"Infostealer" Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by BFLeigh, Jun 16, 2006.

  1. BFLeigh

    BFLeigh Corporal

    I've just found this on my PC:

    Trojan "InfoStealer" found in:
    Key "hkey_current_user \software\microsoft\internet explorer\main" value "formsuggest pw ask"

    The weekend scans have found this, though I have only used eTrust PestScan so far, I'll run my usual scanners and report back anything else. Hopefully they'll discover it and also be able to scrub it out.
     
  2. BFLeigh

    BFLeigh Corporal

    Ad-Aware: Nothing

    Spybot: Nothing

    Defender: Still going

    I'll be sure to run Bitdefender and Panda as well but I thought I'd also report this: AVG Resident Shield has found a virus on my computer.

    Trojan horse PSW.Generic2.AOK was found 'while opening file' C:\System Volume Information\_restore{2329625C-C872-4651-B064-B709891ACC07}\RP460\A0057014.exe

    Should I make a new thread for this?
     
  3. BFLeigh

    BFLeigh Corporal

    Bitdefender failed to update the virus definitions, told me it would not be able to do a complete scan and then asked if I wanted to go ahead with it or not, I said no and then scanned with Panda. That scan's findings are attached below. I've still got the AVG Resident Shield pop-up showing the trojan and I can either Ignore, get Info (though it can't find any in the encyclopaedia), Move to Vault (I then get the message that the "Requested action is not available for this object. Access to the file has been denied".) and Enable Access. There's no option to heal the file or delete the file. Should I go ignore or Enable Access?
     

    Attached Files:

  4. BFLeigh

    BFLeigh Corporal

    Update: Defender found nothing,
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Was your only problem the item found in System Restore? Or are you still you still having detetctions by PestScan?

    Is PestScan a paid version of a free version?

    Complete step 7 of the READ & RUN ME and attach a HijackThis log.
     
  6. BFLeigh

    BFLeigh Corporal

    PestScan is the free version, it is still detecting that same thing.

    I've run AVG and it finds nothing, and the AVG Resident Shield isn't telling me about the trojan anymore. I'm unsure what to do as no site seems to have info on this particular trojan.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  8. BFLeigh

    BFLeigh Corporal

    I've unchecked the boxes that ask me if I want to save passwords and I've cleared the form and password histories.

    I'm still having trouble loading Bitdefender's virus updates (via their online scanner), all the other scans have turned up nothing bar PestPatrol.
     
  9. BFLeigh

    BFLeigh Corporal

    Speaking of PestPatrol, I've just run it again and it's found another example of Infostealer/psw.generic2.aok

    Trojan "InfoStealer" found in:
    Key "hkey_current_user \software\microsoft\internet explorer\main" value "formsuggest passwords"
    Key "hkey_current_user \software\microsoft\internet explorer\main" value "formsuggest pw ask
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Perhaps the change of the option to autocomplete forms is not actually removing the entries. I think this happen sometime because when you make a change to the option, the Apply button does not become active and the change is not make. I'll give you something to try, but first I repeat! This is not malware. It is a setting that you have chosen for Internet Explorer. As soon as anyway responds to a prompt about autocompleting for with yes, or if in IE you click Tools, Internet Options, Content, AutoComplete and put a check mark in the Forms box, those two regisry keys will show up.

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    You said Pest Patrol was a free trial version.....uninstall it. It is of no use unless you buy it and it is wrong anyway.
     
    Last edited: Jun 18, 2006
  11. BFLeigh

    BFLeigh Corporal

    Done and done.

    It is weird that AVG Resident Shield no longer tells me about it either, I was actually a little excited as that's the first virus that AVG has found for me, before then I've always been clean and I was then able to see what AVG could really do for me. Should I do anything with System Restore while I'm at it, because that's supposedly where it was located?

    I'll keep an eye out for any more suspicious behaviour, as always sincere thanks to you chaslang.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I repeat! It was not a trojan or virus. There is nothing to do. All we did is set the registry key entries back to system defaults.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds