Announcement

Collapse
No announcement yet.

Trojan

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Trojan

    Ok, I have a problem with a trojan.

    Basically, everynow and again a popup will appear offering me porn videos (It's not an I.E. popup, just a window). When I ctrl + alt + delete, there are two processes I do not recognise: trackurl.exe and delA.tmp (where A can be any alphanumerica character).

    Through experimentation, it appears if I end the trackurl.exe task first, the delA.tmp proceeds to deleting that file from the hard disk and then deletes itself. If I end the delA.tmp process first, I can locate and delete the two files myself. This is to no avail, however, as these files come back after a while (I believe the pop-up may be triggered by certain key-words appearing in I.E. or maybe in the URL (hence the name trackurl).

    I have searched for trackurl.exe in google, but no helpful results were returned. I have run HijackThis, Ad-aware, Spybot S&D and MS Antispyware and they all found some things. The problem seemed to stop for a few days, But this morning has re-appeared. I am currently running a full McAfee Virus Scan of C: drive and I'll let you know of the results (It has so far found 8 files of the "Exploit-ByteVerify" virus which have now been deleted). The pop-up just occured again though.

    Thanks for any help.
    USS Banana after years of superior jav play has amassed 17999 kills, he is 1 kill away from 18k, Type ?go Javs FOR A GAME OF HUNT (no scorereset) -Kim
    ---A few minutes later---
    9:cool koen> you scorereseted
    9:Kim> UM
    9:Kim> i didn't
    9:cool koen> hahahahahahaha
    9:ph <ZH>> LOOOOL
    9:Stargazer <ER>> WHO FUCKING SCORERESET
    9:pascone> lol?

  • #2
    you could try deleting them in Safe Mode? i had a virus that kept coming back once, i turned off system restore and then did a virus scan in safe mode. it fixed the problem.

    Comment


    • #3
      most likely there is a third file in your windows/system folder controlling those two files.
      thread killer

      Also who changed to pw to Squadless, how am I supposed to fly the banner of sucking at the game

      Comment


      • #4
        I know there is probably some third file type, but I don't know what it is or how to find it.

        The Virus scan completed and didn't find any more infections.
        USS Banana after years of superior jav play has amassed 17999 kills, he is 1 kill away from 18k, Type ?go Javs FOR A GAME OF HUNT (no scorereset) -Kim
        ---A few minutes later---
        9:cool koen> you scorereseted
        9:Kim> UM
        9:Kim> i didn't
        9:cool koen> hahahahahahaha
        9:ph <ZH>> LOOOOL
        9:Stargazer <ER>> WHO FUCKING SCORERESET
        9:pascone> lol?

        Comment


        • #5
          www.sysinternals.com

          Download "rootkit revealer". Sounds like you may have a rootkit. Simply put, a very persistant piece of malware. Read about the rootkit revealer before downloading it and read the help file after downloading it. If you don't know much about how your computer works I wouldn't suggest using it and just try different search engines for the file names. Maybe someone will come along on here and actually know what it is/how to remove it.

          You should download "auotruns" as well. See if you find those two files in one of the tabbed lists that program will display, if you see them, delete them. Also, it may actually be registered as an "add-on" for your interenet browser. Download "autoruns" from that same site and click on the Internet Explorer tab. If you see any odd listings remove them. This program anyone can use, just use common sense and don't delete anything that you're not sure of.

          I highly suggest EVERYONE no matter who you are to download "autoruns" from sysinternals.com, it is the most advacned program at finding programs that are set up to run by themselves.

          Edit: I recently had a problem very close to yours and these two programs helped me out.
          Last edited by Kontrolz; 08-19-2005, 05:28 PM.
          (ZaBuZa)>sigh.. i been playing this game since i was 8... i am more mature then ull ever be...

          Comment


          • #6
            I decided to check over my HJT log again.

            Noticed three things which I hadn't noticed til recently.

            Two .exe s in the system32 folder and one in Program Files\HP

            Searched for them in google.

            LiUtilities said: One was a Panda Anti-Virus file (ESSENTIAL DONT TERMINATE THIS PROCESS)

            and

            One was an eTrust Anti-Virus file (ESSENTIAL DONT TERMINATE THIS PROCESS)

            and the last one was an ESSENTIAL FILE to make sure you don't delete a partition by accident on an HP computer.

            Well, I thought hmmmmm, I don't have either of these anti-virus products and my computer is not an HP, so I went to check the creation date of both of these files to see if they were created on the date I reckon the infection occured. Well, they were all apparently created on some random date in 1998 at 0:00 and all were set to hidden. Another file which I had earlier found and deleted which I had found which I was pretty sure was related to this trojan was also created on a random 1998 date at 0:00 and was also hidden.

            So I thought "FUCK YOU LIUTILITIES WARNING" and deleted them, reckoning it was the whole idea of the trojan to imitate essential files so people who aren't as knowledgable about computers would find they are an "essential process" and not delete them. All seems fine for now, I'll let you know if the problem happens again.

            Gonna go delete the contents of prefetch now just to be doubly sure.

            Cheers.
            USS Banana after years of superior jav play has amassed 17999 kills, he is 1 kill away from 18k, Type ?go Javs FOR A GAME OF HUNT (no scorereset) -Kim
            ---A few minutes later---
            9:cool koen> you scorereseted
            9:Kim> UM
            9:Kim> i didn't
            9:cool koen> hahahahahahaha
            9:ph <ZH>> LOOOOL
            9:Stargazer <ER>> WHO FUCKING SCORERESET
            9:pascone> lol?

            Comment


            • #7
              I was gonna suggest reformatting if it really bothered you that much and you couldn't fix the problem, but that doesn't seem to be the case anymore.

              Comment


              • #8
                Originally posted by Asmodeus
                I was gonna suggest reformatting if it really bothered you that much and you couldn't fix the problem, but that doesn't seem to be the case anymore.
                what about a system restore, takes like 5 mins, set it back to when your machine was good?
                Mega Newbie> are you a girl?
                Mithrandia <ER>> yes
                Mega Newbie> lets have some fun?
                Mega Newbie> i already have seen 5 subspace naked girls !!
                Mega Newbie> want to be the next?
                Mithrandia <ER>> hha, ok
                Mega Newbie> u will love it
                Mithrandia <ER>> hmm, well that depends
                Mega Newbie> depends what?how much big it is?
                Mega Newbie> WOW UR MALE
                Mega Newbie> WOW
                Mega Newbie> WOW
                Mega Newbie> JUST SEEN UR PICTURE IN GALLERY WOW
                Mithrandia <ER>> bahahah, tricked!!!
                Mega Newbie> ffs

                Comment


                • #9
                  I like Antivir :x
                  http://www.free-av.com/

                  I've also heard McAfee sucks badly. Don't know if it's fixed, but for months it has had this bug that if it ever runs into a file whose name it can't read, it crashes. I'm not trusting a program like that. :P

                  Comment

                  Working...
                  X