Trojan Horse

Discussion in 'Malware Help (A Specialist Will Reply)' started by Anant, Apr 2, 2008.

  1. Anant

    Anant Private E-2

    Hi, My anti - virus scan recently picked up a trojan horse, in my computer. specifically windowns/system32. Everytime i start the scan in the new file is picked up in system32 called "trojan horse" i have read up about them, but i cant find anyway to remove it. Please advice?
    I have a log by "HIJackThis" do u need it?

    Thanks

    Anant
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!


    HijackThis is simply a tool that is used to identify browser hijackers and in some cases it will show entries for some malware that is for instance running at startup. A HijackThis log shows the following:
    • a running process list with no reference to good or bad
    • it lists the contents of a selected group of registry keys that is an an extremely small subset of the tens of thousands of keys that may exist. Again no reference to good or bad.
    • and some of the above keys that are shown may show some non-Microsoft system services that are running. Again with no reference to good or bad.
    The decision on what is good or bad is left a person with significant Windows and malware cleaning experience.

    HijackThis does not come close to showing all malware that could be hiding on a PC. Anyone who has an infected computer and is relying on HijackThis without the benefit of running other scans such as Spybot, Windows Defender, BitDefender & Panda, CCleaner, etc. are more than likely still infected. In most cases, where there is one virus/trojan there are more.

    So on its own a hijackthis log is not much use, so please follow the below guide.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide

    After these are attached our malware experts will review these to see if your OK, if not they will issue you some further removal instructions, So logs that you will get to attach are:

    MGlogs.zip (which has 5 logs inside it, including Hijackthis, just attach the whole Zip )
    MalwareBytes log
    Superantispyware log

    plus a guide on how to attach the logs HOW TO: Attach Items To Your Post
     
  3. Anant

    Anant Private E-2

    Hi

    Thanks for replying so soon, i have followed the first step. You are the logs u requested. Please keep my posted!

    Thanks Again

    Anant
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please delete the below copy of MGtools.exe. This is not where we asked you to save it or run it from.
    C:\Documents and Settings\P Dole\Desktop\Anant's folders\MGtools.exe

    Now immediately uninstall either Avast or NOD32 as requested at the beginning of the READ ME wher we specified that you must only use one antivirus.

    Now uninstall the below old Sun Java versions and install the current version as requested in the READ ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 9

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    What is the below startup process line for?
    O4 - HKCU\..\Run: [NanoMate] NULL

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [SW20] C:\windows\system32\sw20.exe
    O4 - HKLM\..\Run: [SW24] C:\windows\system32\sw24.exe
    O4 - HKLM\..\Run: [WinSys2] C:\windows\system32\winsys2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  5. Anant

    Anant Private E-2

    Hi

    I have done all that you requested except


    What is the below startup process line for?
    O4 - HKCU\..\Run: [NanoMate] NULL


    I dont know how to find this, please advise?
    Otherwise everything was fine, and my avast virus scan has not been popping up lately saying TROJAN HORSE, i am gratefully for this.

    Thanks!

    Attached are the 2 logs you requested

    Anant
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not asking you to find it. It is in your HijackThis and runkeys.txt log which means it is in your registry. What I'm asking you is do you know what it is for? I assume by your first response that you don't know what it is. If this is true then do the below.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKCU\..\Run: [NanoMate] NULL

    After clicking Fix, exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created.


    Is everything still working OK?
     
  7. Anant

    Anant Private E-2

    Hi

    I fixed the following 2 things that you requested. Otherwise the computer is working 100% ok! There are no problems!

    Attached is the file

    Thanks

    Anant
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    5. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  9. Anant

    Anant Private E-2

    Hi

    I have done eveything, thanks for all the help!

    Thanks again

    Anant
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     
  11. Anant

    Anant Private E-2

    Re: Trojan Horse New (.scr)

    Hi Again,

    I seem to be having some problem with my word documents. When i attach them to email in particular, the file extention changes to .scr
    i read about this extension on the net, and it says it is sometimes caused when u receive a Trojan. But i have found a way to combat the problem by renaming the file and saving it as .doc But i dont know why it save as .scr in the first place...

    What should I do?
    Does this still mean I have a Trojan Horse?
    Please Advise

    Thanks

    yours sincerly

    Anant
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Trojan Horse New (.scr)

    Your problem may or may not be malware. It could be this: http://www.sophos.com/security/analyses/viruses-and-spyware/w32rungbua.html

    However, it has been more than 3 weeks since we cleaned your PC. Even in one weeks time a lot can happen. You need to re-run the READ & RUN ME and attach all new logs, but you need to start a new thread since this has nothing to do with your original problem.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds