Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

lillypaddle

(9,580 posts)
Sat Aug 4, 2012, 05:39 AM Aug 2012

need help with removing a trojan

trojansvchost.exe

malwarebytes removes it, but it's back again after a restart. Security essentials can't remove it, so I ran Windows Defender offline, but it doesn't even show up in the scan. Any suggestions?

Your help is greatly appreciated!

13 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
need help with removing a trojan (Original Post) lillypaddle Aug 2012 OP
Trojan Remover 6.8.4 douglas9 Aug 2012 #1
No luck lillypaddle Aug 2012 #2
Boot to safe mode... Earth Bound Misfit Aug 2012 #3
couldn't access the internet in safe mode lillypaddle Aug 2012 #4
Good to hear... Earth Bound Misfit Aug 2012 #6
hmmmm lillypaddle Aug 2012 #7
Hmmm... Earth Bound Misfit Aug 2012 #9
I think I got it lillypaddle Aug 2012 #10
You're welcome... Earth Bound Misfit Aug 2012 #11
The IT guy at work lillypaddle Aug 2012 #12
Have you tried to run mbam-chameleon.exe? hobbit709 Aug 2012 #5
I will try that lillypaddle Aug 2012 #8
Grab a tissue, carefully pull it off, tie a knot in the end, and deposit in the trash can. HopeHoops Aug 2012 #13

lillypaddle

(9,580 posts)
2. No luck
Sat Aug 4, 2012, 10:21 AM
Aug 2012

Thanks, douglas, but that is one stubborn virus. Ran the trojan remover twice, appeared to find the files & renamed them or deleted them, but upon restart, still got alerts that it was still there. Appreciate the help, though.

lillypaddle

(9,580 posts)
4. couldn't access the internet in safe mode
Sat Aug 4, 2012, 12:23 PM
Aug 2012

but I followed your links anyway. Right now, everything appears "green." eset found 6 viruses not found by any of the other anti-virus software, so hopefully that's done the trick!

I can't thank you enough.

Earth Bound Misfit

(3,554 posts)
6. Good to hear...
Sat Aug 4, 2012, 04:26 PM
Aug 2012

My bad, I should have told u to d/l the tools first or boot to "Safe mode with networking"

Did TDSSKiller and/or MBAM find/remove/cure/delete etc anything?
If you could post the results logs of each scan we may get a better idea if this "thing" is gone for good --only the last 15 or so lines of TDSS, full MBAM log & items found/removed etc. by ESET

What were/are the symptoms of the malware?

lillypaddle

(9,580 posts)
7. hmmmm
Sat Aug 4, 2012, 04:48 PM
Aug 2012

don't know if I'm savvy enough to post what you ask. The main culprit seemed to be a trojan file called svchost.exe. It still seems to have parts popping up, but once I run all the scans again, things seem to be okay. The other files that eset and none of the others found were olmarik.altrogan and some other variations.

I invested in the paid version of malware bytes. Periodically it says that it's blocking outgoing contact with svchost.exe.

I'll keep you posted if anything else pops up again. As far as the symptons, I kept getting alerts from Security Essentials, and when I'd attempt to go to some website, I'd get these fake (at least they seemed so) websites with blue links instead of what I would expect.

Thanks again!

Earth Bound Misfit

(3,554 posts)
9. Hmmm...
Sat Aug 4, 2012, 05:35 PM
Aug 2012

"Olmarik" is bad news... http://www.eset.eu/encyclopaedia/win32-olmarik-rn-trojan-downloader-agent-dmes-backdoor-tidserv-k-alureon-ct?lng=en

Short description

The trojan contains a backdoor. It can be controlled remotely. It uses techniques common for rootkits. The file is run-time compressed using UPX.


The link above contains a "removal tool" but I'm not familiar with, nor have I used it so I can't speak to it's effectiveness etc.

When TDSS completes, a log is produced at "root". It will be named "UtilityName.Version_Date_Time_log.txt"
for example, C:\TDSSKiller.2.2.0_27.1.2010_15.31.43_log.txt

Double clicking that log will open it in Notepad. Copy the last 15-20 or so lines & post them back here

You really should get expert help making sure this thing is not still lurking about. I recommend Bleepingcomputer.com
Read the pinned topic Instructions for posting advice in Am I Infected and start a thread. The helpers there are extremely helpful, courteous and user/noob friendly.

lillypaddle

(9,580 posts)
10. I think I got it
Sun Aug 5, 2012, 04:22 AM
Aug 2012

with a little help from my friends.

Ran eset, trojan remover, malwarebytes pro again this morning, and all came up clean. I think I'm good to go. Thanks again!

Earth Bound Misfit

(3,554 posts)
11. You're welcome...
Sun Aug 5, 2012, 07:30 AM
Aug 2012

It's your call, however I really think it would be wise to err on the side of caution & have an *expert* (which I am NOT) take a deeper look as suggested in post #9.

lillypaddle

(9,580 posts)
12. The IT guy at work
Sun Aug 5, 2012, 07:51 AM
Aug 2012

I'll have him take a look on Monday. I have a laptop, so it will be easy for him.

On edit: PS, I tried the removal tool you posted in #9, but it wasn't compatible with my OS (64-bit)

Latest Discussions»Help & Search»Computer Help and Support»need help with removing a...