I'm sure there's something hiding on my PC. Can't quite put my finger on it, but something doesn't feel right.

- Internet explorer (or rather the first-use wizard, as I use Firefox) often randomly appears
- Some new names appearing on the process list


Attach.txt is in the attached .zip file.

Thank you in advance for the help.


I have bad news I'm afraid. :sad:

One or more of the identified infections is a Backdoor Trojan.

OK since we are dealing with the aforementioned infection(s) I would be providing your good self with a disservice if I did not make you aware of the ramifications below:

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Although an attempt could be made to clean this machine, it could never be considered to be truly clean, secure, or trustworthy. We could not say definitively that unknown and unseen malware will have been removed, nor will your system be restored to its pre-infection state. We cannot remedy unknown changes the malware may likely have made in order to allow itself access, nor can we repair the damage it may possibly have caused to vital system files. Additionally, it is quite possible that changes made to the system by the malware may impact negatively on your computer during the removal process. In short, your system may never regain its former stability or its full functionality without a reformat. Therefore, your best and safest course of action is a reformat and reinstallation of the Windows operating system, and that is the course we strongly recommend.

Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? (http://www.dslreports.com/faq/10451)

When Should I Format, How Should I Reinstall (http://www.dslreports.com/faq/10063)

I can attempt to clean this machine but I can't guarantee that it will be at all secure afterwords.

Should you have any questions, please feel free to ask.

Please let myself know what you have decided to do in your next post.

Many thanks for the warning.

I'll get on with a complete re-format immediately.

Luckily, as I had a funny feeling, I haven't used this PC for my bank account in a while.

Card transactions I have done on here, however. I'll have a think about that one.

Now, where did I put that Dell CD..............?

Out of interest, what was it, specifically, in my original post which highlighted the Backdoor Trojan infection to you??

Best regards,

Hi. :)

Many thanks for the warning.You're welcome!

Out of interest, what was it, specifically, in my original post which highlighted the Backdoor Trojan infection to you??There are several serious infections on-board:-



To name but a few and undoubtedly more that have not been identified. As to how your machine became infected the P2P application you have installed is the most likely culprit.

It's really important, if you value your PC at all, to stay away from P2P file sharing programs, like utorrent, Bittorrent, Azureus, Limewire, Vuze.
Criminals have "planted" thousands upon thousands of infections in the "free" shared files. Some of the recent infections can turn your machine into a doorstop.
It's also very important to avoid any "cracks" or "Keygens" that allow unauthorized use of programs. Besides being illegal, these files also are loaded with "planted" malware.

Would you like some further advice with regard to a reformat and reinstallation of the Windows operating system and some online safety advice?

Being a relative amateur, I didn't understand much of the stuff in those links, but the overall picture was clear - not a very nice infection.

I've now re-formatted the computer. Incidentally, the only recovery CD we have at home is the one for my other-half's Dell laptop... Which is a German version. So I now have German windows! My German's not too bad though, so no loss.

Only other hiccup is my Wireless adaptor not working - very strange indeed. Currently have a cable trailing through the house until that one's solved!

I have done the following things to protect my PC:
- Installed Free AVG
- Installed Spybot and have immunised everything
- Installed the latest windows updates
- Windows firewall turned on

Is there anything else that you would recommend? On that same note, the information you've offered there would be very welcome.

With regard to how I got infected, I rarely use those P2P programmes. It's likely to be, therefore, cracks for various stuff and/or looking for forums for rapidshare links. I shall use much more retraint in future.

Many thanks again for the swift diagnosis and I'll be donating a few bob to the Spoybot-pot.

Best regards,

Hi. :)

Many thanks again for the swift diagnosis and I'll be donating a few bob to the Spoybot-pot.
You're welcome and I am sure it would be appreciated.

I didn't understand much of the stuff in those links, but the overall picture was clear - not a very nice infection. Aye indeed.

I've now re-formatted the computer. Incidentally, the only recovery CD we have at home is the one for my other-half's Dell laptop... Which is a German version. So I now have German windows! My German's not too bad though, so no loss.
Technically that is not legal far as I am aware, however you must have activated windows or you would not have been able to download/install any updates etc.

To be on the safe side I would validate windows (http://www.microsoft.com/genuine/downloads/SuccessfulActivation.aspx?displaylang=en&Error=0&sGuid=22bf60dd-d89a-4c13-a527-e5f6d8c576f7) and you may need to contact Microsoft and actually purchase a product licence.

Is there anything else that you would recommend? On that same note, the information you've offered there would be very welcome.
What you have is fine and the below will compliment your current security:-

Malwarebytes' Anti-Malware - Download it from here (http://www.malwarebytes.org/mbam-download.php)

The tutorial on how to use MBAM is located here (http://thespykiller.co.uk/index.php?PHPSESSID=12a63a8f9a27c9b153f67c04a5c10955&topic=5946.0)

Install WinPatrol - Download it from here (http://www.winpatrol.com/download.html)

You can find information about how WinPatrol works here (http://www.winpatrol.com/features.html)

Keep your system updated- Microsoft releases patches for Windows and other products regularly:
I advise you visit: http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=en-us
Install the Active X
Once installed it will advise set Auto-Updates if not set and you then you will be able to manually check for updates also via:
Start >> All Programs >> Microsoft Updates
Be careful when opening attachments and downloading files:

Never open email attachments, not even if they are from someone you know. If you need to open them, scan them with your antivirus program before opening.
Never open emails from unknown senders.
Beware of emails that warn about viruses that are spreading, especially those from antivirus vendors. These email addresses can be easily spoofed. Check the antivirus vendor websites to be sure.
Be careful of what you download. Only download files from known sources. Also, avoid cracked programs. If you need a particular program that costs too much for you, try finding free alternatives on Sourceforge (http://sourceforge.net/) or Pricelessware (http://www.pricelesswarehome.org/).
Stop malicious scripts:

Windows by default allow scripts (which is VBScript and JavaScript) to run and some of these scripts are malicious. Use Noscript (http://www.symantec.com/avcenter/noscript.exe) by Symantec or Script Defender (http://www.analogx.com/contents/download/system/sdefend.htm) by AnalogX to handle these scripts.


This is a excellent resource I recommend reading:- How to prevent Malware (http://users.telenet.be/bluepatchy/miekiemoes/prevention.html)

Importance of Regular System Maintenance:

I advice you read both of the below listed topics as this will go a long way to keeping your Computer performing well after the format and the reinstallation of the Windows operating system.

Help! My computer is slow! (http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html)

Also so is this:

What to do if your Computer is running slowly (http://www.malwareremoval.com/tutorials/runningslowly.php)

With regard to how I got infected, I rarely use those P2P programmes. It's likely to be, therefore, cracks for various stuff and/or looking for forums for rapidshare links. I shall use much more retraint in future.Well I still stand by my former advice concerning such. Any questions feel free to ask, if not stay safe!

Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than three days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.