trojan on mem stick keeps reappearing

Discussion in 'Malware Help (A Specialist Will Reply)' started by syheidi, Apr 17, 2011.

  1. syheidi

    syheidi Private E-2

    Went through your READ ME FIRST procedure but no where did I find anything regarding mem sticks which is where AVIRA says there is a trojan (awb.3ryk.exe) which keeps reappearing. I believe nothing was found on the PC itself but am including the logs in case I'm wrong. There was something else found as well but it has not reappeared.

    The computer has been slower and slower and I often get "application is not responding" messages. I got one regarding SuperAntiSpyware AFTER all the scans.
     

    Attached Files:

  2. syheidi

    syheidi Private E-2

    last log.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the Avira log so we can see what it is complaining about. Or give me the exact path to the file.

    For the external Hard Drive and a USB stick.

    Insert your flash drive before you begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

    Please have all your removable storage devices ready for disinfection.

    Download Flash Disinfector by sUBs and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it.
    * Your desktop and icons may disappear. This is normal.
    * It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
    * Follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * There will be no GUI interface or log file produced.
    * Reboot your computer when done.

    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.
     
    Last edited: Apr 17, 2011
  4. syheidi

    syheidi Private E-2

    Will do, thanks much. Still wondering about the 'application not responding' so frequently. I assume you only need the most recent avira report.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your best bet is probably to reformat your thumb drive. Are you plugging it into any other systems? That would probably be the only way it is reappearing once Avira removes it.
     
  6. syheidi

    syheidi Private E-2

    Negative. It was used in other machines twice but the virus has reappeared after quarantine without further exposure.
    You recommended flash disinfect - but now recommend reformatting.
    1. The log makes you think flash disinfect won't be sufficient?
    2. Can I back up the flash drive without backing up the virus?
    3. Would you like earlier logs from Avira?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I suggest it only if Avira is not removing it. If it keeps reappearing, the best bet would be to format the drive.
    I think you can safely do that. Just be sure Avira is up to date and all your other AV and AS software is also up to date.
    Not necessary. I just need to know if it keeps reappearing. Did you run the Flash disinfector?
     
  8. syheidi

    syheidi Private E-2

    I used flash disinfect. Later checked flash with Avira which found nothing. So I think that problem is solved.

    Also cleaned registry and checked if disc was fragmented, it wasn't.
    Also followed advice regarding disabling services and cleaning launch tray.

    But the computer keeps running slower the more I try to fix it. And I'm getting the "Application Not Responding" more and more often. :(
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. This is not a malware issue. I suggest you post in the software forum for help with those issues.


    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  10. syheidi

    syheidi Private E-2

    Really appreciate the 'stand down' instructions. Thanks much for all the help.:)
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Good luck and safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds