Author Topic: Trojan in temp  (Read 6115 times)

0 Members and 1 Guest are viewing this topic.

frj1001

  • Guest
Trojan in temp
« on: June 26, 2010, 03:18:51 PM »
Hi
I am using Avast ver 5.0 free antivirus. Recently i am receiving a win32:Trojan-Gen virus threat pop ups by avast every time i log in, shut down my computer or almost at any activity that i do like opening programs, browsers etc. This is the infected file
C:\Documents and Settings\Administrator\Local Settings\temp\ssm.dat
I have already deleted all the files in the temp folder and turned system restore off but this ssm.dat file keeps coming back. i have also deleted it after the avast scan through avast and also tried to repair it but to no avail. plz can someone help me get rid of this virus for good.   

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89012
  • No support PMs thanks
Re: Trojan in temp
« Reply #1 on: June 26, 2010, 03:56:48 PM »
If it keeps coming back, there is likely to be an undetected or hidden element to the infection that restores or downloads the file again. What is your firewall ?

If you haven't already got this software (freeware), download, install, update and run it and report the findings (it should product a log file).

Don't worry about reported tracking cookies they are a minor issue and not one of security, allow SAS to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie.
Also available a portable version of SAS, http://www.superantispyware.com/portablescanner.html, no installation required.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

frj1001

  • Guest
Re: Trojan in temp
« Reply #2 on: June 27, 2010, 09:32:08 AM »
Hi
i have tried both Malware bytes and SAS but neither has detected the threat. what should i do now?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37526
  • Not a avast user
Re: Trojan in temp
« Reply #3 on: June 27, 2010, 10:30:15 AM »
Try this

Dr.Web CureIt http://www.freedrweb.com/cureit/?lng=en
How Do I Use Dr.Web CureIt!? http://www.freedrweb.com/cureit/how_it_works/
Norman Malware Cleaner http://www.norman.com/support/support_tools/58732/en

no install, just save to desktop and run from there.
When they have done the work you can just dragg and dropp in the resycle bin

if this does not work, then Essexboy is next.....

frj1001

  • Guest
Re: Trojan in temp
« Reply #4 on: June 29, 2010, 08:20:38 AM »
No luck again. The malware softwares delete the file temporarily but the trojan keeps coming back. I think the registry is infected. Can someone help me with this?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37526
  • Not a avast user
Re: Trojan in temp
« Reply #5 on: June 29, 2010, 09:00:34 AM »
Follow this guide from Essexboy and post the log`s in your next reply here as attachments
http://forum.avast.com/index.php?topic=53253.0

down left corner > additional options > attach  (OTL.Txt / Extras.Txt. / MBAM log )

frj1001

  • Guest
Re: Trojan in temp
« Reply #6 on: June 30, 2010, 09:00:28 AM »
mbam doesn't detect any infection. here are the log files

frj1001

  • Guest
Re: Trojan in temp
« Reply #7 on: June 30, 2010, 09:08:53 AM »
i'm not being able to upload the log files

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89012
  • No support PMs thanks
Re: Trojan in temp
« Reply #8 on: June 30, 2010, 03:53:33 PM »
What files and Why, e.g. what errors are you getting ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

frj1001

  • Guest
Re: Trojan in temp
« Reply #9 on: June 30, 2010, 07:07:32 PM »
Guys i think i did it but i need your help on this one. i've deleted the temp folder that contained the infected file through the command prompt and the pop ups are not appearing anymore and i've scanned the folder it doesn't show any infection now. has the trojen really gone or is there still a threat? is it okay to delete the files from the avast chest now

CharleyO

  • Guest
Re: Trojan in temp
« Reply #10 on: June 30, 2010, 07:20:44 PM »
***

Where was this temp folder located?


***

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89012
  • No support PMs thanks
Re: Trojan in temp
« Reply #11 on: June 30, 2010, 08:09:53 PM »
You need help but we need answers to the questions we ask so that we can offer better advice.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

frj1001

  • Guest
Re: Trojan in temp
« Reply #12 on: July 01, 2010, 04:38:20 PM »
this is the location of temp
C:\Documents and Settings\Administrator\Local Settings\temp

frj1001

  • Guest
Re: Trojan in temp
« Reply #13 on: July 01, 2010, 04:42:27 PM »
here are the log files again, earlier i was having some connection issues

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Trojan in temp
« Reply #14 on: July 01, 2010, 08:51:52 PM »
It looks like you have an infected USB drive

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

Code: [Select]
:OTL
O33 - MountPoints2\{ed0f3480-7f52-11df-9f41-080046c09b71}\Shell\Autoplay\COmmanD - "" = vkoesa.cmd
O33 - MountPoints2\{ed0f3480-7f52-11df-9f41-080046c09b71}\Shell\AutoRun\command - "" = vkoesa.cmd
O33 - MountPoints2\{ed0f3480-7f52-11df-9f41-080046c09b71}\Shell\ExPlOre\CoMManD - "" = vkoesa.cmd
O33 - MountPoints2\{ed0f3480-7f52-11df-9f41-080046c09b71}\Shell\OPen\COMmand - "" = vkoesa.cmd

:Commands
[resethosts]
[purity]
[emptytemp]
[EMPTYFLASH]
[CLEARALLRESTOREPOINTS]
[Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
    1 - Flash Drive Disinfector
    Download Flash_Disinfector.exe by sUBs from here and save it to your desktop.
    • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
    • Wait until it has finished scanning and then exit the program.
    • Reboot your computer when done.
    Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you run it. Don't delete this folder...it will help protect your drives from future infection.
    [/list]