Author Topic: I got a trojan  (Read 2809 times)

Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #20 on: June 06, 2008, 06:23:30 PM »
[quote name=\'guestolo\' post=\'430371\' date=\'Jun 6 2008, 04:14 PM\']It could be your display drivers got corrupt
Have you checked your display properties to ensure everything looks ok

Can you do the following also
download [color=\"#0000ff\"]OTScanIt.exe[/color] to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.

[color=\"#800080\"]Note: You must be logged on to the system with an account that has Administrator privileges to run this program.[/color]
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program
  • In the Drivers section click on Non-Microsoft.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
    [color=\"#a0522d\"]Reg - BotCheck
    Reg - Software Policy Settings
    [/color]
  • Copy/Paste the text in the codebox below into the Custom Scans box:
Code: [Select]
HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\Desktop
  • Do not change any other settings.
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
  • Save the file to your desktop or other location where you can find it.


Use the Add Reply button and attach the file in your next post (do not try to copy/paste it into the post).[/quote]


will check drivers.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #21 on: June 06, 2008, 06:55:25 PM »
You didn't copy and paste the following into the Custom scans box before scanning with OTScanit

HKEY_CURRENT_USER\Control Panel\International
HKEY_CURRENT_USER\Control Panel\Desktop


Can you please do so then upload the new scan
« Last Edit: June 06, 2008, 06:56:28 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #22 on: June 06, 2008, 07:02:45 PM »
Sorry Bout that.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #23 on: June 06, 2008, 07:11:04 PM »
Can I get some info
Did you recently update your video drivers?
It is an ATI card correct?

Also
Can you right click an empty spot on desktop and select Properties
Under Settings>>Under Display can you post back Monitor info and and graphic adapter info

What is the screen resolution set at right now?
Also, can you try changing your background, as eg...
Use a Microsoft default
Under the DESKTOP tab>>below Background, can you select something like BLISS
Apply and OK it, how does the screen then look?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #24 on: June 06, 2008, 07:31:45 PM »
I did update monitor drivers about 30 minago.
ATI card?  Dunno if it is.
Monitor info

COMPAQ FS7600 Color Monitor

Graphic Adapter Info


Chip Type:         Intel®82845G Graphics Controller
DAC Type:         Internal
Memory Size:     64 MB
Adapter String:   Intel® 82845G/GL/GE/PE/GV Controller
Bios Info:          Intel Video BIOS


Screen Res is set at 1024 by 768 pixels

Applied Desktop Background "Bliss"  Picture came up fine but still have them "smudges"

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #25 on: June 06, 2008, 07:43:53 PM »
I'm not sure if I understand smudges

Can you take a screenshot of your desktop
Press the PrtScr button or Alt PrtScr

Go to START>>All Programs>>accessories>>Paint
In paint choose Edit>>Paste
Save this to desktop

Upload the pic to something like Photobucket
After you upload to Photobucket
Share the direct link back here

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #26 on: June 06, 2008, 07:50:39 PM »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #27 on: June 07, 2008, 02:20:23 AM »
Can you tell me what part of that screen shot looks smudgy
It all looks really good on my end

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #28 on: June 07, 2008, 11:20:50 AM »
When i started my puter today it was fine.  Must be when the monitor gets warm it starts to do it.  Not a software problem.  Is there any other thing that I need to do?  Oh yeah the clock.  Its still on military time.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #29 on: June 07, 2008, 11:50:24 AM »
Let's do some clearing of the tools we used
Go to START>>RUN>>copy and paste the next command in Blue below

[color=\"#0000FF\"]ComboFix /u[/color]

Then click OK
This will uninstall Combofix and it's components, it should reset your clock also

If it doesn't, do the next step please
Open Notepad (START>>>RUN>>>type in notepad)
Hit OK
Copy the contents of the CODE box, not including the word "code"
Paste it to the empty Notepad file
In Notepad click FILE>>SAVE AS
IMPORTANT>>>Change the Save as Type to All Files.
Name the file as fix.reg

