Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: Trojan:Win32/Comroki!rts


02 Jul 2011   #1

Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
 
 
Trojan:Win32/Comroki!rts

Downloaded and ran the Microsoft Safety Scanner and it found this.
Trojan:Win32/Comroki!rts
Safety Scanner removed so it says.

All I found with Google besides sales pitches to buy things is this at MS.
Encyclopedia entry: Trojan:Win32/Comroki - Learn more about malware - Microsoft Malware Protection Center

Basically no info.

Malwarebytes missed it on scan before the MS Safety Scanner and Avast let it in.
Ran Avast after Safety Scanner and nothing else found.
That makes me feel warm and fuzzy since neither caught it the first time.

Anything else I need to run for removal?

One of our security people around tonight?


My System SpecsSystem Spec
.

02 Jul 2011   #2

Microsoft Community Contributor Award Recipient

Windows 7 Ult. x64 Windows 8.1 x64
 
 

Hey,

Run a scan with Malwarebytes FREE if you haven't already mate.

Some info from ThreatExpert : http://www.threatexpert.com/report.a...24beeec4b10e79

Regards,
Golden
My System SpecsSystem Spec
02 Jul 2011   #3

Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
 
 

Golden

I did that first and it missed it. I can rerun just to be safe.

I wanted to make sure that it was that easy to remove or is it one of the stubborn pain in the ... to remove ones.
My System SpecsSystem Spec
.


02 Jul 2011   #4

Microsoft Community Contributor Award Recipient

Windows 7 Ult. x64 Windows 8.1 x64
 
 

Mmm OK....yep I missed the bit where you said that (doh). Have you tried the ESET on-line scan?
My System SpecsSystem Spec
02 Jul 2011   #5

Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
 
 

No like I said the Microsoft Safety Scanner says it was removed.

I have the online ESET so I will update and run it to be sure.

I answered your VM.

If it made all those registry changes that Threatexpert reported I may have a mess.
My System SpecsSystem Spec
02 Jul 2011   #6

Microsoft Community Contributor Award Recipient

Windows 7 Ult. x64 Windows 8.1 x64
 
 

Hop : if its cleaned out thats good, but we need to make sure its not a backdoor variant - I'm not sure how to tell that. We need Jacee or Corinne to give this the once over.

Let us know how you get on mate,
Golden
My System SpecsSystem Spec
02 Jul 2011   #7

Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
 
 

ESET on line scanner shows clean.
My System SpecsSystem Spec
03 Jul 2011   #8

Microsoft Community Contributor Award Recipient

Windows 7 Home Premium x64 SP1
 
 

Trojan.Win32.Pasta [Ikarus] is also known as:

Trojan:Win32/Comroki [Microsoft]

Trojan.Win32.Pasta [Ikarus] is known to be created as:
%ProgramFiles%\ainmet\rainmeter.exe
%ProgramFiles%\complus applications\vwxzceh.exe
%ProgramFiles%\freevpn\freevpn.exe
%ProgramFiles%\internet explorer\svuwyxzd.exe
%ProgramFiles%\microsoft frontpage\oqsrt.exe
%ProgramFiles%\movie maker\utvxw.exe
%ProgramFiles%\movie maker\wybzc.exe
%ProgramFiles%\movie maker\yfhonsr.exe
%ProgramFiles%\msn gaming zone\ilkmonpo.exe
%ProgramFiles%\web publish\gihkmlnp.exe
%ProgramFiles%\windows nt\xhkjln.exe
%ProgramFiles%\winpcap\jltsv.exe
%ProgramFiles%\winpcap\oqprtqpr.exe
%ProgramFiles%\xerox\gikjn.exe
%System%\msnwshoot.exe
%System%\mstooltaskbar.exe
%Temp%\137626.exe
%Windir%\smss.exe

If you find any of these entries, upload them to Virus Total. A Guy
My System SpecsSystem Spec
03 Jul 2011   #9

Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
 
 

Win Defender, ESET on line scanner, Avast and Mbam clean.

The only scanner that found something was MS Safety Scanner.
My System SpecsSystem Spec
03 Jul 2011   #10
Microsoft MVP

Windows 7 Ultimate 32bit SP1
 
 

Download DDS from one of these links:
Mirror 1 Mirror 2 Mirror 3
  • Disable any script blocking protection
  • Right click the dds icon to run the tool as Administrator
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt <--- will be minimized in the task tray
  • Save both reports to your desktop.
Include the contents of both logs in your next post.
My System SpecsSystem Spec
Reply

 Trojan:Win32/Comroki!rts




Thread Tools



Similar help and support threads for2: Trojan:Win32/Comroki!rts
Thread Forum
Trojan.Win32.Jorik.Midhos.axf System Security
Trojan:Win32/FakeSysdef System Security
Win32/fynlovski.aa trojan problem System Security
Totally lost - win32/olmarik.ajl trojan System Security
Win32/Lethic is a trojan Security News
trojan downloader:win32/cutwail.ba HELP! System Security
Trojan-Downloader.Win32.VB.bbl System Security

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd

All times are GMT -5. The time now is 12:28 PM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33