Locating a problematic Trojan?
Author
Discussion

off_again

Original Poster:

13,917 posts

264 months

Tuesday 26th April 2005
quotequote all
I seem to have got some sort of Trojan on my home PC. My virus checker stops it from doing damage, but nonetheless it is still there.

Basically it is some form of trojan which keeps trying to replace my HOSTS file to prevent access to all sorts of things. But, I cant seem to find it anywhere!

Checked the registry etc, but no luck.

But the funny thing is that the virus checker is tripped on resume of the PC; not reboot or anything else. Anyone know what is run / started / executed on resume and where do I need to look?

Think I got this through an IE vulnerability so Firefox all the way now, but still need to get rid of this thing.

Suggestions?

pdV6

16,442 posts

291 months

Tuesday 26th April 2005
quotequote all
Ad-Aware?

FunkyNige

9,829 posts

305 months

Tuesday 26th April 2005
quotequote all
Start Windows in safe mode (press F8 repeatedly on startup), then scan using virus checker/ anti-spyware progs.

ginettag27

7,118 posts

299 months

Tuesday 26th April 2005
quotequote all
Any idea as to the name of the trojan??

Try this (it's free!!) gets rid of a number of Trojans...

If you're concerned, it comes from McAfee, it gets updated every so often, so worth checking back..

http://vil.nai.com/vil/stinger/

hth

kenny320

1,598 posts

275 months

Tuesday 26th April 2005
quotequote all
Have a look in system32 in your Windows folder. My anti-bot software didn't find it and I had to remove it myself.

There may be a .exe and .dll that are recent and shouldn't be there.

BliarOut

72,863 posts

269 months

Tuesday 26th April 2005
quotequote all
Spybot has a "lock hosts" option.... And is free... And is good

off_again

Original Poster:

13,917 posts

264 months

Wednesday 27th April 2005
quotequote all
Tried both Adaware and Spybot but both didnt get anything other than the standard tracker cookies. Only happens on resume and not restart.... seems strange to me.....

jimbro1000

1,619 posts

314 months

Wednesday 27th April 2005
quotequote all
This sounds very similar to the problem I've been having. Locking down the hosts file has prevented extra problems but there is no doubt my machine is still infected but *nothing* is finding it...

BliarOut

72,863 posts

269 months

Wednesday 27th April 2005
quotequote all
try getting "autoruns" from www.sysinternals.com. It shows where everything is starting from!

off_again

Original Poster:

13,917 posts

264 months

Wednesday 27th April 2005
quotequote all
jimbro1000 said:
This sounds very similar to the problem I've been having. Locking down the hosts file has prevented extra problems but there is no doubt my machine is still infected but *nothing* is finding it...


Yeah, just noticed your thread - and mine keeps coming out of suspend too!!! I will try the stuff that you found out and see if it fixes it....

Oh the benefits of PH...

Plotloss

67,280 posts

300 months

Wednesday 27th April 2005
quotequote all
Another vote for Spybots immunisation.

NAPiston

105 posts

266 months

Wednesday 27th April 2005
quotequote all
This may be more a problem for anti-virus software to solve, not anti-spyware. Have you tried running a different anti-virus program to compare results?

Does the antivirus software state what virus it has found?

One way to find it might be to bring up task manager (ctrl-alt-delete in win2k, xp....) and go through the list of processes and figure out which one doesn't belong. That gives you the file name of the program and a good start to ripping it out.

Misc notes:

If this is XP, try turning off your 'system restore' feature. It could be that the virus has told windows that it is an important system file and windows will check to see if it has been deleted and promptly restore it back.

In a recent test of various anti-spyware programs, including spybot, none of the programs dectected everything. At the end of the test the authors were advising to run several different anti-spyware programs to keep your system clean. God what a mess this has turned into.

rsvmilly

11,288 posts

271 months

Wednesday 27th April 2005
quotequote all
Probably spyware as they're the main culprits for changing the HOSTS file - for browser hijacking.

Google for CWShredder and run it in safe mode.

Godfrey H

145 posts

279 months

Wednesday 27th April 2005
quotequote all
Sounds like a CWS variant to me. Google for Hijackthis, run it in it's own subdirectory post the log back here.

jimbro1000

1,619 posts

314 months

Wednesday 27th April 2005
quotequote all
Found mine - latest pattern file has identified it as "Vundo" (not one I've heard of before) but it seems to be an oldie from last year.

Hopefully this is the end of this little problem

off_again

Original Poster:

13,917 posts

264 months

Wednesday 27th April 2005
quotequote all
Never one to be prevented from doing things, I decided to take this one on.....

Anyway, rather nasty one which was spotted by HJT. As you might expect, it did all of the usual stuff. Locked the file, ran from Winlogon and used system restore to prevent itself from being deleted.

I tried everything, even DrDelete and KillBot. Each time it re-set itself (even with SR turned off!). Running out of ideas I was about to resort to NTFSDOS Professional to delete the file. Then I had a brain wave! Boot to safemode (its XP home) and set the permissions on the file to be Deny everything! Bingo.

Cant run it therefore HJT deletes everything correctly. File gone and rid of this scurge.....

But there is a next question - why on earth do these people write these things? What possess them to do this? Probably never get an answer to that I suppose, but its bloody annoying though....

Oh, and thanks for the help chaps, nearly forgot there!

jimbro1000

1,619 posts

314 months

Thursday 28th April 2005
quotequote all
Well done!

I've always been rather reluctant to perform manual clean ups as I only ever seem to make things worse...

Still a bit bemused by my AV not picking it up until yesterday. Must have been infected for nearly two weeks and it is one they've known about for six months. Anyone have any ideas as to why the pattern files would abandon looking for an older virus?

jimbro1000

1,619 posts

314 months

Friday 29th April 2005
quotequote all
Looks like I spoke too soon - seems my pest has swapped tactics and is now downloading different trojans instead of the same one over and over.

Back to the drawing board

off_again

Original Poster:

13,917 posts

264 months

Friday 29th April 2005
quotequote all
jimbro1000 said:
Looks like I spoke too soon - seems my pest has swapped tactics and is now downloading different trojans instead of the same one over and over.

Back to the drawing board


Post up the HJT log and lets see what we can do?

kenny320

1,598 posts

275 months

Friday 29th April 2005
quotequote all
Finding a similar problem myself... Anybody know any good software to find out which processes are trying to access a net connection?

Edited to add I'm a fool. A decent piece of firewall software should do...

>> Edited by kenny320 on Friday 29th April 09:52

>> Edited by kenny320 on Friday 29th April 10:10