:![]()
Thank you.
Can I post them both as attachments? And there’s a file in there called moved.txt but I assume you don’t want that one or you’d have mentioned it?
:![]()
Thank you.
Can I post them both as attachments? And there’s a file in there called moved.txt but I assume you don’t want that one or you’d have mentioned it?
Yes you can, I like attachments. ![]()
Here you go.
I hope… :-\
Please submit these files for analysis
To submit a file to virustoal, please click om this link
copy and paste the following into the upload a file box (one at a time if more than one file is listed)
C:\WINDOWS\Installer{d9bfcedd-23ba-472e-875c-b21807b7641c}\zip.dll
scroll down a bit and click “send file”, wait for the results and post then in your next reply.
Is it me or is this taking a whole shed-load of work? (On your part I mean, obviously). Is it really that bad a TH and will it have damaged my machine?
And do you know why avast! didnt/couldn’t deal with it?
Anyway, here you go:
File zip.dll_ received on 03.18.2008 16:18:32 (CET)
Current status: Loading … queued waiting scanning finished NOT FOUND STOPPED
Result: 21/31 (67.75%)
Loading server information…
Your file is queued in position: 7.
Estimated start time is between 58 and 84 seconds.
Do not close the window until scan is complete.
The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
If you are waiting for more than five minutes you have to resend your file.
Your file is being scanned by VirusTotal in this moment,
results will be shown as they’re generated.
Compact Print results
Your file has expired or does not exists.
Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.
You can wait for web response (automatic reload) or type your email in the form below and click “request” so the system sends you a notification when the scan is finished.
Email:
Antivirus Version Last Update Result
AhnLab-V3 2008.3.18.1 2008.03.18 -
AntiVir 7.6.0.73 2008.03.18 TR/Shell.Eviell
Authentium 4.93.8 2008.03.18 -
Avast 4.7.1098.0 2008.03.18 Win32:Agent-TJH
AVG 7.5.0.516 2008.03.18 Dropper.Generic.VWM
BitDefender 7.2 2008.03.18 Trojan.Dropper.Agent.TPI
CAT-QuickHeal 9.50 2008.03.14 -
ClamAV 0.92.1 2008.03.18 Trojan.Dropper-5137
DrWeb 4.44.0.09170 2008.03.18 Trojan.Inject.770
eSafe 7.0.15.0 2008.03.09 -
eTrust-Vet 31.3.5623 2008.03.17 -
Ewido 4.0 2008.03.18 -
F-Prot 4.4.2.54 2008.03.18 W32/Agent.AT.gen!Eldorado
F-Secure 6.70.13260.0 2008.03.18 Trojan-Dropper.Win32.Agent.fbe
FileAdvisor 1 2008.03.18 -
Fortinet 3.14.0.0 2008.03.17 -
Ikarus T3.1.1.20 2008.03.18 Trojan-Dropper.Win32.Agent.fbe
Kaspersky 7.0.0.125 2008.03.18 Trojan-Dropper.Win32.Agent.fbe
McAfee 5253 2008.03.17 Generic Spy.j
Microsoft 1.3301 2008.03.18 TrojanDropper:Win32/Zirit.B
NOD32v2 2956 2008.03.18 Win32/TrojanDropper.Agent.NIT
Norman 5.80.02 2008.03.18 W32/Agent.EKKY
Panda 9.0.0.4 2008.03.17 Suspicious file
Rising 20.36.12.00 2008.03.18 Trojan.Win32.Runie.a
Sophos 4.27.0 2008.03.18 Mal/Behav-201
Sunbelt 3.0.978.0 2008.03.18 -
Symantec 10 2008.03.18 -
TheHacker 6.2.92.248 2008.03.17 Trojan/Dropper.Agent.fbe
VBA32 3.12.6.3 2008.03.17 Trojan-Dropper.Win32.Agent.fbe
VirusBuster 4.3.26:9 2008.03.18 Trojan.DR.Lodll.Gen
Webwasher-Gateway 6.6.2 2008.03.18 Trojan.Shell.Eviell
Additional information
File size: 22786 bytes
MD5: 8d048aea274336aca0aee5d74990ee70
SHA1: 6679de81f38110b52506484100946405a51920c2
PEiD: -
ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware
I don’t know why avast didn’t detect it before, as it is detected by avast in the virustotal results. Perhaps a new addition to avast’s vps.
What’s happening on your end?
Please follow all previous instructions regarding security programs.
Open a new Notepad session (Do not use a Word Processor or WordPad). Click “Format” and be certain that Word Wrap is not enabled.
Copy and paste all the text in the quote box below into Notepad.
Click File, Save as…, and set the location to your Desktop, and enter (including quotation marks) as the filename: “CFscript.txt” . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.
