automatic updates trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by berthill6@hotmail.com, Jun 18, 2008.

  1. berthill6@hotmail.com

    berthill6@hotmail.com Private E-2

    I was downloading something for a game and I ran the .exe file. It failed saying something about Vista Service Update 1, but then the automatic updates alert appeared on my taskbar.

    I clicked it and it said that 'windows recommends me to keep the automatic update thing on blah blah' so when I click that then it says 'you must do this manually' and when I try to do it manually I found out that my automatic updates are on afterall. Afterwards I was reading the comments about the download and I found warnings that said it had a trojan in it. I tried to delete the .rar file that contained the .exe file and it wouldn't let me because it was in use. Eventually I managed to delete it I think, but the problem remains, probably because the trojan has moved itself elsewhere.

    I'm using Trend Micro PC-cillin (came with my PC) and I scanned and found nothing. Currently I'm downloading Avast! to see if it can succeed where Trend has failed. Is anyone familiar with this type of virus? If so, how can I go about removing it, or at least stop it from being a problem?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What was the name of the file and where exactly was it located.

    You must not install Avast or any other antivirus while another is already installed. If you already installed Avast and still had TrendMicro install, you must uninstall one of them immediately which you will see has one of the first steps in the below instructions.

    If you wish to check to see if you have any real malware problems, please follow the instructions in the below link. Attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. berthill6@hotmail.com

    berthill6@hotmail.com Private E-2

    The name of the .exe file was setup.exe I believe. The name of the .rar directory it was in was called "SPORE Creature Creator multi-lang crack.rar".

    And yes, I was reading your guide to removing malware and did not end up downloading avast.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but where was this rar file located. That is what was the full path to the file.

    That's Great! ;)
     
  5. berthill6@hotmail.com

    berthill6@hotmail.com Private E-2

    The rar file was located in the downloads folder of My Documents.

    By the way, I was checking the recent comments on the torrent and discovered this:

    InkDragon at 2008-06-18 23:42 CET:
    This contains backdoor.rbot.as & sheur.bnru, use AVG to remove them.
     
  6. berthill6@hotmail.com

    berthill6@hotmail.com Private E-2

    I've also been doing a little research and I have high suspicions that these trojans are in C:\Recycler. Is there a way I can delete them from here?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you run the READ & RUN ME, the Recycle Bin will be emptied when you run CCleaner. You can also empty the Recycle Bin yourself any time you want.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds