Forum     

Go Back   Digit Technology Discussion Forum > Portables, Peripherals and Electronics > QnA (read only)
Register FAQ Calendar Mark Forums Read

QnA (read only) Mods please help transfer the contents of this forum to proper sections. :)


 
 
LinkBack Thread Tools Search this Thread Display Modes
Old 09-08-2008, 01:23 PM   #1 (permalink)
In The Zone
 
Sridhar_Rao's Avatar
 
Join Date: Feb 2007
Posts: 353
Default Tojan or Malware?? Help !!


Hello,
When i inserted a flash drive, the avast AV detected
VBS:Malware-gen in autorun.inf. Every attempt to delete repair and
move to chest failed. I disabled autorun feature on all drives using microsoft
TWEAK UI. Finally I used an untested application flash disinfector,
which solved the problem but left its own autorun folder on all
drives.

Whenever I try to connect to net the comodo firewall detects
an application C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\spoolsv.exe
trying to modify the memory of internet explorer and connecting to
some remote location. I am sure there is a trojan. Complete scan
(including boot time) using avast, spybot S&D, Avast adaware, windows
malicious software removal tool, rootkit revealer (all updated
versions) failed to detect anything. There are entries of spoolsv.exe
in registry too. This file exists in recycler too. What is this file doing in recycler and trying to connect internet. Should I delete all
entries in registry? what should i do now?

Any useful help is welcomed.
__________________
Want to study M.Sc in any medical subjects? Read this www.microrao.com/msc.htm
Microx, a diagnostic microbiology laboratory software application www.labmicrox.com
Sridhar_Rao is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 09-08-2008, 01:38 PM   #2 (permalink)
In The Zone
 
pirates1323's Avatar
 
Join Date: Feb 2005
Location: NOiDA
Posts: 282
Default Re: Tojan or Malware?? Help !!

hmm.. first of all Google is your friend ..

Download Spyware doctor .. and scan your pc(COMPLETE SCAN) with it... and remove spywares if found any...

Go to Start> RUn .. type msconfig.. and then go to startup tab .. check for any suspicious application trying to run at startup.. uncheck it ..

I suggest you Kaspersky Internet Security..

Download CCleaner .. clean all your temp files and also scan for registry errors..

Format your flash drive in safe mode... in FAT32 ... then again format in NTFS... try all the options in format ....
pirates1323 is offline  
Old 11-08-2008, 09:37 PM   #3 (permalink)
In The Zone
 
Sridhar_Rao's Avatar
 
Join Date: Feb 2007
Posts: 353
Default Re: Tojan or Malware?? Help !!

Thanks for the post. Since I had so many precautions in place, I always thought my system is immune to any attack. It is now practically evident that no anti-spyware can fully detect all malware/spyware out there. The infected file was there in the recycler folder, none of them detected any problem in that file. It wasn't until I installed trial version of Ashampoo Antispyware 2 guard that the presence of a trojan was officially revealed. The negative aspect of this software is that it does not scan files at boot like avast so removing a file after booting becomes difficult. I restarted in safe mode with command prompt and deleted spoolsv.exe residing in the cycler.
I feel sad that presence of avast, adaware, microsoft malicious software removal tool, all failed to detect the trojan despite being update almost every other day.
I have run full system scan using Ashampoo antispyware guard and have not found anything suspicious. Does it mean there are no harmful files lurking around in my computer. I now use on-screen keyboard to type passwords.
__________________
Want to study M.Sc in any medical subjects? Read this www.microrao.com/msc.htm
Microx, a diagnostic microbiology laboratory software application www.labmicrox.com
Sridhar_Rao is offline  
Old 11-08-2008, 09:41 PM   #4 (permalink)
TechTin.com
 
ravi_9793's Avatar
 
Join Date: Jun 2005
Location: www.TechTin.com
Posts: 4,090
Default Re: Tojan or Malware?? Help !!

This may help you.
How To Do Effective System Scanning
ravi_9793 is offline  
Old 11-08-2008, 09:46 PM   #5 (permalink)
Wandering In Tecno Land
 
Ecko's Avatar
 
Join Date: Feb 2005
Location: 127.0.0.1
Posts: 724
Default Re: Tojan or Malware?? Help !!

Install Avast from then on installation time only it will ask for a boot time scan & check yes for it
On next boot it will scan for virus & press Key 2 (Numeric) from your keyboard
You're done with trojan/virus

Now comes the registry part which you may disinfect using above posts Spyware Doctor or using Spybot Search & Destroy since Spyware Doctor is paid software

Other anytispyware dat can be used Spyware Terminator

Happy Disinfection
__________________
Born in Windows Die In Linux © 2009-10 All Rights Reserved.
Learn Linux : www.linoob.com (Official WebSite)
Ecko is offline  
Old 11-08-2008, 09:51 PM   #6 (permalink)
In The Zone
 
Sridhar_Rao's Avatar
 
Join Date: Feb 2007
Posts: 353
Default Re: Tojan or Malware?? Help !!

There are so many free antivirus, obviously not a single out of them can effectively block or find all malwares/viruses/trojans/ etc. How about a combination of them? Using more than one antivirus on a system is NOT ADVISABLE and may cause COMPATIBILITY issues.
I am using avast antivirus and it runs in the background all the time. Can I additionally install any one among these: AVG Antivirus, AntiVir Personal Edition, BitDefender Free Edition, McAfee® VirusScan Plus - Special edition from AOL without having them run in the background? So that I can their scan functions only when I require. Is this possible?
__________________
Want to study M.Sc in any medical subjects? Read this www.microrao.com/msc.htm
Microx, a diagnostic microbiology laboratory software application www.labmicrox.com
Sridhar_Rao is offline  
Old 15-08-2008, 11:26 AM   #7 (permalink)
In The Zone
 
Sridhar_Rao's Avatar
 
Join Date: Feb 2007
Posts: 353
Default Re: Tojan or Malware?? Help !!

There has been no reply since 4 days to my query.

Here is the update to my problem:
Lavasoft adaware, Avast antivirus, Spybot S&D, microsoft windows defender, microsoft malicious software removal tool, all of which are updated regularly have failed to detect any virus/malware/trojan etc. After obtaining free key for Ashampoo antispyware 2 guard, I updated the definitions and scanned the system.

Here is what I found:

Date & Time Infection/threat found Infection location

15.08.2008 02:36:42 Trojan-Dropper.Win32.Agent.rvv C: \ System Volume Information \ _restore{202550A8-7A33-4BCA-9586-051D24DDBF8F} \ RP444 \ A0130672.exe
15.08.2008 02:35:34 Trojan-DDoS.Win32.Agent.bs C: \ System Volume Information \ _restore{202550A8-7A33-4BCA-9586-051D24DDBF8F} \ RP436 \ A0129687.exe
15.08.2008 02:05:54 Worm.Win32.AutoRun.efq C: \ Program Files \ Alwil Software \ Avast4 \ DATA \ moved \ autorun.inf.vir
15.08.2008 00:45:53 Trojan-Dropper.Win32.Agent.rvv C: \ WINDOWS \ RegisteredPackages \ {3FDF25EE-E592-4495-8391-6E9C504DAC2B}$BACKUP$ \ System \ setup_wm.exe
11.08.2008 01:47:07 Trojan-DDoS.Win32.Agent.bs C: \ RECYCLER \ S-1-5-21-1482476501-1644491937-682003330-1013 \ spoolsv.exe
11.08.2008 01:01:14 Trojan-DDoS.Win32.Agent.bs C: \ RECYCLER \ S-1-5-21-1482476501-1644491937-682003330-1013 \ spoolsv.exe
11.08.2008 00:56:18 Trojan-DDoS.Win32.Agent.bs C: \ RECYCLER \ S-1-5-21-1482476501-1644491937-682003330-1013 \ spoolsv.exe
11.08.2008 00:54:36 Trojan-DDoS.Win32.Agent.bs C: \ RECYCLER \ S-1-5-21-1482476501-1644491937-682003330-1013 \ spoolsv.exe
11.08.2008 00:28:27 Trojan-DDoS.Win32.Agent.bs C: \ RECYCLER \ S-1-5-21-1482476501-1644491937-682003330-1013 \ spoolsv.exe
11.08.2008 00:26:06 Trojan-DDoS.Win32.Agent.bs C: \ RECYCLER \ S-1-5-21-1482476501-1644491937-682003330-1013 \ spoolsv.exe
11.08.2008 00:21:59 Trojan-DDoS.Win32.Agent.bs C: \ RECYCLER \ S-1-5-21-1482476501-1644491937-682003330-1013 \ spoolsv.exe
10.08.2008 21:40:29 Trace.Registry.AdClicker Key: HKEY_USERS \ S-1-5-21-619038027-3559541245-3755859725-1006 \ software \ install

Even the system restore has been affected. An infection was present in Avast folder too.

This sums up that Lavasoft adaware, Avast antivirus, Spybot S&D, microsoft windows defender, microsoft malicious software removal tool have all miserably failed in protecting my computer despite keeping them updated.

I now want to install bitdefender in addition to these existing softwares. Will its installation cause any conflicts, please reply based on your own experience.
__________________
Want to study M.Sc in any medical subjects? Read this www.microrao.com/msc.htm
Microx, a diagnostic microbiology laboratory software application www.labmicrox.com
Sridhar_Rao is offline  
 

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Orkut malware? sakumar79 Internet & WWW 2 20-02-2008 09:52 PM
One in Six PCs Could Be Infected With Malware ax3 Random News 10 17-11-2007 04:39 PM
Best malware scanner??? Liggy Software Q&A 12 12-06-2007 02:54 AM
Expect New malware attacks ... soon !!! anandk Technology News 1 22-12-2006 09:22 AM
Disinfecting Malware readermaniax Tutorials 2 06-11-2005 11:56 PM

 
Latest Threads
- by abhidev
- by clinton

Advertisement




All times are GMT +5.5. The time now is 06:19 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2