Hello from Italy!

I've followed your instruction but when I've tried to run FindAWF again ( Press 2 and copy/paste the text ), the program runs and show me on the screen: Error: Cannot

Hope this can help you, thanks a lot for your patience!

Alternatively they may be installed by visiting a malicious web page (either by clicking on a link, or by the website hosting a scripted exploit which installs the Downloader onto the If a user is infected with a Trojan related to Doginhispen or it may render a computer useless by embedding a virus into a system's registry.

However they may themselves be downloaded by other viruses and/or Trojans to be installed on the user's system. Jan 9, 2008 #3 momok TS Rookie Posts: 2,265 Hi, You have not followed the instructions for the preliminary removal thread. Please attach this new FindAWF log in your reply, as well as the other required logs Regards, momok =)

When the program returns to the main menu, use the following option: Press E then Enter to EXIT Delete the following folder: C:\QooBox\Quarantine\C\WINDOWS Thereafter, please post fresh HJT and AVG Antispyware See how HERE After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"): RE: A.doginhispen paullotion Mar 3, 2008 4:25 AM (in response to HDoc) HDocThis particular trojan you have on board replaces legitimate files that are common on most computers with an infected Agent.DXH appears to be a component of a malware that targets Italian computer users.

Once files.txt is saved, FindAWF does the following: -It attempts to terminate the process represented by each filename on the list, if running -Deletes the rogue file from the parent folder, This trojan tries to download other malware from various websites and also lowers security settings on the compromised machine. A.doginhispen Started by Wuiser , Feb 09 2008 07:01 PM Press 1 then Enter.

ComboFix will begin to execute, just follow the prompts. I went to the Microsoft site and ran the virus scan there...also without result. I've attached the AWF file.

Once files.txt is saved, FindAWF does the following: -It attempts to terminate the process represented by each filename on the list, if running -Deletes the rogue file from the parent folder,

Join the community here, it only takes a minute.

The IP address may infect users with a very difficult Trojan to remove. Thank you! Asking for help via Private Message or Mail will be ignored - So If you need help, post your problem in the forum.

The Doginhispen and IP address infections are usually spread from a codec download. Regards KsB Jan 17, 2008 #21 momok TS Rookie Posts: 2,265 Hi, Your logs look clean now. You may wish to copy and paste these instructions on notepad for easier reference later.

Removal Trojan Technical Details Agent.DXH is installed on the system when the file is executed with "INSTALL" as the parameter.When this malware is installed on the system it will traverse the Press 2 then Enter. Next, close and click Yes to save the changes. Minimum Engine 5600.1067 File Length Description Added 2007-10-01 Description Modified 2007-10-03 Malware Proliferation The trojan tries to contact the following websites: http://b.whataboutadog.com[REMOVED] http://a.doginhispen.com[REMOVED][REMOVED][REMOVED] http://a.ciscering.com[REMOVED] It adds the following

Save this as CFScript on the desktop. Here's my Hijackthis log, and thanks in advance for your help:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:50:17 PM, on 2/9/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16574)Boot

Here the file Regards, KsB Jan 15, 2008 #13 momok TS Rookie Posts: 2,265 Hi, Run FindAWF again in safe mode. Similar Topics A.doginhispen.com and whataboutadog got me too Nov 19, 2007 A.doginhispen.com & b.skitodayplease.com Feb 7, 2008 A.doginhispen.com help Feb 2, 2008 A.doginhispen.com - help Feb 6, 2008 Help Please - IE7 often opens iin a non-maximized window, and these three entries appear. By performing this routine, the malware is able to automatically start itself during the system start.This malware is a downloader that tries to connect to the following domains: a.doginhispen.com b.skitodayplease.com Notes:

It is always a good practice to avoid unnecessary downloads if they are not approved by your currently installed software. Error: Cannot find a process with an image named CAPONN.exe Killing PID 560 'tfswctrl.exe' Regards, KsB Jan 14, 2008 #11 momok TS Rookie Posts: 2,265 Hi, Are you able to C:\WINDOWS\system32\spool\drivers\w32x86\3\bak C:\WINDOWS\system32\dla\bak C:\WINDOWS\system32\bak C:\Programmi\Toshiba\Windows Utilities\bak C:\Programmi\Toshiba\Touch and Launch\bak C:\Programmi\Toshiba\TOSHIBA Zooming Utility\bak C:\Programmi\Toshiba\TOSCDSPD\bak C:\Programmi\Synaptics\SynTP\bak C:\Programmi\Synaptics\SynTP\bak C:\Programmi\QuickTime\bak C:\Programmi\Nero\Nero8\Nero BackItUp\bak C:\Programmi\Lexmark X1100 Series\bak C:\Programmi\Kaspersky Lab\Kaspersky Anti-Virus Personal\bak C:\Programmi\iTunes\bak C:\Programmi\Google\GoogleToolbarNotifier\bak C:\Programmi\File comuni\Real\Update_OB\bak C:\Programmi\File comuni\Nero\Lib\bak C:\Programmi\ATI N/A.

Please remember to attach this report file in your reply along with all other required logs. Regards, momok Jan 14, 2008 #12 kingsbishop TS Rookie Topic Starter Posts: 24 Hello Momok, Done, seems it works! What do I do?