BleepingComputer.com: Trojan probems

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Trojan probems No sound or internet

#1 User is offline   GeraldUK 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 88
  • Joined: 18-May 09

Posted 21 August 2011 - 06:37 AM

Hello
Not sure if it this is the best forum, but it is problems from a trojan which has been
quarantined.

I do not have internet access so this is being sent from a friend's computer.

Am running a Desktop, Windows XP SP3 with 2gig RAM.

Anvira AntiVir said:
The file 'C:\WINDOWS\system32\ble.dll'
contained a virus or unwanted program 'TR/Agent.osnw.1' [trojan]
Action(s) taken:
The registration entry
<HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\
NameSpace_Catalog5\Catalog_Entries\000000000004\LibraryPath> was successfully
repaired.
An error has occurred and the file was not deleted. ErrorID: 26003.
The file could not be deleted!
Attempting to perform action using the ARK library.
The file was moved to the quarantine directory under the name '549309d1.qua"

I ran Malwarebytes and that took over an hour, Event Viewer reporting it had timed out about
30 times. It showed a clean result. I then rebooted (which took much longer than usual) and
find I have now lost my Internet Connection and all sound.

Ran Spybot search & Destroy and that came up with a clean result. Ran scannow without any
problems.

Looking at the Internet connection Network Diagnostics says that there was an error in the
Winsock provider catalog and the TCP/IP protocol had not been set properly plus an error in
detecting offline status of IE with error in InternetOpen call 12159. It offers to fix the
problem, but nothing changes.

From a previous visitation I have rkill.scr; FixExe.reg; and unhide.exe still on my desktop. I
also have an old copy of Hijack This and attach a log of my system now. ( I normally would
not do this, but am using a neighbour's computer).

Logfile of Trend Micro HijackThis v2.0.2

Log removed. ~ OB

Sorry about the amount of information. Have already spent an hour on the phone to my ISP
in India. Would be very grateful for any assistance from the more knowledgeable.

This post has been edited by Orange Blossom: 21 August 2011 - 02:11 PM


#2 User is offline   GeraldUK 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 88
  • Joined: 18-May 09

Posted 21 August 2011 - 11:14 AM

Sorry about adding the Hijack log with the post.

One of my neighbours is pretty IT savy and he came up with running a file called "winsockfix.exe" which did the trick, altering the Registry entries back to pre-trojan so I now have internet connectivity plus sound.

Therefore a happy bunny, and this thread could be closed.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users