Trojan Downloader Generic.ISG

I have had this in the system volume information for a few days and each time AVG tells me it cant fix it. So I ran a HiJackThis scan and created a log file, it quite long so I have not included it here but attached it, if anyone can help get rid of this problem please tell me :confused:

Comments

  • edited November 2005
    I forgot to say I run AD Aware and SpyBot-S&D at least once a week after checking for updates. They still do not clear the problem on their own though.

    Andy :(
  • TroganTrogan London, UK
    edited November 2005
    Hi,

    I think what AVG is finding is files that are stuck in System Restore or something to that affect. Nothing to worry about....:)
    ===


    Please move HJT from your Desktop to its own folder on your C: so backups can be created. Do this before continuing.
    ===


    Check the following in HJT and click 'Fix Checked'

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O1 - Hosts: 127.0.0.5 n-glx.s-redirect.com
    O1 - Hosts: 127.0.0.5 x.full-tgp.net
    O1 - Hosts: 127.0.0.5 counter.sexmaniack.com
    O1 - Hosts: 127.0.0.5 autoescrowpay.com
    O1 - Hosts: 127.0.0.5 www.autoescrowpay.com
    O1 - Hosts: 127.0.0.5 www.awmdabest.com
    O1 - Hosts: 127.0.0.5 www.sexfiles.nu
    O1 - Hosts: 127.0.0.5 awmdabest.com
    O1 - Hosts: 127.0.0.5 sexfiles.nu
    O1 - Hosts: 127.0.0.5 allforadult.com
    O1 - Hosts: 127.0.0.5 www.allforadult.com
    O1 - Hosts: 127.0.0.5 www.iframe.biz
    O1 - Hosts: 127.0.0.5 iframe.biz
    O1 - Hosts: 127.0.0.5 www.newiframe.biz
    O1 - Hosts: 127.0.0.5 newiframe.biz
    O1 - Hosts: 127.0.0.5 www.vesbiz.biz
    O1 - Hosts: 127.0.0.5 vesbiz.biz
    O1 - Hosts: 127.0.0.5 www.pizdato.biz
    O1 - Hosts: 127.0.0.5 pizdato.biz
    O1 - Hosts: 127.0.0.5 www.awmcash.biz
    O1 - Hosts: 127.0.0.5 awmcash.biz
    O1 - Hosts: 127.0.0.5 buldog-stats.com
    O1 - Hosts: 127.0.0.5 www.buldog-stats.com
    O1 - Hosts: 127.0.0.5 fregat.drocherway.com
    O1 - Hosts: 127.0.0.5 slutmania.biz
    O1 - Hosts: 127.0.0.5 www.slutmania.biz
    O1 - Hosts: 127.0.0.5 toolbarpartner.com
    O1 - Hosts: 127.0.0.5 www.toolbarpartner.com
    O1 - Hosts: 127.0.0.5 www.megapornix.com
    O1 - Hosts: 127.0.0.5 megapornix.com
    O1 - Hosts: 127.0.0.5 www.sp2****ed.biz
    O1 - Hosts: 127.0.0.5 sp2****ed.biz
    O1 - Hosts: 127.0.0.5 greg-tut.com
    O1 - Hosts: 127.0.0.5 www.greg-tut.com
    O1 - Hosts: 127.0.0.5 nylonsexy.com
    O1 - Hosts: 127.0.0.5 www.nylonsexy.com
    O1 - Hosts: 127.0.0.5 vparivalka.com
    O1 - Hosts: 127.0.0.5 www.vparivalka.com
    O1 - Hosts: 127.0.0.5 iframeprofit.com
    O1 - Hosts: 127.0.0.5 www.iframeprofit.com
    O1 - Hosts: 127.0.0.5 topsearch10.com
    O1 - Hosts: 127.0.0.5 www.topsearch10.com
    O1 - Hosts: 127.0.0.5 statscash.biz
    O1 - Hosts: 127.0.0.5 www.statscash.biz
    O1 - Hosts: 127.0.0.5 vxiframe.biz
    O1 - Hosts: 127.0.0.5 www.vxiframe.biz
    O1 - Hosts: 127.0.0.5 crazy-toolbar.com
    O1 - Hosts: 127.0.0.5 www.crazy-toolbar.com
    O1 - Hosts: 127.0.0.5 topcash.biz
    O1 - Hosts: 127.0.0.5 www.topcash.biz
    O1 - Hosts: 127.0.0.5 loadcash.biz
    O1 - Hosts: 127.0.0.5 www.loadcash.biz
    O1 - Hosts: 127.0.0.5 txiframe.biz
    O1 - Hosts: 127.0.0.5 www.txiframe.biz
    O1 - Hosts: 127.0.0.5 procounter.biz
    O1 - Hosts: 127.0.0.5 www.procounter.biz
    O1 - Hosts: 127.0.0.5 advadmin.biz
    O1 - Hosts: 127.0.0.5 www.advadmin.biz
    O1 - Hosts: 127.0.0.5 trafficbest.net
    O1 - Hosts: 127.0.0.5 www.trafficbest.net
    O1 - Hosts: 127.0.0.5 besthvac.com
    O1 - Hosts: 127.0.0.5 www.besthvac.com
    O1 - Hosts: 127.0.0.5 traff4.com
    O1 - Hosts: 127.0.0.5 www.traff4.com
    O1 - Hosts: 127.0.0.5 ambush-script.com
    O1 - Hosts: 127.0.0.5 www.ambush-script.com
    O1 - Hosts: 127.0.0.5 beehappyy.biz
    O1 - Hosts: 127.0.0.5 www.beehappyy.biz
    O1 - Hosts: 127.0.0.5 tracktraff.cc
    O1 - Hosts: 127.0.0.5 www.tracktraff.cc
    O1 - Hosts: 127.0.0.5 allcount.net
    O1 - Hosts: 127.0.0.5 www.allcount.net
    O1 - Hosts: 127.0.0.5 onedayoffer.biz
    O1 - Hosts: 127.0.0.5 www.onedayoffer.biz

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

    O4 - Startup: PowerReg Scheduler.exe
    ===


    Download Ewido Security Suite
    1. Install ewido security suite
    2. When installing the program, under "Additonal Options" uncheck..
      • Install background guard
      • Install scan via context menu
    3. Launch ewido, there should now be an icon on your desktop, double-click it.
    4. The program will now open to the main screen.
    5. When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We will fix this in a moment.
    6. You will need to update ewido to the latest definition files:
      • On the left hand side of the main screen click update.
      • Then click on Start Update.
    7. The update will start and a progress bar will show the updates being installed.
      (the status bar at the bottom will display "Update successful")
    If you are having problems with the updater, you can use this link to manually update ewido.
    Ewido Manual Updates

    Once the updates are installed, do the following:
    1. Click on scanner.
    2. Click on Complete System Scan, the scan will now begin.
    3. While the scan is in progress you will be promted to clean files, click OK.
    4. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says "Perform action on all infections", then choose clean and click OK.
    5. Once the scan has completed, there will be a button located at the bottom of the screen named Save Report.
    6. Click Save Report.
    7. Now save the report .txt file to your desktop.
    ===

    Reboot and post a new HJT log :)
  • edited November 2005
    Thanks Trogan :thumbsup:

    When I ran Ewido Security Suite it found cleaned and backed up 242 errors. I then rebooted and ran HiJackThis and the log is 3k smaller, its attached.

    Andy :)
  • TroganTrogan London, UK
    edited November 2005
    Look at this guide here: http://www.short-media.com/forum/showpost.php?p=172591&postcount=4

    This is what I want you to do.

    1) Disable System Restore

    2) Reboot

    3) Enable System Restore

    4) Create a new restore point

    5) Update AVG and do a full system scan.


    Post back with the results of AVG, if any :)
  • edited November 2005
    I have done the things you sugest. I could not find an easy way to save the AVG log but it was clean and I had the update from 22/11 at 17:30. It looks like all the problems are gone :D

    Thanks again :thumbsup:

    Andy
  • TroganTrogan London, UK
    edited November 2005
    No problem. Glad I could help :)


    I'm on my laptop at the moment but when I go on the desktop PC, i'l give you some instructions to follow to stay more secure. :thumbsup:
  • edited November 2005
    I have updated Spybot-S&D to 1.4 from 1.3. I am running Microsoft AntiSpyware and ewido secrity guard. I have searched for upgraded to SpyBot and done a scan. FYI

    Andy :)
  • TroganTrogan London, UK
    edited November 2005
    Good job :thumbsup:



    Please consider joining the Folding@Home Project :)
    Join our Folding@Home team! Alzheimer's, Parkinson's, cancer... we're trying to cure them with our computers! You've at least read a little about it in the greeting I sent you when you signed up for the site. We're always really pleased to greet new members to the team, and it's a quick way to become an appreciated member of the community.
    MORE INFO: READ THIS



    Follow this guide by Crunchie to stay more secure

    Now that your PC is clean you need to follow these easy steps to keeping it this way:

    Secure your Internet Explorer by going here and following the instructions there.

    Better yet, use an alternative browser! Download FireFox and give it a run. It is far more secure than Internet Explorer. Or, you can get Opera which in my opinion, is better still.

    Use a firewall to help prevent your PC's control being usurped by undesireables.

    Install and keep updated, Ad-Aware SE, and Spybot S&D.
    Run them both on a regular basis, following the manufacturer's recommendations.

    Install and keep updated, SpywareBlaster 3.4

    Install an anti-virus. There are some good, free AV's available today. Make sure that it is updated regularly and have it scan your system often.

    Check for Windows Updates. Microsoft regularly post updates for your systems safe running. Make sure to take advantage of this. Reboot when installed and return to make sure there are no others.


    Clear your Temp folders.
    Clear out your Temporary internet files and other temp files.
    Go to Start > Settings > Control Panel >Internet Options.

    Under the General tab click the Delete temporary internet files,
    delete all Offline content as well. Clear out Cookies.

    Also, go to Start > Find/search > Files or folders > in the named box, type: *.tmp and choose Edit > select all -> File > delete.

    Empty/delete the entire contents of the C:\Windows\temp folder and C:\temp folder, if you have one. (Contents but not the folder itself.)

    C:\Documents and Settings\username\Local Settings\Temp\

    In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.

    Empty the Recycle Bin.

    For XP users.
    After something like this it is a good idea to Flush the Restore Points and start fresh.
    To flush the XP system Restore Points.

    Go to Start>Run and type msconfig. Press enter.

    When msconfig opens, click the Launch System Restore Button.
    On the next page, click the System Restore Settings link on the left.

    Check the box labelled 'Turn off System restore'.

    Reboot. Go back in and Turn System Restore Back on. A new Restore Point will be created.

    Note that all previous restore points will be lost.

    ===============

    If you have any more problems, post back.
  • edited November 2005
    I have FireFox 1.5rc3. I have Ad-Aware SE, and Spybot S&D. I will be getting SpyWareBlaster very soon after I have checked for Windows updates. I will check out Folding@Home, but I already run SETI@home, Einstien@home and Predictor@home.

    Andy :D
  • TroganTrogan London, UK
    edited November 2005
    OK Cool :thumbsup:

    Let me know if I can mark this resolved or leave it open.

    :thumbsup:
  • edited November 2005
    Its resolved, thanks :thumbsup:

    Andy :cool:

    PS. Its a shame Folding at Home is not a BOINC client so I could add it to the rest.
  • TroganTrogan London, UK
    edited November 2005
    Hmmm...I don't think this thread should be closed until you get Folding atleast on one computer :D


    So, whats a BOINC client?
  • edited November 2005
    BOINC is an open client and runs many different projects such as SETI@Home soaking up the unused CPU time on your PC. It seems to work much as F@H does from what I read check http://boinc.berkeley.edu/

    If F@H was to use the BOINC client I would add it to the three projects I have running at this time. As it stands it would either get 0% CPU or block BOINC I think.

    Andy ;)
  • TroganTrogan London, UK
    edited November 2005
    Ohh, I see :thumbsup:


    Maybe someday F@H will use BOINC :)


    Shall I mark this thread resolved?
  • edited November 2005
    Yes all resolved now :thumbsup:

    I will see I can get on to a project with the same objectives as F@H as its a great idea :D

    Andy :)
  • TroganTrogan London, UK
    edited November 2005
    Thanks :thumbsup:
This discussion has been closed.