Author Topic: Trojan.Downloader Detected  (Read 6908 times)

0 Members and 1 Guest are viewing this topic.

Offline Patrick2

  • Poster
  • *
  • Posts: 489
Trojan.Downloader Detected
« on: September 23, 2016, 11:00:36 PM »
Hi There

Asked in another forum, which they recommended to use Defender after upcoming clean install,  Defender so far has quarantined the file which is TrojanDownload.JS/Nemucod.HC

 I can't do Clean install today, stuff to do, you know, anyways is it safe to use Avast if I choose to after Windows 10 Pro clean install?  Use Ms Edge and IE for browsing, how I got it, I'm not really sure, probably from a site I would guess, or email possibly

I can provide logs from all the scans I ran if need be, I just wanna feel comfortable the machine is totally clean, and doesn't spread to entire network of systems.   So in morning doing clean install

Windows 10 Pro 64bit 1909 18363.476, Intel I7 7700 Nvidia Geforce 1050 16gb DDR4, WD 250GBSSD, 1tb Storage, Avast Free 19.8.2393
HP Omen Laptop Intel I7 7700HQ, 8gb Of Ram Windows 10 Home x64 1909 18363.476 128GB SSD, 1tb Storage, Avast Free 19.8.2393

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Trojan.Downloader Detected
« Reply #1 on: September 23, 2016, 11:01:24 PM »

Offline Patrick2

  • Poster
  • *
  • Posts: 489
Re: Trojan.Downloader Detected
« Reply #2 on: September 23, 2016, 11:02:05 PM »
Oops wrong area sorry there...

« Last Edit: September 23, 2016, 11:46:41 PM by Patrick2 »
Windows 10 Pro 64bit 1909 18363.476, Intel I7 7700 Nvidia Geforce 1050 16gb DDR4, WD 250GBSSD, 1tb Storage, Avast Free 19.8.2393
HP Omen Laptop Intel I7 7700HQ, 8gb Of Ram Windows 10 Home x64 1909 18363.476 128GB SSD, 1tb Storage, Avast Free 19.8.2393

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Trojan.Downloader Detected
« Reply #3 on: September 23, 2016, 11:29:03 PM »
Clean install of what?  ... wipe the computer and resinstall?


Offline Patrick2

  • Poster
  • *
  • Posts: 489
Re: Trojan.Downloader Detected
« Reply #4 on: September 23, 2016, 11:31:26 PM »
Yeah thinking doing that, Another forum suggested after clean install done, to stick with Windows 10 Defender,  I forgot I had Avast installed yesterday, should've asked here in the first place,  (last week or two was switching between Defender/Avast trying to decide which protection program to stay with, and may have gotten the infection then possibly, not sure)


Moral of the story is I guess I have to be more careful, stay with 1 Antivirus program.

« Last Edit: September 23, 2016, 11:35:13 PM by Patrick2 »
Windows 10 Pro 64bit 1909 18363.476, Intel I7 7700 Nvidia Geforce 1050 16gb DDR4, WD 250GBSSD, 1tb Storage, Avast Free 19.8.2393
HP Omen Laptop Intel I7 7700HQ, 8gb Of Ram Windows 10 Home x64 1909 18363.476 128GB SSD, 1tb Storage, Avast Free 19.8.2393

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Trojan.Downloader Detected
« Reply #5 on: September 23, 2016, 11:36:59 PM »
If you are going to reinstall then why all this?


Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Trojan.Downloader Detected
« Reply #6 on: September 23, 2016, 11:37:20 PM »
a .dat file can be detected as malicious, but it doesn't run without something else.
I suggest you provide the log files and let us have a look at them.
A good check will not hurt ;)

As far as Defender or avast...
Defender has (to put it simple) just a database that is used to scan files.
avast has a lot more other protection methods than just a database (VPS).

Offline Patrick2

  • Poster
  • *
  • Posts: 489
Re: Trojan.Downloader Detected
« Reply #7 on: September 23, 2016, 11:44:32 PM »
Will do, Keep in mind original detection quarantined in Defender still, so maybe that is why other programs found nothing



« Last Edit: September 23, 2016, 11:53:41 PM by Patrick2 »
Windows 10 Pro 64bit 1909 18363.476, Intel I7 7700 Nvidia Geforce 1050 16gb DDR4, WD 250GBSSD, 1tb Storage, Avast Free 19.8.2393
HP Omen Laptop Intel I7 7700HQ, 8gb Of Ram Windows 10 Home x64 1909 18363.476 128GB SSD, 1tb Storage, Avast Free 19.8.2393

Offline Rednose

  • Pirate Party Member
  • Avast Überevangelist
  • Massive Poster
  • *****
  • Posts: 3739
  • Bits of Freedom : https://www.bof.nl
    • Nederlandstalig Avast! forum
Re: Trojan.Downloader Detected
« Reply #8 on: September 24, 2016, 12:16:14 AM »
Hi Patrick :)

As far as providing log files, Eddy is meaning the log files from the sticky as well :

https://forum.avast.com/index.php?topic=53253.0

Greetz, Red.
OS: Win 10 / iOS 17 / Debian 12 / Tails 5
Real Time: Avast Premium Security
On Demand: Malwarebytes
VPN: NordVPN ( NordLynx ) with Threat Protection ( Lite )

Offline Patrick2

  • Poster
  • *
  • Posts: 489
Re: Trojan.Downloader Detected
« Reply #9 on: September 24, 2016, 12:24:51 AM »
Sure can do that, one moment here

*Note Getting Rest of the logs might be a bit, checking External drives as well, maybe not such a good idea lol, 500gb times x 2,  usb 2.0 speeds, rest of logs posted soon as possible though*

Checking externals will make sure files are fully clean anyways before full clean system install early tomorrow anyhow, last night I only checked Internal C Drive

« Last Edit: September 24, 2016, 02:39:48 AM by Patrick2 »
Windows 10 Pro 64bit 1909 18363.476, Intel I7 7700 Nvidia Geforce 1050 16gb DDR4, WD 250GBSSD, 1tb Storage, Avast Free 19.8.2393
HP Omen Laptop Intel I7 7700HQ, 8gb Of Ram Windows 10 Home x64 1909 18363.476 128GB SSD, 1tb Storage, Avast Free 19.8.2393

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Trojan.Downloader Detected
« Reply #10 on: September 26, 2016, 06:00:15 PM »
To add to what Rednose mentioned, the main log needed was FRST.txt and Addition.txt.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Patrick2

  • Poster
  • *
  • Posts: 489
Re: Trojan.Downloader Detected
« Reply #11 on: September 26, 2016, 06:05:35 PM »
Well I can provide those logs, but those showed clean when I ran those, wasn't sure if previous Antivirus removed the Threat fully, so went ahead with Clean PC install anyways, despite all the other scans and programs showed clean, can re run those scans, to make sure still clean though after data restored and such

« Last Edit: September 26, 2016, 06:11:23 PM by Patrick2 »
Windows 10 Pro 64bit 1909 18363.476, Intel I7 7700 Nvidia Geforce 1050 16gb DDR4, WD 250GBSSD, 1tb Storage, Avast Free 19.8.2393
HP Omen Laptop Intel I7 7700HQ, 8gb Of Ram Windows 10 Home x64 1909 18363.476 128GB SSD, 1tb Storage, Avast Free 19.8.2393

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Trojan.Downloader Detected
« Reply #12 on: September 26, 2016, 06:13:32 PM »
Quote
Well I can provide those logs, but those showed clean when I ran those
Do you know how to read those logs?

FRST is a diagnostic program and will not show any detection


Offline Patrick2

  • Poster
  • *
  • Posts: 489
Re: Trojan.Downloader Detected
« Reply #13 on: September 26, 2016, 06:15:03 PM »
Ohhh didn't know that, well that programs logs are posted now, will get rest posted in a few moments here, or after lunch....got a lot to learn still I guess on various programs, and such it appears, Still wonders if I hadn't switch to Defender if Avast would've seen the original threat, which I paniced on a bit, and ended up rushing thru Windows 10 Clean install, changed all account passwords even.   

Little back story on this situation

Had some folks in another forum telling me to stick with Windows Defender, Malwarebytes, and Malwarebyes Anti Exploit,  Well then I felt a little unsafe after Defender blocked a Severe Threat--Trojan Downloader, (exact name I can get easily), then reinstalled Avast remotely via Remote desktop from my phone that late night, didn't feel safe after that even, so decided to do a complete clean install, and so far so good

« Last Edit: September 26, 2016, 09:43:07 PM by Patrick2 »
Windows 10 Pro 64bit 1909 18363.476, Intel I7 7700 Nvidia Geforce 1050 16gb DDR4, WD 250GBSSD, 1tb Storage, Avast Free 19.8.2393
HP Omen Laptop Intel I7 7700HQ, 8gb Of Ram Windows 10 Home x64 1909 18363.476 128GB SSD, 1tb Storage, Avast Free 19.8.2393

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Trojan.Downloader Detected
« Reply #14 on: September 26, 2016, 10:48:39 PM »
Ah, cheers. As Pondus mentioned these are custom logs. Most people can't read them.

@Pondus, have you PM'd dbrise?

@Patrick2, is this a commercial PC? The reason I ask is because you're running Windows 10 Pro, and you have a commercial version of Windows Defender. "Windows Defender Advanced Threat Protection"

More on that here: https://www.microsoft.com/en-us/WindowsForBusiness/Windows-ATP

Also, can you find this file: C:\Users\amdma\AppData\Local\Temp\sonarinst.exe

Scan it at www.virustotal.com and post results back here.

Someone else will take care of you, dbrisendine I'm sure.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.