Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

View previous topic View next topic Go down

Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by seafaerie on 28th April 2010, 5:09 am

Hi, soooo this has been going on for a while since 19/06/09 to be exact, at first I didn't know what it was so I gave up on my desktop and started to use my laptop BUT now that has crashed too... but that another story.

AVG found the infection and it is now in my virus vault but my computer is running dead slow, the virus found is a Win32/Cryptor which has now spawned into multiple areas in my system, followed by Trojan Horse Agent2.GZM and then Trojan horse Generic13.APIH, AND NOW Win32/Induc.A which was on the 19/8/09. :sad:

I do realise I have left this for ridiculously long but I now have the patience and time to try and fix it....... I think. Goofy

If anyone can help me I would be forever grateful as after this hurdle I am going to have to fix my laptop which I think could be contaminated with something similar but is alot more serious.

As for my desktop PC I am able to download and access what I like it just runs really really excruciatingly SLOW. Whoa!

The operating system is Windows XP Professional.
I don't want to have to wipe my C: Drive clean and start over again but if that is the last resort then so be it.

Also, if you are checking it out, Im pretty sure that my rundll32.exe application has been changed and I have looked into what I can do but am terribly lost. Suspect

Goodluck!

Here is my HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:04:55 PM, on 4/28/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\lauren\Start Menu\Programs\Startup\TXMouse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: TXMouse.exe
O4 - Global Startup: AutorunsDisabled
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [You must be registered and logged in to see this link.]
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {6F74F92E-8DD8-4DDE-8FB8-CBB882A68048} (Microsoft Office XP Professional Step by Step Interactive) - [You must be registered and logged in to see this link.] Files\Microsoft Interactive Training\O10C\mitm0026.cab
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} (Java Plug-in 1.6.0_13) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{66BF92F0-4FF9-4CA9-BB1A-94BC466C9219}: NameServer = 192.168.0.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe

--
End of file - 6568 bytes




Cheers! Smile Hope you can help me. Thank You!

seafaerie
Novice
Novice

Posts Posts : 6
Joined Joined : 2010-04-28
OS OS : Windows XP Professional 2003
Points Points : 24258
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by Kenny94 on 28th April 2010, 1:15 pm

Hi seafaerie And Welcome to GP!

Please download [You must be registered and logged in to see this link.] by Atribune.


  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.


Click Exit on the Main menu to close the program.


Next



Please download Malwarebytes Anti-Malware from [You must be registered and logged in to see this link.].

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediatly.

Kenny94
Tech Officer
Tech Officer

Posts Posts : 2019
Joined Joined : 2010-04-22
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avira/Router and Malwarebytes
Points Points : 33551
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by seafaerie on 30th April 2010, 4:31 am

Hi Kenny,

Thanks so much for coming to the rescue! Big Grin

The AFT Cleaner and Anti-Malware worked fine.

Here is my report:

Malwarebytes' Anti-Malware 1.46
[You must be registered and logged in to see this link.]

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

4/30/2010 1:57:54 PM
mbam-log-2010-04-30 (13-57-54).txt

Scan type: Quick scan
Objects scanned: 159375
Time elapsed: 56 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\WinPC AntiVirus (Rogue.WinPCAntiVirus) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\lauren\Application Data\asd.bat (Rogue.WinPCDefender) -> Quarantined and deleted successfully.


Are there any programs I could run for future preventions other than AVG, that you swear by?

Smile Thank You!

seafaerie
Novice
Novice

Posts Posts : 6
Joined Joined : 2010-04-28
OS OS : Windows XP Professional 2003
Points Points : 24258
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by Kenny94 on 30th April 2010, 8:17 pm

Were not done yet.... Smile

Open Hijackthis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - (no file)
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)

Again, make sure ALL browser windows are closed when you click FIX.

Next

ESET Online Scanner

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however may need to disable your current installed Anti-Virus, how to do so can be read [You must be registered and logged in to see this link.].


  • Please go [You must be registered and logged in to see this link.] then click on:
  • Select the option YES, I accept the Terms of Use then click on:
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:


    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology

  • Now click on:
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on:
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!


Next



Download Security Check from [You must be registered and logged in to see this link.] or [You must be registered and logged in to see this link.].

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



In your next reply, please include these log(s):

EsetOnlineScanner\log.txt
checkup.txt


Also, please let me know how things are running now and if you encountered any problems while you were following the instructions I posted.

Kenny94
Tech Officer
Tech Officer

Posts Posts : 2019
Joined Joined : 2010-04-22
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avira/Router and Malwarebytes
Points Points : 33551
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by seafaerie on 5th May 2010, 1:17 am

Hi Kenny,

Quick q's.

When I did the HJT scan I fixed the three 02-BHO:(no name)........ as listed in your previous reply.
I noticed that there is another one that is called

02-BHO:(no name)- AutorunsDisabled- (no file)

Should this be FIXED aswell?


I haven't ran the other scans yet, the ESET Online Scanner link doesn't seem to be working, but I can just Google it.


Cheers Smile

seafaerie
Novice
Novice

Posts Posts : 6
Joined Joined : 2010-04-28
OS OS : Windows XP Professional 2003
Points Points : 24258
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by Kenny94 on 5th May 2010, 1:25 am

No do not fix this one "AutorunsDisabled" please.

Eset Link is working on my end:

[You must be registered and logged in to see this link.]

Kenny94
Tech Officer
Tech Officer

Posts Posts : 2019
Joined Joined : 2010-04-22
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avira/Router and Malwarebytes
Points Points : 33551
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by seafaerie on 5th May 2010, 2:02 am

Awesome.... well the scan won't run, my internet usage is done for the month.. grrr.

Soo, I'll just have to wait.
But in the meantime my step brother was over the other day and I uninstalled AVG and he installed:

~avast! Free antivirus
~Spybot Search and Destroy

Are they ok to use?

seafaerie
Novice
Novice

Posts Posts : 6
Joined Joined : 2010-04-28
OS OS : Windows XP Professional 2003
Points Points : 24258
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by Kenny94 on 5th May 2010, 2:16 am

Both are good. AVG has gone south in the past year or so. IMO...

Lets try another scanner:

Please run the [You must be registered and logged in to see this link.]

Note: You must use Internet Explorer for this scan!

  • Accept the License Agreement.
  • Once the ActiveX installs click Full System Scan
  • Once the download completes, the scan will begin automatically.
  • The scan will take some time to finish, so please be patient.
  • When the scan completes, click the Automatic cleaning (recommended) button.
  • Click the Show Report button and copy and paste the entire report in your next reply.

Kenny94
Tech Officer
Tech Officer

Posts Posts : 2019
Joined Joined : 2010-04-22
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avira/Router and Malwarebytes
Points Points : 33551
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by Kenny94 on 8th May 2010, 1:31 pm

You still there?

Kenny94
Tech Officer
Tech Officer

Posts Posts : 2019
Joined Joined : 2010-04-22
Gender Gender : Male
OS OS : Windows 7
Protection Protection : Avira/Router and Malwarebytes
Points Points : 33551
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by seafaerie on 24th May 2010, 2:58 am

Hi kenny

Sorry I have been lacking Internet for a bit... Just trying to run the ESET Online Scanner. Smile

seafaerie
Novice
Novice

Posts Posts : 6
Joined Joined : 2010-04-28
OS OS : Windows XP Professional 2003
Points Points : 24258
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor,Trojan horse Agent2.GZM,Trojan horse Generic13.APIH,Win 32/Induc.A

Post by seafaerie on 24th May 2010, 3:50 am

ok here they are

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=e4ba6d1da260be4db52f681764d77975
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-05-24 03:38:36
# local_time=2010-05-24 01:38:36 (+1000, AUS Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 1491664 1491664 0 0
# compatibility_mode=768 16777191 100 0 1231729 1231729 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# compatibility_mode=9217 16777214 0 9 28612752 42987549 0 0
# scanned=24985
# found=0
# cleaned=0
# scan_time=1711

Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
avast! Free Antivirus
ESET Online Scanner v3
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
HijackThis 2.0.2
Java(TM) 6 Update 15
Out of date Java installed!
Adobe Flash Player
Adobe Reader 7.0.9
Out of date Adobe Reader installed!
````````````````````````````````
Process Check:
objlist.exe by Laurent

Alwil Software Avast5 AvastSvc.exe
ALWILS~1 Avast5 avastUI.exe
````````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

seafaerie
Novice
Novice

Posts Posts : 6
Joined Joined : 2010-04-28
OS OS : Windows XP Professional 2003
Points Points : 24258
# Likes # Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum