Author Topic: Daily Trojan  (Read 13378 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Daily Trojan
« on: November 19, 2015, 06:01:38 AM »
MalwareBytes is finding Trojans nearly every day after I check my email...I am not doing anything stupid in my email opening.  This is an old computer I use for photo editing, and it freezes, I scan, a Trojan is there.  It's mostly in the same Registry location...is it replicating itself there?  Would deleting that registry key stop it? I don't know how it is getting past my Avast Protection/firewall, etc.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Daily Trojan
« Reply #1 on: November 19, 2015, 06:22:33 AM »
Attach your basic diagnostic logs. (MBAM, FRST and aswMBR)
Instructions: https://forum.avast.com/index.php?topic=53253.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Daily Trojan
« Reply #2 on: November 19, 2015, 06:45:04 AM »
Can you attach the MBAM scan log?

One other scan to run (along with the FRST scan):


Please download Malwarebytes Anti-Rootkit from here
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder... mbar-log.txt and system-log.txt
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Daily Trojan
« Reply #3 on: November 20, 2015, 04:57:00 AM »
OK, it's taken me all day to get FRST to download and scan...finally done...and a few MBAM logs exported.  Let me know if anything is missing, please.  Thanks.

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Daily Trojan
« Reply #4 on: November 20, 2015, 05:15:35 AM »
Did you scan with Malwarebytes' Anti-Rootkit?
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Daily Trojan
« Reply #5 on: November 20, 2015, 05:40:46 AM »


FIRST >>>>

Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

Freemake Audio Converter version 1.1.0
Freemake Video Converter version 4.1.7
Freemake Youtube Mp3 Converter


To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window. 

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.


SECOND >>>>

Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Daily Trojan
« Reply #6 on: November 20, 2015, 06:17:17 PM »
Yes, I did scan with MBAR, just forgot to attach that scan...will attach now with FRST fixlist.
Re the Desktop of the September discussion, I found that the network card is apparently destroyed, still can't get it online, and also somehow, the name of my default printer has been changed, so that I could not print over my network. I would still like to have some answers to the original question of how these Trojans are getting past my Avast firewall/protection, and what I can do to prevent further damage to my equipment and data?  And if you would please tell me what you are finding from my logs, it would be helpful to have them translated so that I can understand what is affecting my computer.  Thank you for your assistance.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37530
  • Not a avast user
Re: Daily Trojan
« Reply #7 on: November 20, 2015, 06:34:52 PM »
Quote
I would still like to have some answers to the original question of how these Trojans are getting past my Avast firewall/protection,
No security program have 100% detection or zero false positives

In your reply nr#3 you have attached Malwarebytes protection log twice, please attach Malwarebytes scan log so  dbrisendine can se what is detected

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Daily Trojan
« Reply #8 on: November 21, 2015, 07:51:41 AM »
The Fixlist.txt you ran is NOT the one I provided to you.  Where did it come from?
Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE

REDACTED

  • Guest
Re: Daily Trojan
« Reply #9 on: November 21, 2015, 06:01:50 PM »
Not sure how I got the wrong fixlist attached, but am attaching what I hope is the right one...in my first post I attached a copy of the scan log, and am attaching the one I just did this morning. This trojan turns up in the same registry key over and over...does it clone itself there? and would it be harmful to delete that registry key?

REDACTED

  • Guest
Re: Daily Trojan
« Reply #10 on: November 21, 2015, 07:05:28 PM »
Second time today: at 1:00pm  Another scan result

Another note: on my Vista SP2 computer, first, there is no "Program Data" file on the C drive...second, in the Avast Software file, I have not been able to find a record of my boot scan results. Do you know where I might find that log?
« Last Edit: November 21, 2015, 07:15:27 PM by Kathryn9 »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Daily Trojan
« Reply #11 on: November 22, 2015, 03:31:35 AM »
Is the one on your primary system appear to be ghosted?

It likely is, it will be re-hidden. It's a Windows Folder, don't delete it!!

I will find the Avast! Save location as soon as possible

I can't find anything concrete, but you might be able to locate it under "C:\ProgramData\Avast Software\Avast\Log"

or

"C:\ProgramData\Avast Software\Avast\report"
« Last Edit: November 22, 2015, 03:47:55 AM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Daily Trojan
« Reply #12 on: November 22, 2015, 06:10:36 AM »
That's the problem, in Vista SP2, there isn't a Program Data File...I think I found it?? but there is only one scan on it, so where are all the rest...this is in the Program File, Avast Software, aswMBR...does that sound right?  Attaching...see if this is what I'm looking for.
Thanks
PS, I don't know if the registry file is ghosted...how would I tell?
« Last Edit: November 22, 2015, 06:12:36 AM by Kathryn9 »

REDACTED

  • Guest
Re: Daily Trojan
« Reply #13 on: November 22, 2015, 06:33:57 AM »
Just scanned with MBAM again, 3rd time since this morning it is there again....

Offline dbrisendine

  • Malware Fighter
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1258
Re: Daily Trojan
« Reply #14 on: November 22, 2015, 08:13:51 AM »
Is there an issue I am not understanding here?  You posted the same Fixlog.txt log file twice now and did not say where you got the file from.  Are you getting help from another source and / or working on two different systems or what?

Here are my instructions once again:

FIRST >>>>

Please go to START (Windows Orb) >> Control Panel >> Uninstall a Program or Programs and Features and remove the following (if listed):

Freemake Audio Converter version 1.1.0
Freemake Video Converter version 4.1.7
Freemake Youtube Mp3 Converter


To do so, left clicking on the name once and then click Uninstall/Change at the bar above the list window. 

Follow the prompts of the uninstaller BUT please read carefully any questions it asks before answering; some uninstallers will try and deceive you into keeping the software.


SECOND >>>>

Fix with Farbar Recovery Scan Tool
This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

Win7 x32 Ult. SP1, Brain 2.0 / Win10 x64, Brain2.5
My help is always free but if you would like to help encourage me or show your thanks -----> DONATE