Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: SpywareDoctor can't remove Trogan  (Read 13806 times)

0 Members and 1 Guest are viewing this topic.

evanesco

    Topic Starter


    Beginner

    SpywareDoctor can't remove Trogan
    « on: June 10, 2008, 05:15:52 AM »
    I have Spware Doctor on my PC, and it's picked up a Trogan, but it can't fix it, what should I do?

    Carbon Dudeoxide

    • Global Moderator

    • Mastermind
    • Thanked: 169
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Experience: Guru
    • OS: Mac OS
    Re: SpywareDoctor can't remove Trogan
    « Reply #1 on: June 10, 2008, 05:19:05 AM »
    Our Malware Specialists are currently offline but if you could look HERE to get a head start.

    evanesco

      Topic Starter


      Beginner

      Re: SpywareDoctor can't remove Trogan
      « Reply #2 on: June 10, 2008, 07:21:41 AM »
      Thanks for that. I've started foloowing the instructions. I've attatched the first log from SAS.

      [Saving space - attachment deleted by admin]

      Broni


        Mastermind
      • Kraków my love :)
      • Thanked: 614
        • Computer Help Forum
      • Computer: Specs
      • Experience: Experienced
      • OS: Windows 8
      Re: SpywareDoctor can't remove Trogan
      « Reply #3 on: June 10, 2008, 09:46:15 PM »
      Next logs, please.

      evanesco

        Topic Starter


        Beginner

        Re: SpywareDoctor can't remove Trogan
        « Reply #4 on: June 11, 2008, 01:54:10 AM »
        Next logs, please.

        Sorry, I had to go out, I'm on it now  :)

        evanesco

          Topic Starter


          Beginner

          Re: SpywareDoctor can't remove Trogan
          « Reply #5 on: June 11, 2008, 02:36:45 AM »
          MBAM log attached.

          [Saving space - attachment deleted by admin]

          evanesco

            Topic Starter


            Beginner

            Re: SpywareDoctor can't remove Trogan
            « Reply #6 on: June 11, 2008, 02:42:44 AM »
            HJT log attatched.

            [Saving space - attachment deleted by admin]

            evanesco

              Topic Starter


              Beginner

              Re: SpywareDoctor can't remove Trogan
              « Reply #7 on: June 11, 2008, 02:45:26 AM »
              I think I've done everything required. My pc is actually running a lot better, just from the scans I've done, but obviusly I need some help with the complete removal of the trogan. I also wanted to ask which programmes are essential for start up, so I can disable the rest of them from running on start up.

              Carbon Dudeoxide

              • Global Moderator

              • Mastermind
              • Thanked: 169
                • Yes
                • Yes
                • Yes
              • Certifications: List
              • Experience: Guru
              • OS: Mac OS
              Re: SpywareDoctor can't remove Trogan
              « Reply #8 on: June 11, 2008, 04:02:56 AM »
              If you're talking about the startup in MSCONFIG, the computer will work without any of them checked but I don't think it would stop the Trojan. I would wait until one of our malware specialists to have a look at the logs you've posted.

              Don't worry, they will be online soon to give you a tune-up.  ;)

              evanesco

                Topic Starter


                Beginner

                Re: SpywareDoctor can't remove Trogan
                « Reply #9 on: June 11, 2008, 04:30:54 AM »
                I'm not sure what MSCONFIG is, so I'll explain a bit more. When I turn on my pc, several programmes start, like nokia connectivity (which is for my phone, so I know I'm good to disable that on start up), things that run in the background that don't really need to and could be run when needed. How do I check what's running so I can disable what I don't need running?

                Carbon Dudeoxide

                • Global Moderator

                • Mastermind
                • Thanked: 169
                  • Yes
                  • Yes
                  • Yes
                • Certifications: List
                • Experience: Guru
                • OS: Mac OS
                Re: SpywareDoctor can't remove Trogan
                « Reply #10 on: June 11, 2008, 04:34:07 AM »

                CBMatt

                • Mod & Malware Specialist


                • Prodigy

                • Sad and lonely...and loving every minute of it.
                • Thanked: 167
                  • Yes
                • Experience: Experienced
                • OS: Windows 7
                Re: SpywareDoctor can't remove Trogan
                « Reply #11 on: June 11, 2008, 04:36:14 AM »
                I'm only going to be on for a little bit longer, but I'll go ahead and get the ball rolling.  It looks like SAS and MBAM cleared out quite a few infections for you, but you're not entirely in the clear just yet.  For now, we're only going to concern ourselves with the infections.  We can worry about your start-up entries later.


                Once we start, you won't have access to this post anymore, so I recommend that you print out this post or save it to a Notepad file.  Open HijackThis and scan again.  Check the following entries, but don't do anything to them yet...

                O2 - BHO: (no name) - rsion - (no file)
                O2 - BHO: (no name) - X$þ - (no file)
                O2 - BHO: (no name) - Ø$þ - (no file)
                O2 - BHO: (no name) - ˆ$þ - (no file)

                O4 - HKLM\..\Run: [BarbieGirlsTray] C:\Program Files\Mattel\Barbie Girls\Mattel.BarbieGirls.Tray.exe

                O20 - Winlogon Notify: iifdbaAs - iifdbaAs.dll (file missing)
                O20 - Winlogon Notify: tuvvuro - tuvvuro.dll (file missing)


                Now, close all windows (including this one) besides HijackThis, then click Fix Checked.  Close HijackThis and reboot into Safe Mode and enable hidden files and folders.

                Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...

                Barbie Girls or Mattel Barbie Girls

                Please note any other programs that you dont recognize in that list in your next response.

                Navigate to and delete the following folder(s) if present...

                C:\Program Files\Mattel\Barbie Girls

                Navigate to and delete the following file(s) if present...

                C:\WINDOWS\system32\iifdbaAs.dll
                C:\WINDOWS\system32\tuvvuro.dll


                Once you've done all of this, reboot into Normal Mode and post a new HijackThis log along with new SAS and MBAM logs so we can see if there's any other junk we need to clean up.  And just for the heck of it, also run a scan with SpywareDoctor and tell us the results.  Let me know how everything's running now and if you had any problems following my steps.

                Also very important...
                I don't see any anti-virus (SpywareDoctor is only anti-spyware) or firewall running on your computer.  This needs to be remedied as soon as possible!
                Quote
                An undefined problem has an infinite number of solutions.
                —Robert A. Humphrey

                Carbon Dudeoxide

                • Global Moderator

                • Mastermind
                • Thanked: 169
                  • Yes
                  • Yes
                  • Yes
                • Certifications: List
                • Experience: Guru
                • OS: Mac OS
                Re: SpywareDoctor can't remove Trogan
                « Reply #12 on: June 11, 2008, 04:40:59 AM »
                Also very important...
                I don't see any anti-virus (SpywareDoctor is only anti-spyware) or firewall running on your computer.  This needs to be remedied as soon as possible!
                Here are some good Antivirus software:

                http://www.computerhope.com/issues/ch000514.htm

                Personally, I like AntiVir, AVG and McAfee.

                Note, only have one antivirus software.

                evanesco

                  Topic Starter


                  Beginner

                  Re: SpywareDoctor can't remove Trogan
                  « Reply #13 on: June 11, 2008, 04:48:54 AM »
                  Thanks I'm on it now.

                  evanesco

                    Topic Starter


                    Beginner

                    Re: SpywareDoctor can't remove Trogan
                    « Reply #14 on: June 11, 2008, 05:23:11 AM »
                    O2 - BHO: (no name) - rsion - (no file)
                    O2 - BHO: (no name) - X$þ - (no file)
                    O2 - BHO: (no name) - Ø$þ - (no file)
                    O2 - BHO: (no name) - ˆ$þ - (no file)

                    O4 - HKLM\..\Run: [BarbieGirlsTray] C:\Program Files\Mattel\Barbie Girls\Mattel.BarbieGirls.Tray.exe

                    O20 - Winlogon Notify: iifdbaAs - iifdbaAs.dll (file missing)
                    O20 - Winlogon Notify: tuvvuro - tuvvuro.dll (file missing)


                    Done


                    Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following (if present)...

                    Barbie Girls or Mattel Barbie Girls I couldn't remove this in safe mode, the installsheild wizard wouldn't start up, so I've removed it in normal mode.

                    Please note any other programs that you dont recognize in that list in your next response.

                    Navigate to and delete the following folder(s) if present...

                    C:\Program Files\Mattel\Barbie Girls Done

                    Navigate to and delete the following file(s) if present...

                    C:\WINDOWS\system32\iifdbaAs.dll
                    C:\WINDOWS\system32\tuvvuro.dll
                    Niether were present.

                    Once you've done all of this, reboot into Normal Mode and post a new HijackThis log along with new SAS and MBAM logs so we can see if there's any other junk we need to clean up.  And just for the heck of it, also run a scan with SpywareDoctor and tell us the results.  Let me know how everything's running now and if you had any problems following my steps.

                    Also very important...
                    I don't see any anti-virus (SpywareDoctor is only anti-spyware) or firewall running on your computer.  This needs to be remedied as soon as possible!
                    I'm going to do the scans and logs now. I haven't got anti virus, becasue I thought it was in with Spyware Doctor, obviously not, and I thought my windows firewall was enough. I'll get sorted with this and then get me some anti-virus and a better firewall. Thanks =)

                    Oh, I didn't know how to reboot in safe mode and how to show hidden folders, I figured it out though.