Trojan constantly trying to get into my system

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by moondragon1, Jun 30, 2011.

  1. moondragon1

    moondragon1 Private E-2

    I have Norton IS (Internet Security) and have used it since I got my current laptop. I've never had a problem and it's always been good to me. Recently it's been stopping a Trojan.Adclicker almost every 20 minutes from getting in. Norton says it's located at C:\Windows\assembly\tmp\U\800000cb.@ after going to Windows\assembly and finding no tmp file (it's not hidden either) I can only assume there must be something else making it and trying to self download this trojan. I'm not infected (to my knowledge at least) and have followed the steps outlined in this forum minus using ComboFix. I didn't run ComboFix because currently Norton is stopping this thing from infecting my computer so I don't want to disable it.

    Below are the log files for SAS, Malware Bytes and MGtools. I'm running a 64-bit Windows Ultimate laptop with Norton IS 2011. Everything is updated (minus the language files that you can get for Windows Ultimate) and backed up. If need be I can reset to factory defaults but I'd like to avoid that if I can.

    If there's anything else you'd like me to run I can do so. Thanks in advance for any help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware in your logs, but you are allowing BitTorrent to run at start up, which opens your system to everyone. You should only run it when you are using it and stop it afterwards. It may be why you are seeing these intrusions.
     
  3. moondragon1

    moondragon1 Private E-2

    I usually never have it on and I haven't used at any point while these intrusions have been starting to occur. It's not running in the background or anything so it's not the problem. Thanks for the reply though.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not according to your logs:
    O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files (x86)\DNA\btdna.exe"

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "BitTorrent DNA"="\"C:\\Program Files (x86)\\DNA\\btdna.exe\""
     
  5. moondragon1

    moondragon1 Private E-2

    Strange. Either way I've removed it now so it shouldn't be a problem. Still getting the pop ups (a little less but still there). Any ideas or should I run something else? Thanks again.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What kind of pop ups are you getting? Is it in all browsers? Have you installed any browser add ons such as a pop up blocker?
     
  7. moondragon1

    moondragon1 Private E-2

    I'm getting Norton constantly popping up saying that it's blocking a Trojan.Adclicker.

    Another problem I've noticed is sometimes when I click on google it's now redirecting me to some odd sites but when I refresh the page it works fine. I followed the instructions in the redirect solutions thread but it still does it.
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  9. moondragon1

    moondragon1 Private E-2

    I actually ran that a little earlier. I'm going through the list again of the programs to run but it'll take a while to get through all of them again.

    Here's the log from that program.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  11. moondragon1

    moondragon1 Private E-2

    Found 3 infections. Just got back from work so I won't be testing it tonight but hopefully that'll fix it. Thanks for your help so far.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me know how things are running.


    Note: Those were false detections.
     
    Last edited by a moderator: Jul 2, 2011
  13. moondragon1

    moondragon1 Private E-2

    Something that was done corrupted my startup so I just reset the computer, I already had everything backed up so I didn't have an issue.

    Thanks anyway for the help.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds