how to identify trojan threat source when AVG catches it

Discussion in 'Malware Help (A Specialist Will Reply)' started by bullfrog, Jun 14, 2010.

  1. bullfrog

    bullfrog Private E-2

    How can I identify a trojan generic dropper source when AVG catches it? It has happened each day the last few days. AVG has them in the Vault, but I would like to know where it is coming from.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What are you doing when AVG flags it? Are you downloading, on a certain web site? It is very difficult to pin point where a trojan may be coming from as you can sometimes get infected just flipping through web sites without having to click on anything. But if you are getting it repeatedly, are you certain that there is not something else on your system that is causing it? The best thing to do is to follow these instructions so we can ascertain whether you are clean or not:

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. bullfrog

    bullfrog Private E-2

    Thanks for some outstanding help.

    What am I doing when it happens? checking email through Outlook Express

    Today I had TrojanHorse Downloader.small.HFH : It occurred twice

    Then I got TrojanHorse Downloader.Generic9.CCSI

    I ran all the Read and Run First with the exception of the final step.

    What I was looking for in my original post was how to identify which email caused it. AVG, in the vault, identifies the object, but can I go to that file without causing more pain?

    Thanks again, TimW
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you think this is an email type infection ( which I am assuming as you did not attach any of the requested logs), then only you can remove the culprit.

    Malware detected in email databases has to be cleaned up by you. You have a few choices:

    1. delete the whole file which is not an option you normally want to use
    2. load the email folder that contains the infection and delete ALL unnecessary emails (hoping to remove the problem email) and then use the Mailbox Cleanup option to delete all old emails. Then compact the Outlook database to permanently remove data. See http://support.microsoft.com/kb/196990 If you do not cleanup and compact the databases, the deleted emails may still be leaving hidden information in the database that you just cannot see but a scanner may still pickup on it.
    3. create a new folder and move only emails you really need into the new folder and then delete the infected folder.
     
  5. bullfrog

    bullfrog Private E-2

    Tim,
    Thanks for this additional information.

    I deleted all the emails that potentially had the virus. None of them were/are of value to me, just stuff from friends(?).

    When AVG blocks the virus and puts it in the vault, is it stripped from the email? Or is it still with the email in the deleted folder.
    Ray
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That I don't know. Obviously if the questionable email is no longer there, then the whole email may be captured by AVG, but I think it is more likely that it only captures the infected file, leaving the email that it came in on.

    This is why I like to use an email program such as Mailwasher. That way you can preview any suspect emails before downloading them.

    And you are most welcome. If you ran our procedures:

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     
  7. bullfrog

    bullfrog Private E-2

    Tim,
    Thanks again very much for all your recommendations and suggestions.

    Nothing showed up today in the email. My suspected source for yesterday's viruses uses Norton; he scanned yesterday, but found nothing. Who knows??

    Thanks again,
    Ray
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds