1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojan - Collected.5.L

Discussion in 'Malware and Virus Removal Archive' started by cvzyl, 2005/06/19.

Thread Status:
Not open for further replies.
  1. 2005/06/19
    cvzyl

    cvzyl Inactive Thread Starter

    Joined:
    2005/06/19
    Messages:
    8
    Likes Received:
    0
    I have a PC that seems to be infected with the trojan Collected.5.L. I use AVG Free 7.0 virus scanner and it reports that the c:\windows\system32\msdirectx.sys file is infected. Neither healing, deleting the file or moving the file to quarantine seems to be able to resolve the problem.

    How do I fix this???

    Here is my HijackThis log. (There are also mcafee32.exe and hwclock.exe which I cannot get rid of.)

    Please help!!!

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINDOWS\Explorer.exe
    C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\mcafee32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
    C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
    C:\Program Files\KGSoft\HiDialer 2000\HiDialer2k.exe
    C:\WINDOWS\slrundll.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\System32\devldr32.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avginet.exe
    C:\WINDOWS\System32\WISPTIS.EXE
    C:\WINDOWS\System32\dwwin.exe
    C:\Setup\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.standardbank.co.za/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.standardbank.co.za/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.standardbank.co.za/
    F2 - REG:system.ini: Shell=Explorer.exe mcafee32.exe
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [Device Detector] DevDetect.exe -autorun
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe "
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{33B803D3-7A9D-42C3-BB5E-5E22D8AF16B0}: NameServer = 196.25.1.1 196.25.1.9
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)
    O23 - Service: Remote Administrator Service (r_server) - Unknown owner - C:\WINDOWS\System32\r_server.exe" /service (file missing)
    O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
    O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
     
  2. 2005/06/19
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Trojan - Collected.5.L is a rootkit backdoor trojan with the ability to hide other malware and keep it from being detected by malware removal tools.

    It can be removed by some antivirus pgms and online scanners. AVG does not yet fully handle this trojan.

    There's a solution here:
    http://discussions.virtualdr.com/showthread.php?t=187481
     

  3. to hide this advert.

  4. 2005/06/19
    adamt56

    adamt56 Inactive

    Joined:
    2005/03/24
    Messages:
    38
    Likes Received:
    0
    Delete "mcafee32 "

    C:\WINDOWS\System32\mcafee32.exe

    This is the Backdoor.Win32.Rbot.gen worm.
     
  5. 2005/06/19
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    You may want to print these out.

    Uninstall Spyhunter, it isn't very affective and was considered to be a rogue at one time. It may conflict with MS Antispy resident process. Spybot and Ad-Aware do a much better job, and they are free.

    Download the trial version of ewido security suite.
    Install ewido security suite and start the program from the icon on your desktop, then check for and download updates. Close for now.
    Ewido Setup

    Go to Start\Run and type in Services.Msc and press Enter. Locate the following in the list.
    Hardware Clock Driver (hwclock)
    Highlight it by clicking on it, and then Stop the service, you will get a small progress window when done correctly. Then right click on it and select Properties, and set to Disable.

    Disable System Restore

    Open HJT, and click on 'Open the misc tools section', click on 'Delete a file on reboot', and a File Open window will appear. Copy/paste the following into it.
    c:\windows\system32\msdirectx.sys
    Click on Open, and you will be prompted to reboot, select No at this time. Then do the same for these.
    C:\WINDOWS\System32\mcafee32.exe
    C:\WINDOWS\System32\hwclock.exe

    Rescan with HJT, and remove these items.
    F2 - REG:system.ini: Shell=Explorer.exe mcafee32.exe
    O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)

    Reboot into Safe Mode, and do the ewido scan. It is a trojan scanner and works very well.

    Delete all files in the folders C:\Windows\Prefetch and C:\Windows\Temp, and all files and folders located in the Temp folders for all users. Look under C:\Documents and Settings\username\Local Settings to find them.

    Then reboot in Normal mode, and enable System Restore. Please post a new HJT log
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.