Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 DWH trojan please help!, It keep coming!

views
     
TSVorador
post Jul 26 2007, 09:43 AM, updated 19y ago

Blessed !!!
*******
Senior Member
3,494 posts

Joined: Jan 2003
From: Nosgoth


Oh guys I need help!

I am using Symantec antivirus, version 10.2.0.224 (coporate version i think), scan engine is 71.3.0.25. With latest virus definition update.

Recently when I scan my computer, when it reach the application data > *my user name* > temp,

It detects looooots of trojan name "DWH****" (**** is random number, like 3D25, 5C68). And this file seems duplicate itself into different name when the virus scan touch it, so my virus scan forever stuck in this folder, scan up to 3k of files with the same name, like "DWH1D23, DWH5C71... ...blah blah blah". And it seems endless, I got to manually stop it (scan up to 5 hours!).

When I use the antivirus function to delete all of these file, restart the comp and try scan again, those files are still there, but with slightly different name!

So what I do is I enter the computer safemode, manually go into the same folder (application data > *my username* > temp), delete all of the file (I can't do that in normal mode, when it delete immediately it change name, so it will show "the file is no longer there").

Looksl ike my Symantec antivirus wont give me a damn about it, I download SPybot S&D and update it, scan it but seems no luck as well.

Can someone teach me how to overcome this situation? Thanks ! notworthy.gif notworthy.gif notworthy.gif notworthy.gif notworthy.gif
anthonyz
post Jul 26 2007, 09:47 AM

Getting Started
**
Junior Member
178 posts

Joined: Mar 2007
Just format it...easy and clean...normally that type of trojan hard to clean...
WaCKy-Angel
post Jul 26 2007, 09:48 AM

PeACe~~
*********
All Stars
21,962 posts

Joined: Dec 2004
From: KL



U can use online scanner http://www.kaspersky.com/virusscanner to scan and save a log..
Download OTMoveIt and manually delete the virus shown in the kaspersky log...

or

U can download HijackThis and let pros to clean it....


Added on July 26, 2007, 9:48 am
QUOTE(anthonyz @ Jul 26 2007, 09:47 AM)
Just format it...easy and clean...normally that type of trojan hard to clean...
*
Nope its not hard to clean...


This post has been edited by WaCKy-Angel: Jul 26 2007, 09:48 AM
TSVorador
post Jul 26 2007, 10:16 AM

Blessed !!!
*******
Senior Member
3,494 posts

Joined: Jan 2003
From: Nosgoth


WaCKy-Angel,

THanks for the tips! notworthy.gif notworthy.gif notworthy.gif So using hijackthis is the easier way lor!


Added on July 26, 2007, 10:26 amoops the HIjack this doesn't help, it can't detect the DWH thingy, lemme try another one.

(The thing is, when I scan it via my Symantec it keep duplicate and change the name by itself)

This post has been edited by Vorador: Jul 26 2007, 10:26 AM
WaCKy-Angel
post Jul 26 2007, 12:59 PM

PeACe~~
*********
All Stars
21,962 posts

Joined: Dec 2004
From: KL



QUOTE(Vorador @ Jul 26 2007, 10:16 AM)
WaCKy-Angel,

THanks for the tips! notworthy.gif notworthy.gif notworthy.gif So using hijackthis is the easier way lor!


Added on July 26, 2007, 10:26 amoops the HIjack this doesn't help, it can't detect the DWH thingy, lemme try another one.

(The thing is, when I scan it via my Symantec it keep duplicate and change the name by itself)
*
Hijackthis is not like antivirus scanner...
Its not automated....

Pls post the hijackthis log here for ppl to analyze...
TSVorador
post Jul 26 2007, 04:17 PM

Blessed !!!
*******
Senior Member
3,494 posts

Joined: Jan 2003
From: Nosgoth


Erm when I run it, it keep showing that the windows denied write access to host files, and ask me to delete the hijack this record inside it and save. But when I open up the hosts fils but there's no hijack this record inside, only shows:

127.0.0.1 localhost
::1 localhost

I try to delete it and save as instructed but it will keep showing incorrect path... (when replace the original hosts)

Now I was thinking if there's other way to clean out this bad torjan from my comp... sad.gif

Anyway here is the log file created after bypass the error earlier:

» Click to show Spoiler - click again to hide... «


This post has been edited by Vorador: Jul 26 2007, 04:24 PM

 

Change to:
| Lo-Fi Version
0.0162sec    0.77    5 queries    GZIP Disabled
Time is now: 14th December 2025 - 05:27 AM