Author Topic: Threat: Win32:Downloader-MOG [Trj]  (Read 9200 times)

0 Members and 1 Guest are viewing this topic.

hellflame

  • Guest
Threat: Win32:Downloader-MOG [Trj]
« on: January 26, 2012, 04:43:19 PM »
Hi, i am having problems with a virus detected by Avast when i ran a custom scan with System drive, memory, auto start and auto start programs checked. The scan detected an infected file.

It came up as process 1004 [svchost.exe], memory block 0x0000000001EA0000, block size 315392.
Threat: Win32:Downloader-MOG [Trj]. There wasn't any action that was available to be taken against this file, so i am at a loss as to what i should do.

I scan my computer regularly, both full and quick scans, either one of the scans at least once per day, but there were never any detections until today when Avast Webshield blocked a malicious ad popup on mediafire. Being paranoid, i decided to scan my computer and i created a custom scan which included memory scan. This then came up.

I've also ran scans using MBAM at least twice a week, both full and quick scans, but nothing came up as well.

Being paranoid, i downloaded and ran Spybot Search and destroy, but that too didn't come up with anything.

Data on my computer is divided into two portions, my OS is run on a solid state drive while my media data is stored on a mechanical hard drive. I'd like to know what i should do in this situation and whether my drives are infected, or if it's the memory RAM that's infected. Thank you very much. I'm attaching the scan log of mBam below. Any help is appreciated, thanks.


Edit: After uninstalling spybot (i was worried that it might interfere with Avast and mBam) and restarting, i ran the custom scan again and this time nothing came up. I ran a quick scan with mBam again as well and nothing came up too. I'll attach the 2nd log as well.
« Last Edit: January 26, 2012, 04:57:18 PM by hellflame »

true indian

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #1 on: January 26, 2012, 05:36:33 PM »
http://forum.avast.com/index.php?topic=53253.0

follow the guide...link above..

attach all the logs..

Please give the location of svchost.exe that is detected?

Did u do that scan immediately after the web shield detection?

can u scan again and see if it is still detecting it?

Final advice:Never use memory scan option it causes weird issues...

Essexboy notified...
« Last Edit: January 26, 2012, 05:44:27 PM by true indian »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37561
  • Not a avast user
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #2 on: January 26, 2012, 06:01:56 PM »
Quote
It came up as process 1004 [svchost.exe], memory block 0x0000000001EA0000, block size 315392.
Threat: Win32:Downloader-MOG [Trj]. There wasn't any action that was available to be taken against this file, so i am at a loss as to what i should do.
bc it is a process and not a file....you can`t move a process to chest   ;)


Quote
Being paranoid, i decided to scan my computer and i created a custom scan which included memory scan. This then came up.
and this i where you did wrong......the "scan memory" setting will give some strange results if used...the forum is full if you search


DO NOT use the "scan memory" setting. If you don`t know the result of changing the scan settings, then don`t do it
use the default quick/full scan with default settings and scan again, if you then detect anything....tell us


OBS: and if/when you attach logs, they must be saved as ANSI so we can read them.....now it is chinese  ;)

« Last Edit: January 26, 2012, 06:05:49 PM by Pondus »

hellflame

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #3 on: January 26, 2012, 11:28:47 PM »
Thanks to both of you for your speedy replies. I scanned my computer using the default quick scan functions of mBAm and avast after the block by web shield, and followed it up with full scan function for avast. There were no detections by both softwares. I quick scanned again using both mbam and avast again after I rebooted and nothing came up either.  I'll do another scan when I get home tonight and post the logs just to be sure. Once again, thanks a lot for your help, it is much appreciated.

hellflame

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #4 on: January 27, 2012, 12:57:25 PM »
Hi, i have followed Pondus' advice to do a scan with the default settings for Avast. I restored Avast to it's factory settings just to be sure and did both quick and full scans after rebooting. Nothing was detected. I also did a quick scan with mBam and nothing came up as well. I'll attach the logs from yesterday and now just to be sure.

