Trojan with Antivuris Software Question

Discussion in 'Malware Help (A Specialist Will Reply)' started by aspen_matthews, Jan 1, 2008.

  1. aspen_matthews

    aspen_matthews Private E-2

    Hi there, I have Norton Antivirus 2008 that I run and update on a regular basis (I've only had it a couple weeks). I recently had a problem with adware/malware and a trojan but finally got everything all cleaned out and taken care of. Tonight on my regular full scan Norton found the regular cookie tracker and also this > c:\windows\system32\appcert\wnl32.dll
    which it said was a Trojan. My question is, how did I get this if I have my Norton security? Also, what kind of Trojan is this? I always get paranoid that I may be compromising passwords or other sensitive info and I'm always scared to use my computer anymore, lol. Help would be very appreciated, thanks!
     
  2. abri

    abri MajorGeek

    Hi aspen_matthews!
    Happy New Year!

    If Norton found a trojan and removed it from it's system, it's doing its job. There is no antivirus or security system available that can detect and remove everything. I got a trojan this week by putting a word into Merriam Websters to look up, so you can get them literally anywhere, and I'm sure Merriam Webster did not know they were spreading a trojan. There are weaknesses in all systems and people who wish to compromise computers will look for all of them.

    If you would like for us to make sure your computer is clean, please follow the instructions in the READ & RUN ME FIRST

    If your system is not showing any signs of malware like sluggishness, pop-ups, unexpected shutdowns, odd things on the desktop, then you may just want to read the
    How to Protect Yourself from Malware

    abri
     
  3. aspen_matthews

    aspen_matthews Private E-2

    Yeah I literally JUST went through a huge process with a very helpful guy at Lavasoft to help cleanup and update my computer so I know that is all taken care of. I just want to make sure I'm doing the right thing to keep my computer as safe as possible. So I don't need to worry about the integrity of my passwords on websites or anything? I'm okay? Thanks so much and I'm glad to hear it's not just me being weird that I get these, haha.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are still seeing the folder you mentioned:

    c:\windows\system32\appcert

    Then you are not clean. Especially if there are files in this folder.
     
  5. aspen_matthews

    aspen_matthews Private E-2

    Yes, I did a search on the computer and that folder is still there and there is one 1kb thing in the folder titled options.dat. What does this do to my computer? And how can I fix it?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that means you are not clean and you need to do what Abri gave you in message 2. Namely this: READ & RUN ME FIRST and you need to try and get in finished as soon as possible before the malware has a chance to possible spread again.
     
  7. aspen_matthews

    aspen_matthews Private E-2

    Okay, will run through the process soon as I get home. Computers can be such a pain, I just finished spending a week working with the hijackthis log guy on Lavasoft forums to get rid of my search-daily.com problem! Thanks for the help, hopefully I can get my computer all cleaned up quickly!
     
  8. aspen_matthews

    aspen_matthews Private E-2

    Okay, here is progress so far:

    Checked through program list and uninstalled Viewpoint Media Player, didn't have anything else on list. I did msconfig and normal mode was already clicked but I went ahead and restarted computer anyways. My Norton Antivirus Quarantine has items listed but they are already all removed, only saved in log. Do I need to delete them from log as well? Also, I have newest Norton and can't find Protected Recycle Bin, am I missing something? Thanks! Don't want to move forward until I make sure I'm taking the right steps!
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!

    We don't know since we don't use Norton. Don't worry about it. Just complete all the remaining instructions.
     
  10. aspen_matthews

    aspen_matthews Private E-2

    Hi there, I finished up all the downloading and scans (combofix, spybot, avg, and mgtools). What do I do now? Do I need to post any .txt files or anything? Thanks
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just do what the READ & RUN ME instructions tell you to do. They said
     
  12. aspen_matthews

    aspen_matthews Private E-2

    Okay, well the original file in question, c:\windows\system32\appcert
    is still there, I have attached the 3 requested reports. thanks
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay you are in pretty good shape other than the AppCert folder. I will also give you a few performance tweaks below and then we will try to remove this folder.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  14. aspen_matthews

    aspen_matthews Private E-2

    here are the new logs and when i search my comp that folder is no longer coming up
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix then UNINSTALL COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN
      • Now type combofix /u in the runbox and click OK.
      • Note: The space between the X and the U, it must be there.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  16. aspen_matthews

    aspen_matthews Private E-2

    Great, I went through that and the How Protect yourself thread. I just have a couple questions. So it looks like I can go ahead and keep Norton as my AV and that I should keep Ccleaner for cookies. Norton also has a firewall so I think that should be okay. As far as antispyware, part of the clean up thread had me download Avg Antispyware trial and also SpyBot search and destroy. Should I keep both of these or do I only need one of them?
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, if you don't mind how it slows your PC down.

    These are not realtime antispyware blocking tools unless you purchase AVG Antispyware or unless you enable Spybot's Teatimer which we recommended against. You need a realtime antispyware blocking tool as stated in that link. If you are not going to purchase AVG Antispyware, you can keep it as a backup scanner. Spybot offers non-realtime protection from the SDhelper and Immunize features and these are using very little system resources. And Spybot is also sitting there ready to be an additional backup scanner which can be helpful.

    What I would recommend uninstalling is Ad-Aware 2007 which is a resource waster even when not running the scanner.

    You should also install and use SpywareBlaster as recommended. It does not use any system resources and adds some great protection features.
     
  18. aspen_matthews

    aspen_matthews Private E-2

    Cool thanks for the tips. Question about realtime antispyware. Are there any that are not massive resource hogs? AVG is taking up a huge chunk of my mem usage right now, 35,700k on avgas.exe and 14,400k on guard.exe (which I understand is part of that program). That with Norton my computer is running at 100% CPU usage all the time right now which is quite frustrating. Any suggestions? Also with Norton, anything I can do to it to make is hog fewer resources? Thanks.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I should have clarified something. AVG Antispyware that you installed when coming here for help is a 15 day full featured trial program that does have realtime blocking during the 15 days. (that's the guard.exe program). After 15 days it is a scanner only. So you can either keep it as your realtime protection until the trial is up and then install another blocker. Or you could just uninstall it now and use for example Comodo BO Clean which i just a blocker and has no scanning function (another reason to have other background scanners).

    Now as far as memory usage. Some use more than others. You have to be very careful here because in reality if you found something that is saying it is a realtime blocker and it uses no resources then it is not a realtime blocker. Also the level of protection can be somewhat proportional to the amount of resources. However some programs just waste resources and do not really give that much greater protection (i.e., Norton).

    What processes are using all of the CPU time? Are scans running? If a scan is currently running, yes CPU usage will be high unless you have options in the scanner to scan at slower rate in the background. Takes much longer but requires fewer resources.

    Point blank answer....yes. Uninstall it!
     
  20. aspen_matthews

    aspen_matthews Private E-2

    That is without any scans running. I do have a game running in the background but it definitely affects my gameplay when I'm playing as well (MMO game).

    bah, after all that money I spent on it, sigh. Which of the AV would you recommend? Then I would also need a firewall as well, right?:tas
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you sure that no scans are running? Are you sure your game is not using excessive CPU time. Look in Task Manager and tell me what processes are using all of the ( or the most) CPU time when you have this issue.

    Also try shutting down AVG Antispyware before playing your game. Any change?

    Did you uninstall Ad-Aware 2007?


    Any of the ones in the link I game you to the How to protect yourself thread. AVG Free is a popular choice.

    Yes. I'm not sure what you had from Symantec even included a firewall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds