Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: Need to remove a trojan

  1. #1
    Junior Member
    Join Date
    Aug 2008
    Posts
    7

    Default Need to remove a trojan

    I downloaded a keygen or something for Daniusoft WMA MP3 player (dumb, i now know...) Anyway, I have a trojan. I have AVG running a scan, but it has been running for two days and still isnt finished. These are the infections listed in AVG so far:
    crack.exe
    serial.exe
    number.exe
    danuisoft_wma_mp3_co
    tiny.nfo.viewer.exe
    danuisoft.wma.mp3.co

    My spybot scan said to check error.log file. So I did that. Here is what that says:
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>


    I'm not sure where to go from here. I would greatly appreciate if someone would be able to point me in the right direction. THanks!

  2. #2
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    abbygayle:

    What version of Spybot are you running (Spybot » Help » About)?

    If you are not running Spybot 1.5.2.20 or above, upgrading to the latest version should solve the problem. To upgrade to Spybot 1.6 download the installation program from Mirror selection - The home of Spybot-S&D!.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  3. #3
    Junior Member
    Join Date
    Aug 2008
    Posts
    7

    Default

    ok, thanks for replying. i had 1.4 so i'm trying to update as suggested.
    but when i go to download i get an error that says:
    C:/programfiles/sypbot/search& destroy\plugins/tcpipaddress.dll

    an error occured trying to replace existing file
    delete filefailled;code 5
    access denied

    if i retry i get the same error. should i ignore? (not suggested according to error)?

  4. #4
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    abbygayle:

    Uninstall your old version and reboot the system before installing the new one.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  5. #5
    Senior Member
    Join Date
    Oct 2005
    Location
    Germany
    Posts
    5,263

    Default

    Hello,

    We recommend a fresh install of Spybot - Search & Destroy.

    Please uninstall Spybot - Search & Destroy according to the following link:
    http://www.safer-networking.org/en/howto/uninstall.html
    Then make a fresh install of Spybot - Search & Destroy 1.6.
    You will find links to several download locations on our website:
    http://www.safer-networking.org/en/mirrors/index.html

    You will also have to update your new version using the integrated updater.
    This should solve the problem.

    Best regards
    Sandra
    Team Spybot

  6. #6
    Junior Member
    Join Date
    Aug 2008
    Posts
    7

    Default

    ok,thanks i was able to scan spybot without any interruptions or references to the error.log file, but none of the trojans listed above were in the scan. just things from hitbox, fastclick, tradedoubler, adrevolver, burstmedia, casalemedia.

    Have I removed the trojan? Is there more I need to do?
    Also, should I remove the Danuisoft program if possible? WIll the trojan follow it around?

    if i go to the error.log again it has the following. i dont know if that means or anything or not.
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Delf.Spool.cn | <$SYSDIR>\ntdoss04.sys
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_SYSTEM>
    C:\Program Files\Spybot - Search & Destroy\Includes\Trojans.sbi | Win32.Agent.frl | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | FlashExploit | <$WINDIR>\Tasks\SysFile.brk
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger | <$FILE_EXE>
    C:\Program Files\Spybot - Search & Destroy\Includes\TrojansC.sbi | Zlob.DNSChanger.rtk | <$FILE_EXE>

  7. #7
    Junior Member
    Join Date
    Aug 2008
    Posts
    7

    Default

    i'm not sure how to edit the above post, but i should clarify that the last scan was done with a clean version of spybot s&D 1.6

  8. #8
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    abbygayle:

    Quote Originally Posted by abbygayle View Post
    i'm not sure how to edit the above post, ...
    You can't edit posts in this forum after 15 minutes.

    Quote Originally Posted by abbygayle View Post
    ok,thanks i was able to scan spybot without any interruptions or references to the error.log file, ... Have I removed the trojan?
    There were no Trojans. What you were getting were detection rule errors in the Trojans.sbi and TrojansC.sbi files being reported by the old version of Spybot because some of the new detection rules are incompatible with that old version.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

  9. #9
    Junior Member
    Join Date
    Aug 2008
    Posts
    7

    Default

    i see, thank you...

    i know this is a spybot forum but if i dont have any trojans do you know why my avg would list all of those same things (see first post) under infections?

    if i did, indeed, have a trojan, would spybot have listed it and fixed it?

    thanks again for your help.

  10. #10
    Spybot Advisor Team [Retired] md usa spybot fan's Avatar
    Join Date
    Oct 2005
    Posts
    5,859

    Default

    abbygayle:

    Quote Originally Posted by abbygayle View Post
    i see, thank you...

    i know this is a spybot forum but if i dont have any trojans do you know why my avg would list all of those same things (see first post) under infections?

    if i did, indeed, have a trojan, would spybot have listed it and fixed it?

    thanks again for your help.
    What version of Spybot - Search & Destroy are you currentally running (Spybot » Help » About)?

    I personally do not use Grisoft's AVG and you did not include a log of the detections by AVG, so I am at a loss to answer that question.

    The errors that you posted were primarally the failure of rootkit checks (hidden file checks) that fail in versions of Spybot below Spybot 1.5.2.20.

    Assuming you are running Spybot 1.6.0.30, if the rootkits actually existed with a scan using Spybot 1.6.0.30, Spybot should have detected them.

    Getting an answer is one thing, learning is another.


    Microsoft Windows XP Home Edition running on a 2.40GHz Intel® Pentium® 4 Processor with 512 MB of RAM and a 533 MHz System Bus.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •