Help - Search - Members - Calendar
Full Version: trojan infected registry
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
ronss
got this on Scan started at 7/29/2004 2:55:07 AM

Scanning memory...
Scanning boot sectors...
Scanning files...
C:\WINDOWS\system32\abfgng.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\ajl.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\bgmang.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\bpaknga.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\ccolmg.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\ehkgmg.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\eiken.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\ikbom.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\ohcj.dll - Trojan:Win32/StartPage.IX -> Infected
C:\WINDOWS\system32\omldng.dll - Trojan:Win32/StartPage.IX -> Infectedmy computer

anyone know how to get rid of it??????????????//
LoPhatPhuud
Those files are not part of Windows. My guess is you have some form of malware. Boot into Safe Mode and delete those files.

then:

Download *Hijack This!*
http://209.133.47.12/~merijn/files/HijackThis.exe
http://downloads.net-integration.net/HijackThis.exe
http://www.computercops.biz/downloads-file-328.html

Unzip to a folder other than your Desktop or the Temp folder. Then, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that and copy & paste its contents here.

Most of what it lists will be harmless or even essential, don't fix anything yet. Someone will be along to tell you what steps to take after you post the contents of the scan results.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.