File:: C:\WINDOWS\Installer\{d9bfcedd-23ba-472e-875c-b21807b7641c}\zip.dllFolder::
C:\WINDOWS\Installer{57938394-a2c0-4aa7-a3be-8559401c32f2}Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
“{BB834DE7-ADD8-49ED-826A-3DE15ED23A44}”=-
[-HKEY_CLASSES_ROOT\clsid{bb834de7-add8-49ed-826a-3de15ed23a44}]
[-HKEY_CLASSES_ROOT\enlfxgw.1]
[-HKEY_CLASSES_ROOT\enlfxgw]
We might as well remove the old java now. It can attract malware.
Go to add/remove programs and uninstall the following
J2SE Runtime Environment 5.0 Update 11
Java™ 6 Update 2
Java™ 6 Update 3
Java™ SE Runtime Environment 6 Update 1 →
Do not uninstall Java™ 6 Update 5
Next in windows explorer, navigate to this folder
C:\Program Files\Java <=this folder. Delete any subfolders except the subfolder jre1.6.0_05. This is the newest version.
Do not delete C:\Program Files\JavaVM <=this folder, if found
http://www.java.com/en/download/help/5000020300.xml
Reboot.
Logs required: combofix and a new HJT
Hi Spike1972
You will have to bring me up to speed on the last thing you did and we will take it from there.
I will need a new HJT log.
oldman, when I tried "Click File, Save as…, and set the location to your Desktop, and enter (including quotation marks) as the filename: “CFscript.txt” it said that the filename is invalid? Did you mean not including quotation marks?
Hi
By using the “” marks, notepad will not add the default .txt extention.
Try this
Set the location to the desktop
In the file name type CFscript
In the file types box, set it to all files
Notepad will now add the .txt extention
Ok, I did what you asked with
“Click File, Save as…, and set the location to your Desktop, and enter (including quotation marks) as the filename: “CFscript.txt” . Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown at the bottom of this post.”
When I did that, it ran HJT and that’s the scan I attach.
I tried to run combofix but it said that copy had expired and I need to download a new one. Where’s the best place to do that from?
First you will have to disable Spybot’s teatimer, or it will iinterfere with the fixes.
Open Spybot and make sure teatimer is disabled, we will re-enable afterwards. To do so do the following
Click mode
click Advanced mode
if you get a warning answer “yes”
click tools
click resident
uncheck resident “teatimer”
click allow change
Reboot
You can get a new copy of combofix from the links found here
http://forum.avast.com/index.php?topic=33730.msg281708#msg281708
Delete the copy you have now, before you download the new copy. Follow the instructions in the above link.
“Delete the copy you have now, before you download the new copy. Follow the instructions in the above link”
This is where I ran into problems. (I tried to post about this yesterday but for some reason it didn’t post).
When I hit ‘run’ ComboFix it said something about not being able to save file as ComboFix(1) even though I didn’t physically ask it to do that.
I admit I initially forgot about un-installing the old version, but when I went into Add/Remove Programs, it wasn’t on the list. I then did a Files And Folders search for ComboFix and tried to post you the results, but I think because it had saved as a .fnd (?) file, it didn’t accept, even when I tried changing the file extention to .txt
Hi. A couple of problems with what you are doing.
Find Combofix.exe on your desktop, if that’s where you origonaly downloaded it to. Right click it and delete.
When downloading the new copy, do not click run. click save and set the lcation to desktop.
“Find Combofix.exe on your desktop, if that’s where you origonaly downloaded it to. Right click it and delete”
That’s no longer on my desktop. I’m not sure when it disappeared, but think it was when I tried to download the new version.
Does that change anything? Should I go into Program Files and see if there’s a ComboFix file, and delete it if there is?
Sorry to be such a muppet :![]()
Hi. no problem.
Try downloading it again and save it to your desktop. Follow the instructions in the post on page one and post the new log. don’t worry about the comboscript for now.
Hi,
I hope this is what you need. I haven’t touched it, renamed it or anything but I did it literally just before this post.
Spike.
Hi Spike 1972
The combofix log looks ok. What problems are you having?
I appreciate that this is going off of avast! territory - if it hadn’t already - but my puter is still very slow.
I think there’s a lot going on in Start Up, but I don’t know what everything is so am loath to alter things. Likewise with my Registry Cleaner. All I (can) really do with that is look out for new things.
Hi. Part of the problem may bo due to the time frame. You started this back in March, but some of the instruction weren’t completed until several weeks later.
This file should have been removed several months ago.
C:\WINDOWS\Installer{d9bfcedd-23ba-472e-875c-b21807b7641c}\zip.dll
It was part of the combofix script you were to do back in March. Did you do it?
I’ve no idea, off the top of my head. How do I tell? Can I do a Find Files And Folders search for that file name? (I’ll just copy and paste it in).