Author Topic: what to do if a trojan is found in system restore?  (Read 26167 times)

0 Members and 1 Guest are viewing this topic.

samnetx

  • Guest
what to do if a trojan is found in system restore?
« on: May 11, 2009, 05:15:00 PM »
there are trojans found in my system restore when i scanned my drive from avast home edition
the name of trojans are

win32: Swizzor [trj]
win32: Trojan-gen {other}
win32: Agent-EID [trj]
win32: Spyware-gen [trj]

what to do next?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: what to do if a trojan is found in system restore?
« Reply #1 on: May 11, 2009, 05:25:12 PM »
I suggest:

1. Clean your temporary files.
2. Schedule a boot time scanning with avast with archive scanning turned on. If avast does not detect it, you can try DrWeb CureIT! instead.
3. Use MBAM (or SUPERantispyware or even Spyware Terminator) to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete them.
4. Test your machine with anti-rootkit applications. I suggest avast! antirootkit or Trend Micro RootkitBuster.
5. Make a HijackThis log to post here or this analysis site. Or even submit the RunScanner log to to on-line analysis.
6. Disable System Restore and then reenable it again.
7. Immunize your system with SpywareBlaster.
8. Check if you have insecure applications with Secunia Software Inspector.

The step 2 could clean (and as a side-effect, broke) the system restore points.
The step 6 will delete all restore points (and you could create a new one after that).
The best things in life are free.

samnetx

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #2 on: May 23, 2009, 05:27:24 AM »
here is my HijackThis log file attached

Mr.Agent

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #3 on: May 23, 2009, 03:51:44 PM »
if you know where they are located post a virus total of them and if you feel unsure you can alway move them to the chest like its say its recommand for most people and ALWIL his self :)

Correct me if im wrong.

Thank.

Mr.Agent
« Last Edit: May 24, 2009, 02:21:06 PM by Mr.Agent »

CharleyO

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #4 on: May 23, 2009, 11:29:13 PM »
***

Not much to worry about in your HJT log except for ......

We didn't detect any active process of a firewall on your system. Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don't use any firewall at all.
We recommend you to use a firewall.


Since these were found in System Restore, I suggest you turn off System Restore, restart your computer, and then turn System Restore on again. Create a new restore point.


***
« Last Edit: May 23, 2009, 11:30:50 PM by CharleyO »

CharleyO

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #5 on: May 28, 2009, 07:57:24 AM »
***

Hi samnetx -

I have not been able to be here for a few days plus I have been doing a little research that was suggested by a friend on here. It seems that win32: Swizzor [trj], etc is a sign of a lop infection. So, it seems you may have had a lop infection in the past since these were found in system restore on your computer. Do you remember having a bad computer infection during the recent past?

If you would like, you can follow the below instructions to be sure you do not still have the remains of a lop infection. You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://swandog46.geekstogo.com/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts. Afterwards, Hijack This will launch. Close Hijack This, and click OK to proceed.

At the end of the fix, you may need to restart your computer again.

Finally, please post the contents of the logfile C:\fixwareout\report.txt and the new HJT log.


***

samnetx

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #6 on: July 12, 2009, 01:26:25 PM »
again i found something in System Restore

previously when trojans were found disabled system restore and again enabled it
i found adware in system restore detected by Malwarebytes
SUPERAntiSpyware detected trojan and spyware in system restore and registry
nothing is found in folders WINDOWS and PROGRAMFILES scanned by MBAM and SAS

i reinstalled Outpost firewall pro 2009 because
i think its happening due to Windows Firewall sp3 not avast home shields

my recent OS history
Trojan.lop was detected in recent past by MBAM
i remember having bad system infection my OS crashed in recent past
with AVG - 3 times in 2007 i reinstalled WINDOWS xp sp2

with avast - 2 times in 2008 i reinstalled WINDOWS xp sp2

from November 2008 upto 2009 July
i have not reinstalled windows xp  
now days i found no lack of performance in my computer but i still found Trojans,spyware,adware
mostly in system restore

i want to know about FIXWAREOUT

here are my log files attached of MBAM and SAS
« Last Edit: July 12, 2009, 05:09:18 PM by samnetx »

micky77

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #7 on: July 12, 2009, 01:41:21 PM »
Charley, those links you posted,seem to be dead, well for me they are

samnetx, if you are sure your system is clean, ( not including anything in system restore ) Disable system restore, and re-enable.You will lose all restore points, and anything in them

« Last Edit: July 12, 2009, 02:01:29 PM by micky77 »

Offline mathboyx215

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 449
Re: what to do if a trojan is found in system restore?
« Reply #8 on: July 12, 2009, 05:34:45 PM »
Try disabling system restore for a few days and then enable it again.
It is not possible to divide anything by zero

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: what to do if a trojan is found in system restore?
« Reply #9 on: July 12, 2009, 08:46:40 PM »
It's not necessary to wait some days. Disable, boot, enable will be enough.
The best things in life are free.

CharleyO

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #10 on: July 14, 2009, 04:58:03 AM »
***

Sorry about the bad links.    :(

***

Not much to worry about in your HJT log except for ......

We didn't detect any active process of a firewall on your system. Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don't use any firewall at all.
We recommend you to use a firewall.


Since these were found in System Restore, I suggest you turn off System Restore, restart your computer, and then turn System Restore on again. Create a new restore point.


***

Yeah, I suggested fixing the restore points in my first post. Apparently, that was not followed.


***

samnetx

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #11 on: July 14, 2009, 06:45:15 PM »
Hi CharleyO

I really followed your suggestion the first time you asked me to do, I turned off System Restore, restarted my computer and then turned System Restore on again but I didnt created restore point because it is created automatically when System Restore turned on.

I was using Windows xp firewall sp3 at that time. Now I installed Outpost Firewall Pro 2009 when I found trojan & adware detected by SAS & MBAM once again. I use internet about 5 to 8 hours daily and I think it is due to Windows Firewall sp3.
Nothing is detected by avast, MBAM & SAS in folders [Windows] and [Programfiles].

I dont know why trojans, adwares are found in System Restore.

samnetx

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: what to do if a trojan is found in system restore?
« Reply #12 on: July 14, 2009, 07:16:54 PM »
If you post (attach) the MBAM and SAS logs and we can take a look at them to see what was found. That helps us to help you.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

samnetx

  • Guest
Re: what to do if a trojan is found in system restore?
« Reply #13 on: July 14, 2009, 09:58:04 PM »
Hi DavidR

I have posted (attached) the MBAM and SAS logs in this topic on July 12, 2009. You can take a look at them to see what was found.

samnetx

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: what to do if a trojan is found in system restore?
« Reply #14 on: July 14, 2009, 10:33:01 PM »
Sorry I though you had run them again.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security