Author Topic: Possible trojan  (Read 12351 times)

0 Members and 1 Guest are viewing this topic.

netmars

  • Guest
Possible trojan
« on: November 23, 2013, 12:06:56 PM »
Hello, can you please check possible problem.
I used SUPERAntiSpyware today and it detected:
Trojan/Malware - HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN#20131121

Is it real, or some false alarm?
Can you please check it?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Possible trojan
« Reply #1 on: November 23, 2013, 12:17:01 PM »
if you have a file, upload and test at www.virustotal.com / www.metascan-online.com / www.jotti.org

log experts are notified, it may take some time before they are online


netmars

  • Guest
Re: Possible trojan
« Reply #2 on: November 23, 2013, 12:20:34 PM »
Thank you for reply.
Actually i dont have any file. I did quick system scan and it just detected this one register as malware/trojan.

argus

  • Guest
Re: Possible trojan
« Reply #3 on: November 23, 2013, 12:23:04 PM »
Hello.





Please download Farbar Recovery Scan Tool () by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Under Optional Scan ensure "Driver MD5" are ticked.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

netmars

  • Guest
Re: Possible trojan
« Reply #4 on: November 23, 2013, 12:35:29 PM »
Hello,
here are logs.

argus

  • Guest
Re: Possible trojan
« Reply #5 on: November 23, 2013, 01:16:31 PM »
I see no present or active malware.


Please download DelFix by "Xplode" to your Desktop.

Run the tool and check the following boxes below;
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.



edit.

Or is it some rest in the registry, malware (if it was present) not active.
« Last Edit: November 23, 2013, 01:29:21 PM by argus »

netmars

  • Guest
Re: Possible trojan
« Reply #6 on: November 23, 2013, 01:27:45 PM »
Ok, thank you.

Can you please explain what is Delfix for and what it actually does? i mean if there is no threat, i am curious especially about options - remove desinfection tools and purge system restore.

argus

  • Guest
Re: Possible trojan
« Reply #7 on: November 23, 2013, 01:32:20 PM »
 DelFix, nicely explained :)

Removed system restore and create a new point, also deleted the tools that we use.
« Last Edit: November 23, 2013, 01:36:54 PM by argus »

netmars

  • Guest
Re: Possible trojan
« Reply #8 on: November 23, 2013, 01:40:59 PM »
:)
ok, i did even this, but SUPERAntiSpyware system scan still targeting register (i cant even find it in regedit)

Trojan.Agent/Gen - (x86) HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN#20131121

so you are sure there is no malware and this is only false alarm?

Edit: I did find it. - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 and there is "20131121"=hex:02,00,00,00,00,00,00,00,00,00,00,00
« Last Edit: November 23, 2013, 01:45:04 PM by netmars »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Possible trojan
« Reply #9 on: November 23, 2013, 03:46:01 PM »
Could be a Bitcoinminer detection remainder, use safe mode to not get the alert.
Maybe a temp file cleaner will get rid of this remainder.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

netmars

  • Guest
Re: Possible trojan
« Reply #10 on: November 23, 2013, 03:55:17 PM »
Thanks for reply,
i found that it is in "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run" too.
There is register record "20131121"="C:\\Program Files\\AVAST Software\\Avast\\setup\\emupdate\\737f022d-1098-4dad-9fbb-f3244e2767fc.exe /check".

So can it be actually from Avast?
« Last Edit: November 23, 2013, 04:03:24 PM by netmars »

Offline Simion

  • Advanced Poster
  • **
  • Posts: 976
Re: Possible trojan
« Reply #11 on: November 23, 2013, 10:14:17 PM »
I'm getting the same detection from SAS and believe it's a false positive.

netmars

  • Guest
Re: Possible trojan
« Reply #12 on: November 23, 2013, 10:20:48 PM »
ok, good to know, thank you

Offline Simion

  • Advanced Poster
  • **
  • Posts: 976
Re: Possible trojan
« Reply #13 on: November 23, 2013, 10:25:49 PM »
You're welcome, netmars. Let's see what the experts say, though.  ;)

storm_21

  • Guest
Re: Possible trojan
« Reply #14 on: November 23, 2013, 11:26:17 PM »
Same detection here while running SAS!