Results 1 to 10 of 26

Thread: Yikes! I think I have a Backdoor Trojan Worm

Hybrid View

  1. #1
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Well combofix found nothing. Please Uninstall it by following these instructions exactly:
    * Click START then RUN
    * Now type ComboFix /Uninstall in the runbox and click OK. The space between the combofix and the /uninstall, it must be there.
    When shown the disclaimer, Select "2"

    Now one thing you need to check is this:
    Go to Services again...

    Go to Start/Administrative Tools/Services/Themes. Set to Automatic
    and make sure it is Started.
    Reboot and see if that makes a difference.

  2. #2
    Join Date
    Aug 2006
    Location
    Planet Earth
    Posts
    45
    good morning judy...i followed your instructions.

    i typed a space after combofix before /uninstall.
    i was not offered to select "2"
    combofix was noted as being removed as per the prompt.

    i checked services again.
    themes was already set to automatic and already started.

    i re-booted my pc
    should i run another HJT log to post?

    services is still showing this;

    Windows Driver Foundation -User-mode Driver Framework
    GENERAL TAB
    WudfSvc
    Manages user-mode driver host processes
    C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
    Disabled
    Stopped

    LOG ON TAB
    Local System account is dotted
    Profile 1 / Service Enabled

    RECOVERY TAB
    Take No Action
    Take No Action
    Take No Action
    0 days
    1 minutes

    DEPENDENCIES TAB
    Plug and Play

    Windows Task Manager displays six [6] svchost.exe running at different Memory Usage Amounts - for your info:

    svchost.exe-LOCAL SERVICE [3,696k]
    svchost.exe-SYSTEM [5,200k]
    svchost.exe-NETWORK SERVICE [4,256k]
    svchost.exe-SYSTEM [25,712k]
    svchost.exe-NETWORK SERVICE [3,552k]
    svchost.exe-LOCAL SERVICE [7,208k]

  3. #3
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok Melissa, have done more research on this entry. I was wrong it is not an infection but related to Plug and Play drivers. What external devices do you have connected to this machine? This would include printers, external hard drives, flash drives, scanners, cameras, or anything that is not installed inside the case, even something like a USB mouse or keyboard.
    The correct setting for this WudfSvc should set to Manual not disabled.

    Also go to the Device Manager and click on Display Adapter, is there an error showing there? You may need a new driver or the current driver may have become corrupt. Right Click on your Adapter and choose Uninstall. This will uninstall the adapter. Reboot the computer and allow the computer to find the "new" adapter and install it. See if this makes a difference.
    If it does not then go back in there, open that up again, Right click on the Adapter and choose Properties. Click on the Driver Tab. This will give you the driver provider and version. Go to the driver provider's web site and see if there is an updated driver, if there is one, download and install it. Reboot and again see if this makes a difference.

  4. #4
    Join Date
    Aug 2006
    Location
    Planet Earth
    Posts
    45
    hello judy...and thank you for your time and dedication.

    external devices;
    printer/scanner/fax/copier machine (it's an all-in-one)

    xbox 360

    secondary pc that's never turned on but fully protected with norton as is the primary pc

    external hard drive when needed to do a back-up of files
    keyboard
    mouse
    speakers
    modem
    digital camera on occassion

    i have not yet re-installed my ipod or digital video camera.

    i re-set the WudfSvc to its original settings [manual]

    device manager
    display adapter is working properly
    since no errors are showing, i did not uninstall

    would the i infected file that was deleted by malware bytes be the culprit?
    it was called hijack.startmenu and it's noted on the MBAM log 03-25-2010

  5. #5
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    device manager
    display adapter is working properly
    since no errors are showing, i did not uninstall
    doesn't matter if it shows no errors. Very often the driver file can be corrupt and not show an error. Do as I suggested, uninstall and then reboot and let it find the device and install it.

    No, this problem found by MBA-M would not be the culprit.

  6. #6
    Join Date
    Aug 2006
    Location
    Planet Earth
    Posts
    45
    judy...i followed your last set of instructions with regard to display adapter uninstall, rebooted pc, it found the new device driver.

    what now? :-)

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •