Jump to content
  • Announcements

    • Rodion Nagornov

      Долгое сохранение сообщений || Delays while posting (click here to read the full text RU/EN)   09/20/2017

      Due to some technical reasons visual delays are possible while message sending. Actually your message is published immediately - just interface works long. In such case, please, do not re-send your message immediately! Press F5 to reload the page and check if your message/topic is published. || По техническим причинам возможно визуально долгое отправление сообщений на форуме. Фактически ваше сообщение публикуется мгновенно - долго отрабатывает графика. В случае подобной ситуации, пожалуйста, сначала обновите страницу (F5) и проверьте, появилось ли ваше сообщение. Не пытайтесь сразу отправить его заново.
Chattchitto

Please Help! Torjan Generic And Torjan

Recommended Posts

These Are The notifications i got from kaspersky anti-virus: (please downoad them they are in txt format)

 

http://www.mediafire.com/?1mueo2mlgg1 [Reports/System Security/ Tune]

http://www.mediafire.com/?jonmz2nxzyn [Reports/System Security/ Absent]

 

(They Are Uploaded Here too)

 

And the absent keeps growing!!!! its now 3000!!

 

+

 

every few minutes kaspersky give me this notification:

 

Tune: Loading object

hxxp://206.222.9.187/~dsacom/41.exe,

containing torjan program Torjan.Win32.Agent.ajqf. Detected.

 

please help guys

 

Edit: malware link spoiler.

Edited by richbuff

Share this post


Link to post

Wrong file. That is a gsi.txt. The zipped AVZ sysinfo.zip is needed, run the AVZ utility, instructions linked above.

Share this post


Link to post

Upload your gsi sysinfo.txt to the parser site http://gsi.kaspersky.fr/ and post link to GSI Report. Also, Post a Combofix log, please review and follow these instructions Very carefully.

 

Download it here -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

Before saving it, please rename it to something like 123.exe to stop malware from disabling it.

 

Now, please make sure no other programs are running, close all other windows and pause Kaspersky (Choose the option "resume manually" if still active) until after the scanning and removal process has taken place.

 

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.

Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.

 

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.

 

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt , please attach it to your next post. Also, please don't forget to resume the Kaspersky that you paused.

Share this post


Link to post
Upload your gsi sysinfo.txt to the parser site http://gsi.kaspersky.fr/ and post link to GSI Report. Also, Post a Combofix log, please review and follow these instructions Very carefully.

 

Download it here -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

Before saving it, please rename it to something like 123.exe to stop malware from disabling it.

 

Now, please make sure no other programs are running, close all other windows and pause Kaspersky (Choose the option "resume manually" if still active) until after the scanning and removal process has taken place.

 

Please double click on the file you downloaded. Follow the onscreen prompts to start the scan.

Once the scanning process has started please DO NOT click on the Combofix window or attempt to use your computer as this can cause the scanning process to stall. It may take a while to complete scanning and this is normal.

 

You will be disconnected from the internet and your desktop icons/toolbars will disappear during scanning, do not worry, this is normal and it will be restored after scanning has completed.

 

Combofix will create a logfile and display it after your computer has rebooted. Usually located in c:\combofix.txt , please attach it to your next post. Also, please don't forget to resume the Kaspersky that you paused.

 

All Done Here's The ComboFix File:

 

 

Share this post


Link to post

Run this script, instructions are in thread linked above, PC will reboot:

begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('C:\Documents and Settings\EDDE\run32dll.exe','');
QuarantineFile('C:\Documents and Settings\EDDE\nOT-a-bOT.exe','');
DeleteFile('C:\Documents and Settings\EDDE\run32dll.exe');
DeleteFile('C:\Documents and Settings\EDDE\nOT-a-bOT.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

 

Do you have any information about the following files: C:\SYSTEM, system.exe and C:\RESTORE, dark.exe?

Share this post


Link to post
Run this script, instructions are in thread linked above, PC will reboot:

begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('C:\Documents and Settings\EDDE\run32dll.exe','');
QuarantineFile('C:\Documents and Settings\EDDE\nOT-a-bOT.exe','');
DeleteFile('C:\Documents and Settings\EDDE\run32dll.exe');
DeleteFile('C:\Documents and Settings\EDDE\nOT-a-bOT.exe');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.

 

Do you have any information about the following files: C:\SYSTEM, system.exe and C:\RESTORE, dark.exe?

 

No.. not at all.

I'm inserting your script now, thanks for your quick help man!!

just 2 questions... should i delete the " Qoobox " Folder in C:\ ? [i think it was created by combofix]

and should i worry about dark.exe and system.exe? lol

Share this post


Link to post

First, run the script, then post back about any changes noted with your original infection signs and symptoms. Then, please zip up C:\qoobox\quarantine and upload to a filehost such as http://rapidshare.de/ Then, PM me the link to the uploaded file. Click my user name and select Send message. After that, uninstall Combofix by: Start > run > type combofix /u > ok.

Share this post


Link to post
First, run the script, then post back about any changes noted with your original infection signs and symptoms. Then, please zip up C:\qoobox\quarantine and upload to a filehost such as http://rapidshare.de/ Then, PM me the link to the uploaded file. Click my user name and select Send message. After that, uninstall Combofix by: Start > run > type combofix /u > ok.

 

Ok. I'm Uploading The File Now

Well Everything Is Back To Normal Now :rolleyes:

thanks again for your quick help man!!!

Share this post


Link to post

If you are typing it in correctly, with a space between the x and the /, and receive that message, then that will suffice. Thank you for the qoobox link, and you're welcome. By the way, your GSI report shows incompatible Messenger Plus! Live, so uninstall it if you notice any surfing or other issues.

Share this post


Link to post
Guest
This topic is now closed to further replies.

×