FlyStudio.OGS trojan removal

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by yumatu, Dec 6, 2011.

  1. yumatu

    yumatu Private E-2

    Hi.
    My Eset found FlyStudio_OGS trojan removal in family picture folders on my usb flash. eset wants to delete them but i really need those pics.
    How can i clean and save this data ?
     
  2. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, yumatu!

    Can you attach a log from ESET on what it is claiming to be infected?

    If you would like us to help you remove malware from your PC -- See this link: READ & RUN ME FIRST Malware Removal Guide
     
  3. yumatu

    yumatu Private E-2

    it sais "G:\Mypics.exe - Found FlyStudio_OGS trojan"
    "Mypics" is the name of the folder where the pictures are.
     
  4. thisisu

    thisisu Malware Consultant

    Mypics.exe is a file though. An infected file.

    It's just a coincidence (and clever thinking by the malware creator) that your pictures folder is also named "Mypics". :)

    I would recommend going through the READ and RUN ME First Malware Removal Guide thread as there may be other files infected (not just on your flash drive).
     
  5. yumatu

    yumatu Private E-2

    But when I did try to clean it eset deleted the folder! I did save a copy that is still infected. damn... :confused what is this?
     
  6. thisisu

    thisisu Malware Consultant

    Unfortunately I can't tell you what is wrong without seeing any type of logs.

    I'd be more than happy to help you resolve any malware problems you have but you would first need need to go through the link I posted above so that I have the information needed to help you.
     
  7. yumatu

    yumatu Private E-2

    Scan Log
    Version of virus signature database: 6691 (20111207)
    Date: 07/12/2011 Time: 21:31:33
    Scanned disks, folders and files: F:\Boot sector;F:\
    F:\club_application.exe - a variant of Win32/FlyStudio_OGS trojan
    F:\My Vaults.exe - a variant of Win32/FlyStudio_OGS trojan
    F:\MiriDa.exe - a variant of Win32/FlyStudio_OGS trojan
    F:\Fux.exe - a variant of Win32/FlyStudio_OGS trojan
    F:\Recycled.exe - a variant of Win32/FlyStudio_OGS trojan

    Number of scanned objects: 1904
    Number of threats found: 5
    Number of cleaned objects: 0
    Time of completion: 21:31:52 Total scanning time: 19 sec (00:00:19)

    The names MiriDa,Fux are the folder names.
     
  8. thisisu

    thisisu Malware Consultant

  9. yumatu

    yumatu Private E-2

    I'm not authorized to install new soft here.
    I did mange to install Malwarebytes'.
    so here is the log atached
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    Code:
    Files Infected:
    f:\club_application.exe (Worm.Autorun) -> No action taken.
    f:\my vaults.exe (Worm.Autorun) -> No action taken.
    f:\MiriDa.exe (Worm.Autorun) -> No action taken.
    f:\Fux.exe (Worm.Autorun) -> No action taken.
    f:\Recycled.exe (Worm.Autorun) -> No action taken.
    I would recommend letting MBAM to remove these detected items.

    Is this a work computer?

    Another program you may want to try is: Flash Disinfector by sUBs

    How To Use The Tool

    *Please remember to disable any AV / ScriptBlockers as they might detect Flash Disinfector to be malicious and block it. Hence, the failure in executing. You can enable them back after the cleaning process*

    Mirror — http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe

    Download Flash Disinfector by sUBs and save it to your desktop.

    Double-click Flash_Disinfector.exe to run it. Follow any prompts that may appear.
    Your desktop will vanish for a while, and then reappear. This is normal.
    Wait until the program has finished scanning, then please exit the program.
    Restart your computer and see if problem still persists
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds