT now that has crashed too... but that another story.

AVG found the infection and it is now in my virus vault but my computer is running dead slow, the virus found is a Win32/Cryptor which has now spawned into multiple areas in my system, followed by Trojan Horse Agent2.GZM and then Trojan horse Generic13.APIH, AND NOW Win32/Induc.A which was on the 19/8/09. :sad:

I do realise I have left this for ridiculously long but I now have the patience and time to try and fix it....... I think. Goofy

If anyone can help me I would be forever grateful as after this hurdle I am going to have to fix my laptop which I think could be contaminated with something similar but is alot more serious.

As for my desktop PC I am able to download and access what I like it just runs really really excruciatingly SLOW. Whoa!

The operating system is Windows XP Professional.
I don't want to have to wipe my C: Drive clean and start over again but if that is the last resort then so be it.

Also, if you are checking it out, Im pretty sure that my rundll32.exe application has been changed and I have looked into what I can do but am terribly lost. Suspect

Goodluck!

Here is my HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:04:55 PM, on 4/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\lauren\Start Menu\Programs\Startup\TXMouse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://redirect.zonelabs.com/redirect/route?oem=1042&prod=8&mode=1000&app=inclient&version=6.1.744.000&lang=en&locale=en-US&date=1174003200&link_id=3&dest=whats_new
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: TXMouse.exe
O4 - Global Startup: AutorunsDisabled
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - https://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - https://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6F74F92E-8DD8-4DDE-8FB8-CBB882A68048} (Microsoft Office XP Professional Step by Step Interactive) - file://C:\Program Files\Microsoft Interactive Training\O10C\mitm0026.cab
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{66BF92F0-4FF9-4CA9-BB1A-94BC466C9219}: NameServer = 192.168.0.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe

--
End of file - 6568 bytes




Cheers! Smile... Hope you can help me. Thank You!

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Hi seafaerie And Welcome to GP!

Please download ATF Cleaner by Atribune.


  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.


Click Exit on the Main menu to close the program.


Next



Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A Bf_new Please download Malwarebytes Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Hi Kenny,

Thanks so much for coming to the rescue! Big Grin

The AFT Cleaner and Anti-Malware worked fine.

Here is my report:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/30/2010 1:57:54 PM
mbam-log-2010-04-30 (13-57-54).txt

Scan type: Quick scan
Objects scanned: 159375
Time elapsed: 56 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\WinPC AntiVirus (Rogue.WinPCAntiVirus) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\lauren\Application Data\asd.bat (Rogue.WinPCDefender) -> Quarantined and deleted successfully.


Are there any programs I could run for future preventions other than AVG, that you swear by?

Smile... Thank You!

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Were not done yet.... Smile...

Open Hijackthis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)

Again, make sure ALL browser windows are closed when you click FIX.

Next

ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however may need to disable your current installed Anti-Virus, how to do so can be read here.


  • Please go here then click on: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EOLS1
  • Select the option YES, I accept the Terms of Use then click on: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EOLS2
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:


    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology

  • Now click on: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EOLS3
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EOLS4
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!


Next



Download Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



In your next reply, please include these log(s):

EsetOnlineScanner\log.txt
checkup.txt


Also, please let me know how things are running now and if you encountered any problems while you were following the instructions I posted.

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Hi Kenny,

Quick q's.

When I did the HJT scan I fixed the three 02-BHO:(no name)........ as listed in your previous reply.
I noticed that there is another one that is called

02-BHO:(no name)- AutorunsDisabled- (no file)

Should this be FIXED aswell?


I haven't ran the other scans yet, the ESET Online Scanner link doesn't seem to be working, but I can just Google it.


Cheers Smile...

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
No do not fix this one "AutorunsDisabled" please.

Eset Link is working on my end:

http://www.eset.com/online-scanner

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Awesome.... well the scan won't run, my internet usage is done for the month.. grrr.

Soo, I'll just have to wait.
But in the meantime my step brother was over the other day and I uninstalled AVG and he installed:

~avast! Free antivirus
~Spybot Search and Destroy

Are they ok to use?

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Both are good. AVG has gone south in the past year or so. IMO...

Lets try another scanner:

Please run the F-Secure Online Scanner

Note: You must use Internet Explorer for this scan!

  • Accept the License Agreement.
  • Once the ActiveX installs click Full System Scan
  • Once the download completes, the scan will begin automatically.
  • The scan will take some time to finish, so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and copy and paste the entire report in your next reply.

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
You still there?

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
Hi kenny

Sorry I have been lacking Internet for a bit... Just trying to run the ESET Online Scanner. Smile...

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
ok here they are

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=e4ba6d1da260be4db52f681764d77975
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-05-24 03:38:36
# local_time=2010-05-24 01:38:36 (+1000, AUS Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 1491664 1491664 0 0
# compatibility_mode=768 16777191 100 0 1231729 1231729 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# compatibility_mode=9217 16777214 0 9 28612752 42987549 0 0
# scanned=24985
# found=0
# cleaned=0
# scan_time=1711

Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Free Antivirus
ESET Online Scanner v3
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
HijackThis 2.0.2
Java(TM) 6 Update 15
Out of date Java installed!
Adobe Flash Player
Adobe Reader 7.0.9
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Alwil Software Avast5 AvastSvc.exe
ALWILS~1 Avast5 avastUI.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

descriptionWin32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A EmptyRe: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum