Solved Trojan, Please HELP!!!

EvilOzzmess

Banned
Local time
1:01 PM
Messages
301
Location
California, US
Well, I’m a little embarrassed to say, I’ve been hit with a rather nasty Trojan. McAfee detected it right away, and I told it to quarantine the junk, and I assumed it had… until IE kept opening with random junk pages I didn’t prompt it to open. :mad:

I therefore, did not write down the name of the malware, or even bookmark the info page that came up about it – as again, I thought McAfee had taken care of it. I remember something about “Auto” and it ending in .CO though, anybody know what the rest of it is or could be?

Anyway, I foolishly neglected to set weekly restore points, and so I cannot roll the system back to said restore points (I assumed that was already set up, but it isn’t). So, with that said how can I get rid of this and also how can I set up these weekly restore points so I don’t ever have to consider factory restoring again because of this problem?

I’m running a free trial of A-Squared right now, but I don’t know if that’s going to take care of it yet or not.

Thanks in advance for any help or information…
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5738PG-6306
OS
7 Ultimate x64 SP1
CPU
Core 2 Duo T6600 @ 2.20GHz
Motherboard
Acer JV50 | Intel PM45 Chipset | BIOS Phoenix v1.21
Memory
4GB SDRAM DDR2 667
Graphics Card(s)
ATI Mobility Radeon 4570HD 512MB VDDR3 (2.25GB HyperMemory)
Sound Card
Integrated Dolby Home Theater HD Audio Support
Monitor(s) Displays
15.6" LED backlight HD/WS CineCrystal w/ Multi-Touch
Screen Resolution
Notebook: 1366x768 | Syncmaster P2370HD: 1920x1080
Hard Drives
Primary internal: 320GB WD3200BEVT-22ZCT0 @ 5400 RPM | Secondary external 1: 2TB Cavalry CAXB3702T0 @7200 RPM (USB 2.0) | Secondary external 2: 500GB Calvary CAUM @7200 RPM (USB 2.0).
PSU
AC Adapter
Case
Blue Clam shell
Cooling
OEM Bult-in.
Keyboard
Microsoft Wireless 3000 (USB)
Mouse
Logitech V220 (USB)
Internet Speed
31Mbps DL/25Mbps UL - Verizon fiOs/Netgear WNDR37AV
Other Info
EXTERNAL DISPLAY: 23" Samsung Syncmaster P2370HD | EXTERNAL SOUND: 300 Watt MX-KB30 JVC Stereo (AUX) | ROUTER: Netgear WNDR37AV 802.11a/b/g/n Dual-Band Gigabit | Satechi 12-Port USB 2.0 Hub | GAME PAD: SteelSeries 3GC USB 2.0 (JoyToKey Mapping) | DETAILED SYSTEM SPECIFICATIONS: http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=5265887&CatId=4938

My Computer

Computer Manufacturer/Model Number
Gateway NV5378u
OS
Windows 7 Ultimate 64-bit
CPU
AMD Athlon II X2 M300
Motherboard
Gateway SJV50TR 0100
Memory
4GB
Graphics Card(s)
AMD M880G with ATI Mobility Radeon HD 4200
Sound Card
Conexant High Definition Audio
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
15.6" 16:9 HD LED LCD
Hard Drives
Hitachi HTS545050B9A300 Disk Device 500GB
Thank you so much! Where McAfee, Microsoft Malicious Remover Tool and A-Squared failed, MBAM took care of it! Again, thank you so, so, so much! You just saved me hours of restores!

I would really like to know how I can set up system restore points to save on the hard disk though, in case this ever happened again and for whatever reason, antivirus removals fail. Any help on that would again, be very much appreciated!

EDIT: I know how to do this manually, but I would like to somehow set it up to do it automatically once a week, at a specific day and time. Thanks again for the help in advance!
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5738PG-6306
OS
7 Ultimate x64 SP1
CPU
Core 2 Duo T6600 @ 2.20GHz
Motherboard
Acer JV50 | Intel PM45 Chipset | BIOS Phoenix v1.21
Memory
4GB SDRAM DDR2 667
Graphics Card(s)
ATI Mobility Radeon 4570HD 512MB VDDR3 (2.25GB HyperMemory)
Sound Card
Integrated Dolby Home Theater HD Audio Support
Monitor(s) Displays
15.6" LED backlight HD/WS CineCrystal w/ Multi-Touch
Screen Resolution
Notebook: 1366x768 | Syncmaster P2370HD: 1920x1080
Hard Drives
Primary internal: 320GB WD3200BEVT-22ZCT0 @ 5400 RPM | Secondary external 1: 2TB Cavalry CAXB3702T0 @7200 RPM (USB 2.0) | Secondary external 2: 500GB Calvary CAUM @7200 RPM (USB 2.0).
PSU
AC Adapter
Case
Blue Clam shell
Cooling
OEM Bult-in.
Keyboard
Microsoft Wireless 3000 (USB)
Mouse
Logitech V220 (USB)
Internet Speed
31Mbps DL/25Mbps UL - Verizon fiOs/Netgear WNDR37AV
Other Info
EXTERNAL DISPLAY: 23" Samsung Syncmaster P2370HD | EXTERNAL SOUND: 300 Watt MX-KB30 JVC Stereo (AUX) | ROUTER: Netgear WNDR37AV 802.11a/b/g/n Dual-Band Gigabit | Satechi 12-Port USB 2.0 Hub | GAME PAD: SteelSeries 3GC USB 2.0 (JoyToKey Mapping) | DETAILED SYSTEM SPECIFICATIONS: http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=5265887&CatId=4938
No problem you can always rep my post... and yea for your antivirus you should consider Microsoft Security Essentials.
 

My Computer

Computer Manufacturer/Model Number
Gateway NV5378u
OS
Windows 7 Ultimate 64-bit
CPU
AMD Athlon II X2 M300
Motherboard
Gateway SJV50TR 0100
Memory
4GB
Graphics Card(s)
AMD M880G with ATI Mobility Radeon HD 4200
Sound Card
Conexant High Definition Audio
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
15.6" 16:9 HD LED LCD
Hard Drives
Hitachi HTS545050B9A300 Disk Device 500GB

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home
Yeah, I was thinking about that too. Ghosting right? I think I would have to partition the External for that... a bit beyond my expertise.


UPDATE: I still have crap on here, actually. I don't know why, but it keeps coming back and I think it's "Zwangi". I'm running a full scan, but I think it won't work either. I don't know. I might have to just wipe everything out and then restore from the disks I made (thank God I did that)! If this doesn't work, should I try it in safemode with networking - before dealing with the pain in the butt that is resorting to factory image?
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5738PG-6306
OS
7 Ultimate x64 SP1
CPU
Core 2 Duo T6600 @ 2.20GHz
Motherboard
Acer JV50 | Intel PM45 Chipset | BIOS Phoenix v1.21
Memory
4GB SDRAM DDR2 667
Graphics Card(s)
ATI Mobility Radeon 4570HD 512MB VDDR3 (2.25GB HyperMemory)
Sound Card
Integrated Dolby Home Theater HD Audio Support
Monitor(s) Displays
15.6" LED backlight HD/WS CineCrystal w/ Multi-Touch
Screen Resolution
Notebook: 1366x768 | Syncmaster P2370HD: 1920x1080
Hard Drives
Primary internal: 320GB WD3200BEVT-22ZCT0 @ 5400 RPM | Secondary external 1: 2TB Cavalry CAXB3702T0 @7200 RPM (USB 2.0) | Secondary external 2: 500GB Calvary CAUM @7200 RPM (USB 2.0).
PSU
AC Adapter
Case
Blue Clam shell
Cooling
OEM Bult-in.
Keyboard
Microsoft Wireless 3000 (USB)
Mouse
Logitech V220 (USB)
Internet Speed
31Mbps DL/25Mbps UL - Verizon fiOs/Netgear WNDR37AV
Other Info
EXTERNAL DISPLAY: 23" Samsung Syncmaster P2370HD | EXTERNAL SOUND: 300 Watt MX-KB30 JVC Stereo (AUX) | ROUTER: Netgear WNDR37AV 802.11a/b/g/n Dual-Band Gigabit | Satechi 12-Port USB 2.0 Hub | GAME PAD: SteelSeries 3GC USB 2.0 (JoyToKey Mapping) | DETAILED SYSTEM SPECIFICATIONS: http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=5265887&CatId=4938
Trying that now... let's hope this works.

And of course, they want my money before getting rid of it.

I give up, I'm broke. I can't pay for it. So... factory image restore it is.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5738PG-6306
OS
7 Ultimate x64 SP1
CPU
Core 2 Duo T6600 @ 2.20GHz
Motherboard
Acer JV50 | Intel PM45 Chipset | BIOS Phoenix v1.21
Memory
4GB SDRAM DDR2 667
Graphics Card(s)
ATI Mobility Radeon 4570HD 512MB VDDR3 (2.25GB HyperMemory)
Sound Card
Integrated Dolby Home Theater HD Audio Support
Monitor(s) Displays
15.6" LED backlight HD/WS CineCrystal w/ Multi-Touch
Screen Resolution
Notebook: 1366x768 | Syncmaster P2370HD: 1920x1080
Hard Drives
Primary internal: 320GB WD3200BEVT-22ZCT0 @ 5400 RPM | Secondary external 1: 2TB Cavalry CAXB3702T0 @7200 RPM (USB 2.0) | Secondary external 2: 500GB Calvary CAUM @7200 RPM (USB 2.0).
PSU
AC Adapter
Case
Blue Clam shell
Cooling
OEM Bult-in.
Keyboard
Microsoft Wireless 3000 (USB)
Mouse
Logitech V220 (USB)
Internet Speed
31Mbps DL/25Mbps UL - Verizon fiOs/Netgear WNDR37AV
Other Info
EXTERNAL DISPLAY: 23" Samsung Syncmaster P2370HD | EXTERNAL SOUND: 300 Watt MX-KB30 JVC Stereo (AUX) | ROUTER: Netgear WNDR37AV 802.11a/b/g/n Dual-Band Gigabit | Satechi 12-Port USB 2.0 Hub | GAME PAD: SteelSeries 3GC USB 2.0 (JoyToKey Mapping) | DETAILED SYSTEM SPECIFICATIONS: http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=5265887&CatId=4938
Thank you so much! Where McAfee, Microsoft Malicious Remover Tool and A-Squared failed, MBAM took care of it! Again, thank you so, so, so much! You just saved me hours of restores!

I would really like to know how I can set up system restore points to save on the hard disk though, in case this ever happened again and for whatever reason, antivirus removals fail. Any help on that would again, be very much appreciated!

EDIT: I know how to do this manually, but I would like to somehow set it up to do it automatically once a week, at a specific day and time. Thanks again for the help in advance!

Hi there
consider a commercial backup product such as Acronis -- thei is quite a popular one and can restore images directly from a bootable USB or DVD.

Macrium is another one -- I haven't used macrium but I gather its highly regarded as well and its free.

After a CLEAN install of your OS you should take an image and use it to restore after any computer infection.

I would NEVER trust a machine again if it had been infected . A complete restore IMO is the only safe solution.

Cheers
jimbo
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom built, several laptops HP/ASUS
OS
Linux CENTOS 7 / various Windows OS'es and servers
CPU
Intel i7 Intel i5
Memory
8GB, 16GB
Graphics Card(s)
On Motherboard
Sound Card
Realtek HD audio
Monitor(s) Displays
Apple Cinema display, Samsung LCD
Screen Resolution
1920 X 1080
Hard Drives
4 X 1TB SATA
Mouse
Toshiba wireless laser
Internet Speed
> 20MB up
even though this is categorized as a low threat, I agree with Jimbo... a clean install!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
LENOVO K450 @3.0GHZ
OS
64-bit Windows 8.1 Pro
CPU
Core(TM) i5 CPU 4330 Haswell @ 3.20GHz
Motherboard
LENOVO
Memory
12.00 GB
Graphics Card(s)
Intel(R) HD Graphics
Sound Card
Intel HD integtrated
Monitor(s) Displays
HP 25' ISP Monitor
Screen Resolution
1900/1020
Hard Drives
(1) ST1000DM003-1CH162 (2) Generic STORAGE DEVICE USB Device (3) Generic STORAGE DEVICE USB Device
Internet Speed
100mb down/10mb up
Trying that now... let's hope this works.

And of course, they want my money before getting rid of it.

.

hitman pro has free cleaning for 30 days....just activate trial license and it will clean for free.....;)
 

Attachments

  • hmp 30 days.PNG
    hmp 30 days.PNG
    7.4 KB · Views: 2

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Macrium

I use Macrium Reflect and I take an image of my machine about once a month, it's quite easy to use and I have had to restore twice in the past after I messed things up, just download from there website, Macrium Reflect FREE Edition - Information and download make a rescue disk and make an image on an external HDD or network drive or a bunch of DVD's. It took about 40 mins to back up and the same to restore a 160gb HDD that was half full.:geek:
 

My Computer

Computer Manufacturer/Model Number
Home built
OS
Windows 7 Enterprise 64bit
CPU
Intel Pentium dual core E2200 2.2ghz
Motherboard
Asrock Wolfdale 1333-d667 r2.0
Memory
4 gb (2 x 2g Kingston DDDR11 800)
Graphics Card(s)
Nvidia Geforce 8400 gs
Sound Card
On board
Monitor(s) Displays
DiFusion 17"
Screen Resolution
1280 x 1024
Hard Drives
1 x 160gb (4 Partitions, Os, pagefile, programs and documents)
1 x 1tb
1 x 320 external
PSU
? one that supplies power
Case
Old, on about the 4th mobo, re-build
Cooling
? some fan on the CPU
Keyboard
Logitech Wave
Mouse
Trust 300 Optical dual scroll
Internet Speed
10mb
Other Info
Advent QT5500 Laptop
Intel T5500 167ghz 2 core
2gb ram
Windows 7 Enterprise 32bit
I use Macrium Reflect and I take an image of my machine about once a month, it's quite easy to use and I have had to restore twice in the past after I messed things up, just download from there website, Macrium Reflect FREE Edition - Information and download make a rescue disk and make an image on an external HDD or network drive or a bunch of DVD's. It took about 40 mins to back up and the same to restore a 160gb HDD that was half full.:geek:

Jo 90 -

I've been thinking of giving this app a try. Which rescue method do you use (linux disk, linux usb, bartPE disk)?

Any tips/pointers in overall use?

THANKS!
 

My Computer

Computer Manufacturer/Model Number
eMachines W3502
OS
7 Ultimate
CPU
Intel® Celeron® D 3.20GHz, 512KB L2 cache, 533MHz FSB
Motherboard
Gateway Grant County
Memory
2 Gb DDR
Graphics Card(s)
Nvidia GeForce 7200
Sound Card
Onboard 6-Channel High-Definition Audio (Realtek)
Monitor(s) Displays
Changes with mood
Screen Resolution
Changes with monitor
Hard Drives
Seagate 250 Gb, 7200 RPM SATA (internal)
PSU
CoolerMaster something or other
Case
Stock
Cooling
Case, CPU and graphics coolers
Keyboard
Saitek Illuminated - USB
Mouse
Dell POS
Internet Speed
Cable
Other Info
Optical: Samsung DVD ROM, Asus CDR/W

Config changes regularly. Won't look like this for long...
I removed the same trojan from a clients computer yesterday. I started it up in safemode with networking. Downloaded and ran Rkill then downloaded and ran Malwarebytes scan, do the full scan as it is much more accurate.

While it is running go and do something else as it can take quite some time.

It found 27 items. I quarantined and then removed all items. I restarted the machine and then deleted restore points see here

http://windows.microsoft.com/en-US/w...-restore-point

This is important as if you go back to a restore point at a later date you might restore this virus.

Run the Malwarebytes scan again (quick this time) and bob's your uncle.
__________________
 

My Computer

Computer Manufacturer/Model Number
Self build
OS
Windows 7 Ultimate x64
CPU
AMD Phenom II x4
Motherboard
Gigabyte 880
Memory
8GB
Graphics Card(s)
NVIDIA GeForce HD
Sound Card
Realtek HD Audio
Screen Resolution
1920 x 1080
Hard Drives
2 x 1TB
PSU
Thermalake 550w
Case
XCase
Internet Speed
8MB
Thanks guys, I chose a full factory restore - so my computer's now exactly back to how Acer shipped it out as (and subsequently was their recommended course of action for persistent, severe malware infestations). Along with five other programs, I tried running MBAM twice, fully - and twice quickly, and it DID detect and remove two Trojans - each time, but it was unable to fully remove whatever caused those two to get in here - so I really had no choice but to completely wipe out the system on this one.

I wouldn't have trusted it if I hadn't, anyway. Just kind of ticked I forgot to save my Firefox bookmarks before doing it... this is why you shouldn't panic and try to do this stuff on an all-nighter whilst half asleep. Ha... >_<


As for backup, I discovered I didn't really need that at all. I DO have a self-made Acer Restore Manager set of disks which did ghost the entire drive, along with drivers and the OS itself. But I find Factory Restore to do the exact same thing, so it's less complicated to just do that and then put everything back as it was before (like I'm doing right now, in fact). No big deal.

Thanks again for all your help guys! Really appreciate it.
 

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5738PG-6306
OS
7 Ultimate x64 SP1
CPU
Core 2 Duo T6600 @ 2.20GHz
Motherboard
Acer JV50 | Intel PM45 Chipset | BIOS Phoenix v1.21
Memory
4GB SDRAM DDR2 667
Graphics Card(s)
ATI Mobility Radeon 4570HD 512MB VDDR3 (2.25GB HyperMemory)
Sound Card
Integrated Dolby Home Theater HD Audio Support
Monitor(s) Displays
15.6" LED backlight HD/WS CineCrystal w/ Multi-Touch
Screen Resolution
Notebook: 1366x768 | Syncmaster P2370HD: 1920x1080
Hard Drives
Primary internal: 320GB WD3200BEVT-22ZCT0 @ 5400 RPM | Secondary external 1: 2TB Cavalry CAXB3702T0 @7200 RPM (USB 2.0) | Secondary external 2: 500GB Calvary CAUM @7200 RPM (USB 2.0).
PSU
AC Adapter
Case
Blue Clam shell
Cooling
OEM Bult-in.
Keyboard
Microsoft Wireless 3000 (USB)
Mouse
Logitech V220 (USB)
Internet Speed
31Mbps DL/25Mbps UL - Verizon fiOs/Netgear WNDR37AV
Other Info
EXTERNAL DISPLAY: 23" Samsung Syncmaster P2370HD | EXTERNAL SOUND: 300 Watt MX-KB30 JVC Stereo (AUX) | ROUTER: Netgear WNDR37AV 802.11a/b/g/n Dual-Band Gigabit | Satechi 12-Port USB 2.0 Hub | GAME PAD: SteelSeries 3GC USB 2.0 (JoyToKey Mapping) | DETAILED SYSTEM SPECIFICATIONS: http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=5265887&CatId=4938
Well good to here your virus problems are over, but for future reference have Microsoft Security Essentials as your antivirus if you cant afford to buy one and Malwarebytes along with it. These are two great programs that will keep you safe :)
 

My Computer

Computer Manufacturer/Model Number
Gateway NV5378u
OS
Windows 7 Ultimate 64-bit
CPU
AMD Athlon II X2 M300
Motherboard
Gateway SJV50TR 0100
Memory
4GB
Graphics Card(s)
AMD M880G with ATI Mobility Radeon HD 4200
Sound Card
Conexant High Definition Audio
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
15.6" 16:9 HD LED LCD
Hard Drives
Hitachi HTS545050B9A300 Disk Device 500GB
No, wait...once again, not sure if it's completely gone. MBAM found "Hijack.DisplayProperties" Registry Data HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges

I don't know how that is even possible, but there it is. What should I do now? I don't see the old Processes that I had with whatever it was last time, that I believe I did just get rid of, but... yeah. It's there, somehow. :mad:


EDIT: I have found winlogon.exe in the processes, and when I checked it out it shows an icon with a WINDOW, WITH A MOON IN THE BACKGROUND. It is NOT capitalized, and it is NOT WINLOGIN.EXE which I know to be the TRUE Windows program type. How do I kill this?
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Acer Aspire 5738PG-6306
OS
7 Ultimate x64 SP1
CPU
Core 2 Duo T6600 @ 2.20GHz
Motherboard
Acer JV50 | Intel PM45 Chipset | BIOS Phoenix v1.21
Memory
4GB SDRAM DDR2 667
Graphics Card(s)
ATI Mobility Radeon 4570HD 512MB VDDR3 (2.25GB HyperMemory)
Sound Card
Integrated Dolby Home Theater HD Audio Support
Monitor(s) Displays
15.6" LED backlight HD/WS CineCrystal w/ Multi-Touch
Screen Resolution
Notebook: 1366x768 | Syncmaster P2370HD: 1920x1080
Hard Drives
Primary internal: 320GB WD3200BEVT-22ZCT0 @ 5400 RPM | Secondary external 1: 2TB Cavalry CAXB3702T0 @7200 RPM (USB 2.0) | Secondary external 2: 500GB Calvary CAUM @7200 RPM (USB 2.0).
PSU
AC Adapter
Case
Blue Clam shell
Cooling
OEM Bult-in.
Keyboard
Microsoft Wireless 3000 (USB)
Mouse
Logitech V220 (USB)
Internet Speed
31Mbps DL/25Mbps UL - Verizon fiOs/Netgear WNDR37AV
Other Info
EXTERNAL DISPLAY: 23" Samsung Syncmaster P2370HD | EXTERNAL SOUND: 300 Watt MX-KB30 JVC Stereo (AUX) | ROUTER: Netgear WNDR37AV 802.11a/b/g/n Dual-Band Gigabit | Satechi 12-Port USB 2.0 Hub | GAME PAD: SteelSeries 3GC USB 2.0 (JoyToKey Mapping) | DETAILED SYSTEM SPECIFICATIONS: http://www.tigerdirect.com/applications/SearchTools/item-details.asp?EdpNo=5265887&CatId=4938
Back
Top