What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Closed TopicStart new topic
> [Resolved] trojan on my pc?, trojandownloader win32.renos.io
weemic
post Jun 25 2009, 06:44 AM
Post #1


New Member
*

Group: Authentic Member
Posts: 13
Joined: 25-June 09
Member No.: 86,415
Operating System: windows vista basic home



hello,

i seem to have managed to get a trojan on my pc.
tried a couple of free software programs.
i have downloaded atf cleaner, anit malwarebytes and has antivirus super pro, which i;ve tried to remove, it seem to be giving my grief.
i also have virgin media guard pro.

the virus can cause the pc the hang or restarts itself at any time. i've tried doing scan on normal and safe mode. when doing scan, sometimes it will pick up files to delete, sometime it will say pc is clean and other times while doing the scan it restarts pc.

your help will be very much appreciated.
i have access to internet at my work pc, so this will be where i get most of my time to check back on your updates before i head home. i can access internet but as i said it can hang and restart all over the place.

i will be able to respond quicker between 9am - 4pm uk time.

if you could let me know of what steps to complete first of all that would be ideal.

the trojan in the topic description has definatley shwon up on my machine not sure if there is anything else.
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
CatByte
post Jul 2 2009, 01:31 PM
Post #2


Classroom Administrator
Group Icon

Group: Classroom Admin
Posts: 9,640
Joined: 18-November 04
From: Canada
Member No.: 18,614
Operating System: xp sp3



QUOTE
what you think the best free anti virus + spyward program is


You will get many different opinions on this, but in my opinion Avira AntiVir is the best free program out there.

Many people are annoyed by the "Nag Screen" that pops up once a days after Avira automatically updates it's virus definitions, but I think one click on the close button, once a day is a small price to pay for a most excellent antivirus product.

As for an Anti Spyware product - personally I use Windows Defender along with the stand alone scanner Malwarebytes Antimalware.


The programs can be found here:
(please don't install anything until the computer is completely clean - stay off the internet unless it's to download a tool or perform a scan)

Avira AntiVir Personal

Windows Defender

You already have Malwarebytes, which we are now going to use.

NEXT

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

It's normal after running TFC cleaner that the PC will be slower to boot the first time.

NEXT

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.


Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

**Vista users - right click on the IE icon and run as administrator

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan

3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.


  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report



Go to the top of the page
 
+Quote Post

Posts in this topic
- weemic   [Resolved] trojan on my pc?   Jun 25 2009, 06:44 AM
- - CatByte   Hi, Please do the following: STEP #1 Please dow...   Jun 26 2009, 08:53 PM
- - weemic   hi, thanks for looking into this for me. on satu...   Jun 29 2009, 03:09 AM
- - CatByte   Hi, Yes...transfer the files via USB Please don...   Jun 29 2009, 05:40 AM
- - weemic   hello. managed to download your files to a pen dr...   Jun 30 2009, 01:18 PM
- - CatByte   Hi, Please do the following: Make sure you renam...   Jun 30 2009, 01:22 PM
- - weemic   hello, managed, eventually to get combofix workin...   Jul 2 2009, 04:25 AM
- - CatByte   Hi can you please tell me what files you do see? Y...   Jul 2 2009, 05:40 AM
- - weemic   hey there. thanks for the tip. i just ran combofi...   Jul 2 2009, 01:17 PM
- - CatByte   QUOTE what you think the best free anti virus + sp...   Jul 2 2009, 01:31 PM
- - weemic   cheers for that. ran the tfc cleaner. ran the mal...   Jul 2 2009, 07:08 PM
- - weemic   hey, not sure what happening, ran kaspersky again...   Jul 3 2009, 12:34 AM
- - CatByte   That's odd...must be a hiccup in the Kaspersk...   Jul 3 2009, 01:11 AM
- - weemic   now on my work pc. i sent screen prints in a m...   Jul 3 2009, 02:20 AM
- - CatByte   Hi, I can't see the full path of the infected...   Jul 3 2009, 04:54 AM
- - weemic   thanks, i'll give it a blast when i get home ...   Jul 3 2009, 05:36 AM
- - CatByte   Yes, go ahead and delete all those infected music ...   Jul 3 2009, 05:47 AM
- - weemic   this is the copy to clipboard option list from the...   Jul 3 2009, 11:49 AM
- - weemic   need to go out ill do the fressh dds log shortly   Jul 3 2009, 11:50 AM
- - weemic   hello. i've attached the attach.txt file, its...   Jul 3 2009, 02:32 PM
- - CatByte   Hi, Go ahead and install the antivirus of your ch...   Jul 3 2009, 05:17 PM
- - weemic   hello, i have managed to donwload all the program...   Jul 6 2009, 06:15 AM
- - CatByte   Yes, you have done a good job You should be fin...   Jul 6 2009, 06:19 AM
- - CatByte   Since this issue appears to be resolved ... this T...   Jul 8 2009, 06:04 AM


Closed TopicStart new topic

 


RSS Time is now: 19th March 2010 - 02:58 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy