Go Back   Computer Juice > Computer Software > Virus, Spyware & Security
Register Members New Posts Donate Unanswered Posts Site Spy Search


Reply
 
Thread Tools
  #1  
Old 17-11-2007, 06:37 AM
No Avatar
Ancodi  United Kingdom
CJ New Member
 
Ancodi is offline
 
Join Date: Nov 2007
Last Online: 19-11-2007 08:10 AM
Posts: 7
iTrader: (0)
Ancodi is on a distinguished road
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

How do I remove it? Is DLLhost an important file? I have Eset Nod32 2.7.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #2  
Old 17-11-2007, 06:43 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 02:37 AM
Posts: 4,601
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

Welcome to TCF.

Lets have a closer look.

Download HijackThis to your desktop.
Double-click on the file you just downloaded.
Click on the "Install" button to install.
It will by default install to the directory - C:\Program Files\Trend Micro\HijackThis
Please do not change the default install location.
Upon install, HijackThis should open for you.

Next click on the "Do a system scan and save a log file" button.
HijackThis will scan and then a log will open in notepad.
In the top left of the notepad window click "File" > "Save As" name it hijackthis and then save it to the Desktop.
Please save the log as a text (.txt) file or .log
Do NOT attach MS-Word .DOC files, they will NOT be looked at!
In your post, add the log as an Attachment.
* Don't have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
** Don't use the Analyse This button. It's findings are dangerous if misinterpreted.

Guide for attaching logs to a post
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #3  
Old 17-11-2007, 06:51 AM
No Avatar
Ancodi  United Kingdom
CJ New Member
 
Ancodi is offline
 
Join Date: Nov 2007
Last Online: 19-11-2007 08:10 AM
Posts: 7
iTrader: (0)
Ancodi is on a distinguished road
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

is it safe to post this file? I will if you say it is. =] thanks for the help, i just need to save it all. =]
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #4  
Old 17-11-2007, 06:55 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 02:37 AM
Posts: 4,601
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

There is no personal information in any log I will ask for. We have to be able to see what all is running on the PC to know the right steps to remove it.

Also what program reported the infection?
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #5  
Old 17-11-2007, 06:57 AM
No Avatar
Ancodi  United Kingdom
CJ New Member
 
Ancodi is offline
 
Join Date: Nov 2007
Last Online: 19-11-2007 08:10 AM
Posts: 7
iTrader: (0)
Ancodi is on a distinguished road
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

When I booted up the computer, Ashampoo FIrewall said that a filter thing hadn't worked or something.
Nod 32 2.7 said I had the virus.
Attached Files
File Type: txt hijackthis.txt (8.0 KB, 7 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #6  
Old 17-11-2007, 07:09 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 02:37 AM
Posts: 4,601
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

Open HijackThis and select "Do a system scan only"

Place a check mark next to these entries:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - S-1-5-21-299502267-839522115-854245398-1003 Startup: PowerReg Scheduler.exe (User '?')
O4 - Startup: PowerReg Scheduler.exe
O23 - Service: Windows Display Driver - Unknown owner - C:\Program Files\Common Files\Dllhost.exe
O24 - Desktop Component 1: (no name) - http://en.wikipedia.org/


Close all windows and click "Fix checked"

==========

Please download Combofix by sUBs from either here or here

Save Combofix.exe to your your Desktop.

1. Double click combofix.exe & follow the prompts. (from the keyboard select 1 and press enter at the prompt)
2. When finished, it will produce a log for you.
3. Attach that log in your next reply.

Note:
Do not mouseclick combofix's window while it's running. That may cause your computer to stall
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #7  
Old 17-11-2007, 07:36 AM
No Avatar
Ancodi  United Kingdom
CJ New Member
 
Ancodi is offline
 
Join Date: Nov 2007
Last Online: 19-11-2007 08:10 AM
Posts: 7
iTrader: (0)
Ancodi is on a distinguished road
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

Just to let you kno, I hate the program, I don't trust it xD. It kinda delete sys32, which I thought you kinda needed. I probably hate it because it's not GUI, which I trust xD.
Attached Files
File Type: txt log.txt (14.3 KB, 2 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #8  
Old 17-11-2007, 07:56 AM
No Avatar
Ancodi  United Kingdom
CJ New Member
 
Ancodi is offline
 
Join Date: Nov 2007
Last Online: 19-11-2007 08:10 AM
Posts: 7
iTrader: (0)
Ancodi is on a distinguished road
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

Hello? I am desperate...
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #9  
Old 17-11-2007, 07:58 AM
evilfantasy's Avatar
CJ Moderator
Intel ATi
evilfantasy is online now
Send a message via Yahoo to evilfantasy
 
Join Date: Jul 2007
Last Online: Today 02:37 AM
Posts: 4,601
iTrader: (0)
evilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond reputeevilfantasy has a reputation beyond repute
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

Takes a minute to look through the logs mate...

Run HijackThis and post a fresh log please.
__________________
.
.
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote
  #10  
Old 17-11-2007, 08:06 AM
No Avatar
Ancodi  United Kingdom
CJ New Member
 
Ancodi is offline
 
Join Date: Nov 2007
Last Online: 19-11-2007 08:10 AM
Posts: 7
iTrader: (0)
Ancodi is on a distinguished road
Default c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan

Ah, sorry. ^^;
What my dad's telling me to do is just scan nod, if it isn't in the system32 folder, which I thought that combofix deleted, I'll delete it, he said. But, we think it's gone.
Attached Files
File Type: txt hijackthis.txt (7.6 KB, 4 views)
Digg this postDel.icio.us this postTechnorati this postNetscape this postStumble this post
Reply With Quote

Please support this forum, donate towards our running costs.


Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Win 2000Pro has 2 program files directory jensen1328 Windows Operating Systems 2 07-06-2008 07:05 PM
convert .mov (quicktime) files to .avi files? Kona1984hawaii Multimedia, Drivers & Codecs 9 03-03-2008 06:58 PM
Re: c:\program files\common files\dllhost.exe infrected with Win32/Hupigon.MN trojan cjd666 Virus, Spyware & Security 3 21-11-2007 08:14 PM
Win32.Poison.k Trojan casselle Virus, Spyware & Security 7 22-10-2007 08:28 AM
Whats a free program can i use to convert files... -=>¿Luî§?<=-™ Multimedia, Drivers & Codecs 1 01-04-2007 08:17 AM


Copyright ©2006 - 2008 Computer Juice.

Powered by vBulletin® Copyright ©2000 - 2008 Jelsoft Enterprises Ltd. SEO by vBSEO ©2008, Crawlability, Inc.

Page copy protected against web site content infringement by Copyscape