Mysterious Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by flankadank, Jun 15, 2006.

  1. flankadank

    flankadank Private First Class

    My spysweeper program detected a trace of the massaker trojan on my system last night and quarantined it. I run Spysweeper every night and the trojan was not detected the night before. This is my home computer and I have it turned off during the night and most of the day while I'm at work. I turn it on when I'm going to use it and usually lock it (windows+l) if I'm away from the computer for long.

    I checked the registry and couldn't find anything unusual in windows/current version/run or run services.

    I run my computer on a limited account and use Firefox browser, but still have IE set to high security. I also have Zone Alarm, PC Cillin (which I'm surprised didn't catch this), Spybot w/teatimer running, and Windows defender.

    I hadn't noticed any problems with my computer. This was only detected on a routine scan with Spysweeper.

    After the quarantine, I re-scanned with Spysweeper and scanned with PC Cillin; both came up clean.

    The strange thing is that Spysweeper's site says this trojan is generally spread through email attachments, but the only email account I check on this computer is hotmail, which scans for viruses, and I won't open email from someone I don't know and don't open attachments that I'm not 100% sure about and I rarely receive attachments from anyone I know. The file that Spysweeper said was infected is easyoffice\pop.wav. Easy Office is a program that I've had installed for at least a year.

    The thing I'm worried about and really want advice about is the recommendation that Spysweeper's site gives to consider changing your bank account and credit card numbers (if you bank online, which I do) and all passwords. They also recommend checking your credit report regularly in the near future, which I will do, since I work for an organization that handles consumer fraud and I understand all about identity theft. Changing my bank account numbers and credit card numbers would be a great inconvenience that I will do if necessary, but I'm not sure whether my case warrants it. I did not visit my bank website since my last clean Spysweeper scan and don't have Firefox save ANY passwords. I have Firefox automatically clear out history, cookies, cache, etc. every time I close it and I have all files on my computer with passwords, personal info. or other sensitive data encrypted.

    Does anyone have any idea how I may have picked up this bug, how much damage it could have done on a limited account and an opinion on the bank account issue?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right now it sounds like it could be a false positive. However for your own piece of mind, you should check with banks and credit card companies for any illegal activity.

    It also sounds to me like you are using too many realtime blocking tools. Running SpySweeper, Spybot's Teatimer, Windows Defender (and do you also have Trend Micro's Antispyware tool installed) is going to slow your PC down, cause potential conflicts between each application which could make it more difficult for any of them to find or fix problems, and could just make it extremely difficult for you since they all will get in the way when doing any manual cleaning.


    At any rate, if you want to make sure your PC is clean, you can follow the procedures below (but still check with your financial institutions).
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
  3. flankadank

    flankadank Private First Class

    I had a suspicion it might be a false positive, but don't want to take any chances with something that potentially serious.

    I will be keeping a close eye on all of my financial accounts, believe me.

    How many real time blockers do you recommend that I keep? I would like to keep Spysweeper, other than that which do you recommend that I keep running? Should I keep the main programs installed, so I can still do manual or scheduled scans (for the ones I end up disabling real-time blocking on)?

    Should I disable those before or after I follow your recommended steps?

    I will wait for your response before proceeding.
     
  4. flankadank

    flankadank Private First Class

    Actually, I just noticed that the scanning in you recommended steps is done in safe mode, so I won't worry about waiting to hear from you to start, but I still would like your opinion on the real-time blockers. I will be back later with my HJT log.
     
  5. flankadank

    flankadank Private First Class

    Ok, I've finished all of the recommended steps. None of the scanners found anything, except Panda, which found 2 cookies. I deleted them via the browser and re-scanned with Panda. The second scan was clean.

    I'm attaching that log and the HJT log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Sun Java version is old and must be updated!

    Did you install this iGive stuff? As far as I know, it is malware. See: http://virusinfo.prevx.com/viruscenter.asp?GRP=1760400013
    O8 - Extra context menu item: iGive Shopping Window - file://C:\Program Files\iGive_Shopping_Window\iGivesShoppingWindow\iGivetShoppingWindow\igivC0.htm
    O9 - Extra button: iGive Shopping Window - {9B7E79AC-A646-4e45-A70F-1B3981FE370E} - file://C:\Program Files\iGive_Shopping_Window\iGivesShoppingWindow\iGivetShoppingWindow\igivC0.htm (HKCU)

    You log is clean other than that.

    You have the below real time antispyware blocking tools installed and running:
    Spy Sweeper
    Ad-Aware SE Plus Ad-Watch
    SpyBot's TeaTimer
    Microsoft AntiSpyware

    Here is what I recommend:
    1) Keep Spy Sweeper because it is the best. But make sure you keep it current and pay for yearly subscription. If it is out of date it will not be that valuable just like any other program of this type.

    2) Disable Ad-Aware's Ad-watch feature but keep Ad-Aware installed only for a backup scanner

    3) Disable Spybot's Teatimer but keep Spybot installed for a backup scanner and also use it's Immunize feature for protection.

    4) Uninstall MicrosoftAntispyware which is no longer supported anyway. It has been replace by Windows Defender but you do not want this installed if you have Spy Sweeper.
     
  7. flankadank

    flankadank Private First Class

    I will follow your advice as far as my scanners/real-time blockers. I did actually install the igive window. Igive is a site that has agreement with large online retailers, so they will donate portions of your purchase to your favorite cause. I may uninstall it anyway, though, since I haven't been able to get it to work.

    Thank you so much for your help. You all have the biggest hearts to spend time helping people like me.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Are you having any other malware problems I can help you with? If not then you should work thru the below:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds