PDA

View Full Version : backdoor trojan? something that doesnt want to be found or removed



mrgcap
2009-03-30, 14:40
Computer seems to be infected. I was troubleshooting an infected pc and used a flash drive to transfer logs to the clean pc to upload to this forum. IE will run normally for about 5 minutes but then will stop responding. MA anti-malware also stops responding after an all clear message. Also access to most spyware removal sites is denied. When I first ran an anti-malware scan I had 18 items which I removed, these returned and were removed again. Now showing clear but I'm not conviced it is a true negative. I have had to retype all the above as the pc is not responding. I will post an HJT log once I have restarted the infected pc. My previous thread will give more detail of other items that were removed, one was a proxy override, and 01-Hosts:74.208.77.54 hcurltest1 and 01-Hosts: 82.165.61.232 hcurltest2...both pointing to Schlund + partner AG in Germany . I tried to start in safe mode with networking to run ESET, but got an error message which seemed common on forums. I tried Trend Micro house call but it stopped responding half way through and combofix, but after the blue timing bar ran nothing happened. It seems that there is something in here that is determined to block all removal attempts....help!!

Matt
2009-03-30, 14:43
Hi mrgcap,

I would like you to open your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22). Therefore, please read the thread "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) from tashi and prepare an HijackThis log file.

mrgcap
2009-03-30, 16:08
Sorry Matt thought I was in malware removal forum....my bad

Matt
2009-03-30, 16:55
Hi mrgcap,


Sorry Matt thought I was in malware removal forum....my bad

That's not an issue.

Thread in Malware Removal Forum (http://forums.spybot.info/showthread.php?t=47227)