Also, i am not sure as to what the process 1004 [svchost.exe], memory block 0x0000000001EA0000, block size 315392 is as it did not come up again the memory scan i did yesterday after i rebooted, should i be worried about it? Thanks for the help. :)

I am not sure if this is of any help, but previous scans before this particular memory scan which picked up the svchost.exe virus, both full and quick on mBam and avast have not detected anything until the custom scan picked up this virus yesterday.

Lastly,will checking the "Test whole file" option, turning on scan PUP and increasing the heuristics sensitivity and the scan priority of both the default quick and full scan to the max affect the scan results in a negative way? (Sorry for being so terribly long winded, this were the changes i made to the built in scans on Avast before i restored it to the default factory settings, so i was worried it might have affected the scan results negatively.)

hellflame

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #5 on: January 27, 2012, 02:00:14 PM »
Just did a full scan with mbam as well, attaching log.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37561
  • Not a avast user
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #6 on: January 27, 2012, 02:09:54 PM »
Quote
Lastly,will checking the "Test whole file" option, turning on scan PUP and increasing the heuristics sensitivity and the scan priority of both the default quick and full scan to the max affect the scan results in a negative way? (Sorry for being so terribly long winded, this were the changes i made to the built in scans on Avast before i restored it to the default factory settings, so i was worried it might have affected the scan results negatively.)
In a computer there are lots of files that are not necessary to scan.....so if you turn on every thing and scan every thing, the scan will be slow as molasses and take a week to finish
also a antivirus with real time protection like avast is scanning every file that moves in the computer when you use it.....it is working in the background all time

the guys at avast have played with malware 24/7 for 20 years.....they know how this works.
So unless you have some special needs...and know what you do, leave it at default settings



OBS: and PUP is not virus. it is a warning that you have (if detected) a program that can be used for good or bad (like a commercial key logger)

PUP (potentially unwanted program) http://searchsecurity.techtarget.com/definition/PUP


hellflame

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #7 on: January 27, 2012, 03:09:33 PM »
Okay, thanks a lot for the heads up pondus :)
With regards to my logs and the detection, i suppose i have to wait for Essexboy then?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37561
  • Not a avast user
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #8 on: January 27, 2012, 03:19:12 PM »
well the detection in memory i would not worry about.....reason explained above
and your mbam logs are clean..


but if you want Essexboy to have a look inside...he is the Malware terminator expert
then follow this guide, and attach the OTL log`s
http://forum.avast.com/index.php?topic=53253.0

hellflame

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #9 on: January 27, 2012, 03:54:43 PM »
I've dl-ed OTL from the link you've given me, but avast identifies it as a potentially unsafe software and advises me to open it up in the avast sandbox. Do i run it in the sandbox or do run it normally? Windows will tell me that it cannot access the file if i select cancel opening. Thanks for your help.
« Last Edit: January 27, 2012, 03:56:59 PM by hellflame »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37561
  • Not a avast user
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #10 on: January 27, 2012, 04:02:28 PM »
you run it Normally.....no sandbox

hellflame

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #11 on: January 27, 2012, 05:22:43 PM »
Alright, i've ran OTL. Attaching the logs. Thanks for helping!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #12 on: January 27, 2012, 08:54:35 PM »
The log looks clean are you experiencing any problems

hellflame

  • Guest
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #13 on: January 27, 2012, 08:59:30 PM »
Nope, there doesn't seem to be any problems with my computer. The quick and full scans by Avast and mbam are not detecting anything. The scans have not picked up anything for quite a period of time now and it's only the memory scan yesterday that picked up the process. Is it safe to say that it's a false positive then?
« Last Edit: January 27, 2012, 09:05:38 PM by hellflame »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Threat: Win32:Downloader-MOG [Trj]
« Reply #14 on: January 27, 2012, 09:07:31 PM »
Yes, you will get that when you do a memory scan

Run OTL and press the cleanup button to remove it