Save this file on the desktop
Ensure to copy from REGEDIT4 and down in the code box

 
Code: [Select]
REGEDIT4

[HKEY_CURRENT_USER\Control Panel\International]
"sTimeFormat"="h:mm:ss tt"


Double click on fix.reg and Allow to add/merge to the registry at the prompt

When we reboot the computer, the time should be back to Normal
Don't reboot yet

Instead
Delete Smitfraudfix.zip and it's folder on desktop
Open Malwarebytes' AntiMalware
In the main window open the Quarantine tab and "Delete All" in this area>>Don't choose Restore
Close MBAM

Afterwards, it's your option to uninstall it from Add and Remove Programs
Or hold onto it and update and run scans occassionally

When that's done
Open OTMoveit2.exe
  • Double-click OTMoveIt2.exe to run it.
  • Click the Cleanup! button
    A list will be downloaded>>Allow it Internet access if prompted by your Firewall
    Don't change anything in this list
  • Select Yes at the prompt
    Wait for the confirmation box to open to reboot the computer
    Don't mouseclick during the wait as you may cause the tool to stall
  • Select Yes to reboot Now
NOTE: This procedure will also delete OTMoveit.exe from desktop

Back in Windows
Here's a direct link to the manual on your Monitor, in case needed, it will show adjustments to your monitor
http://h10032.www1.hp.com/ctg/Manual/c00522046.pdf

Taken from this link
http://h10025.www1.hp.com/ewfrf/wc/documen...product=1841657
Check out the Tips and Recommendations
Also ensure that the Power and Video cable from the monitor to wall and computer and connected securely
You may want to Degauss the monitor if you haven't done this
Only do it once, as stated in the manual

If monitor is overheating: As stated by manual

Quote
There is not enough air space
to allow proper ventilation.

Leave at least 3
inches (76 mm) of
ventilation space
around the monitor,
and do not place
objects on top of the
monitor.

Do the above and let me know how things are running afterwards, let me know if the time of clock is back to Normal too please
Also, what is the refresh rate of the monitor set at?
« Last Edit: June 07, 2008, 12:07:19 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #30 on: June 07, 2008, 09:24:50 PM »
Thanks for the links.  

It is running like normal now.  Thank you very much.

Clock is back to normal again

Screen refresh rate is 75 hertz

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #31 on: June 07, 2008, 09:33:49 PM »
All sounds good, I did realize however
After you removed Trend Security suite, it left you without it's firewall software

Does your version of Norton Security have Firewall protection
We can get you a free Firewall software if it doesn't
Is your Norton's AntiVirus updated to latest definition files?
« Last Edit: June 07, 2008, 09:34:07 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #32 on: June 08, 2008, 10:13:53 AM »
I just turned on my windows firewall.
My nortons has expired so i dont think i can get the updated virus definitions.
Waiting till payday to get new nortons.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #33 on: June 08, 2008, 10:15:57 AM »
Do you want to try a free AntiVirus software?
We'll have to make sure Norton's is uninstalled before we install a new one

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #34 on: June 08, 2008, 08:31:58 PM »
What program are you thinking of?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #35 on: June 08, 2008, 08:50:18 PM »
I was thinking about Avira or Avast for AntiVirus

Would you like to try one?
If so, like I mentioned download the installer first
Don't install yet, instead we'll have to remove Norton's first

Do you want full instructions

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline weasel096

  • Jr. Member
  • **
  • Posts: 99
  • Karma: +0/-0
    • View Profile
I got a trojan
« Reply #36 on: June 08, 2008, 09:39:22 PM »
let me check them out first. I will get back to you soon.
I will be out of town from tuesday till sat night.  Hope to let you know before then.
« Last Edit: June 08, 2008, 10:05:34 PM by weasel096 »

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
I got a trojan
« Reply #37 on: July 06, 2008, 08:12:02 PM »
I'll lock this topic as your problems appear resolved
Take care

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here