Trojan.Win32.FTP

Discussion in 'Malware Help (A Specialist Will Reply)' started by grgsmth2006, Mar 5, 2006.

  1. grgsmth2006

    grgsmth2006 Private E-2

    i did a scan with my Yahoo Anti-spy (on yahoo toolbar) and it says that i got a Trojan.Win32.FTP i have tried to remove it but i havent been able to. i've tried to scan it with Windows Defender and my norton-antivirus but the dont read the trojan. Can anyone help me remove this trojan Trojan.Win32.FTP
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    • Bitdefender
    • Panda Scan
    • HijackThis
    .
     
  3. grgsmth2006

    grgsmth2006 Private E-2

    ok i will, but give me a sec.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It will take a lot longer than a second! Do not post a HijackThis log without running all the steps in the READ & RUN ME.
     
  5. grgsmth2006

    grgsmth2006 Private E-2

    I Had Already tried to scan and remove this trojan many times with diffrent programs.. i used HijackThis to get a log and see if u can help me like this.

    Edit by chaslang: Inline log removed. Improperly installed HJT. No cleaning instructions followed
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read message # 2 & # 4 again!!!!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    NOTE:

    Yahoo is more than likely giving you a false positive detection on the below which is not Trojan.Win32.FTP
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
     
  8. grgsmth2006

    grgsmth2006 Private E-2

    what does that mean.?? when i start up my computer a "common folder pops up"

    oh yeah i downloaded all the programs and i was going to boot my system into safe mode.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What does what mean?

    What is a common folder? Do you mean that Windows Explorer opens up your system32 folder?
     
  10. grgsmth2006

    grgsmth2006 Private E-2

    no it opens a this folder C:\Program Files\Common
     
  11. grgsmth2006

    grgsmth2006 Private E-2

    im not sure if i got rid of the trojan, but just to be sure, here are the logs from the online scans and my hijackthis log ..help me plz
     

    Attached Files:

  12. grgsmth2006

    grgsmth2006 Private E-2

    can anyone help me noe? i put the scan reports up and my hijack this log up
     
  13. grgsmth2006

    grgsmth2006 Private E-2

    anyone???
     
  14. grgsmth2006

    grgsmth2006 Private E-2


    what does this mean??????? plz help this thing is driving me crazyyy
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Quite simply it means that Yahoo is wrong!!

    False positive is a term used to describe a situation where any malware scanner detects something to be bad when it is not. It means they did not use the proper methods in their program to actually truly detect the malware. In many instances they just blindly look at the name of a file and decide that it is bad because of the name.

    Read this: http://www.liutilities.com/products/wintaskspro/processlibrary/Remind_XP/
     
  16. grgsmth2006

    grgsmth2006 Private E-2

    o i c. so this isnt really a big problem..rite
    but y does Windows Explorer Open up that Common folder? C:\Program Files\Common when i start up my computer
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure it is opening to that folder? Or is it opening to the c:\windows\system32 folder. If system32, this is a typical problem that occurs on many system when their is a corrupted registry entry in startups (which is would not be a malware problem).
     
  18. grgsmth2006

    grgsmth2006 Private E-2

    i am positive it opens that common folder
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please run the steps in Using GetRunKey and attach the runkeys.txt log.

    Do you know what the below process is supposed to be doing at startup? Is it really something from HP?
    O4 - HKLM\..\RunOnce: [regcmdcons] c:\windows\regedit.exe /s c:\hp\bin\cmdcons2.reg
     
  20. grgsmth2006

    grgsmth2006 Private E-2

    here you go . and i do not know what the proccess is suppose to be doing at start-up.and i dont know if its from HP
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Locate the cmdcons2.reg file and put it into a ZIP file and attach it to your next message.
     
  22. grgsmth2006

    grgsmth2006 Private E-2

    im kinda confused on how to do that..
     
  23. grgsmth2006

    grgsmth2006 Private E-2

    how do i put it into a ZIP file??
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have WinZIP installed on your PC?

    If so, just right click on the file and select Add to ZIP.
     
  25. grgsmth2006

    grgsmth2006 Private E-2


    i dont have WinZip
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What did you use to extract HijackThis.exe from the ZIP file?
     
  27. grgsmth2006

    grgsmth2006 Private E-2

    i just right clicked it and pushed Unzip. and then it brought up this wizard and it tells me where i want to unzip the folder to. but when i tried to put that thing u told me in a zipped folder i couldnt
     
  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you just used the extractor built into to Windows XP.

    Make a copy of the file in another folder. Then right click on the file and select Rename. Rename it to cmdcons2.txt

    Then attach the cmdcons2.txt file to a message!
     
  29. grgsmth2006

    grgsmth2006 Private E-2

    this is what it would be


    REGEDIT4

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "regcmdcons"="c:\\hp\\bin\\cloaker.exe c:\\hp\\bin\\cmdcons.cmd"
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It seems to me that you jsut have a few startup programs that are not properly quoted in the registry. This is not a malware problem. You may want to discuss it in the Software Forum. But based on your HJT log the below items look to be missing quotes.

    O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"

    There should be quotes as given below in bold red color.

    O4 - HKLM\..\Run: [SSC_UserPrompt] "c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
    O4 - HKLM\..\Run: [IS CfgWiz] "c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe" /GUID NIS /CMDLINE "REBOOT"

    You will need to edit the registry to add these quotes or correct where they are located.
    Or you have something application missing in from an expected location.

    You can see info about that in links like below:

    http://www.techimo.com/forum/archive/index.php/t-128257.html
    http://www.miclasificado.com.ar/cgi/News/i50/How_to_stop_folder_c_program_files_common_opening_on_startup.php
    http://www.experts-exchange.com/Applications/MultiMedia_Applications/Q_21092755.html
     
  31. grgsmth2006

    grgsmth2006 Private E-2

    ok i put in those quotaion marks. will it help if i delete the "C:\Windows\Creator\Remind_XP.exe" from the regisrty??? . so we have come to the conclusion that ii dont have a trojan on my computer. i just wanna be sure. and is their anything else you can say that will help me with this problem.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Deleting this will not do anything for you other than make Yahoo not complain about somethings they should not be complaining about. But it is not a process you really need, so you can remove the registry entry without it causing you any problems but is will not fix your problem with the C:\Program Files\Common Files folder opening at startup.

    I already told you that in message # 7 when I said it was a false positive.

    Your problem is not malware. It is related to problems with some of those registry keys being incorrectly formatted (with quotes) or corrupted. It is probably one of the items that show in your HJT log in the O4 items that list show C:\Program Files\Common Files

    If you need to discuss this further, you should be able to do that in the Software Forum.
     
  33. grgsmth2006

    grgsmth2006 Private E-2

    well anywyz..thank you guyz for EVERYTHING!!! you guys are a GREAT help!! :)
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds