Windows Vista Forums

kaspersky found trojan virus
  1. #1



    Banned
    Join Date : Sep 2010
    Posts : 10
    vista home premium 32 bit
    Local Time: 08:03 AM

    kaspersky found trojan virus

    kaspersky found a trojan virus in c:\windows\system32\services.exe and when i try to neutralize it nothing happens and i've scanned that file myself and it finds nothing and i did a full scan as well and finds nothing. So what can i do?

    attached is hijackthis log with my pc info.


      My System SpecsSystem Spec

  2. #2
    Jacee's Avatar

    Security


    Join Date : May 2010
    Posts : 676
    Windows 7 Ultimate Vista Business SP2
    Local Time: 05:03 AM
    usa us washington

     

    Re: kaspersky found trojan virus

    twex.exe is a variant of ZBot, which is a password and personal information stealer.

    First let's flush your DNS cache, and restore MS's original Hosts file.

    Copy and paste these lines in Note pad.
    @Echo on
    pushd\windows\system32\drivers\etc
    attrib -h -s -r hosts
    echo 127.0.0.1 localhost>HOSTS
    attrib +r +h +s hosts
    popd
    ipconfig /release
    ipconfig /renew
    ipconfig /flushdns
    netsh winsock reset all
    netsh int ip reset all
    shutdown -r -t 1
    del %0


    Save as flush.bat to your desktop. Right click on the .bat file and run as Administrator. Your computer will reboot itself.

    After rebooting download Malwarebytes' Anti-Malware to your desktop
    |MG| Malwarebytes Anti-Malware 1.46 Download
    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform full scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.

    * When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.

      My System SpecsSystem Spec

  3. #3



    Banned
    Join Date : Sep 2010
    Posts : 10
    vista home premium 32 bit
    Local Time: 08:03 AM


      Thread Starter

    Re: kaspersky found trojan virus

    Hey thanks for your response, i was just wondering if that malware program would interfere with kaspersky, which i have

      My System SpecsSystem Spec

  4. #4



    Account Suspended

    Join Date : Aug 2010
    Laytonsville, Maryland, USA
    Posts : 2,212
    Vista Business 32bit SP2 (build 6002)
    Local Time: 07:03 AM
    usa us maryland

     

    Re: kaspersky found trojan virus

    Malwarebytes runs with pretty much every AV program I've ever heard about with no problems (unlike many or maybe even most other programs). But make sure that Kaspersky isn't scheduled to do a scan at the same time that you run the Malwarebytes scan (it wouldn't be good to run both scans at the same time - I don't know that it would cause a problem, but let's avoid it just to be on the safe side). Keep in mind it could take a few hours for a full scan depending on the amount of data you need to scan on however many drives/partitions you need to scan. You're safe running it without disabling or uninstalling Kaspersky.

    Remember, Malwarebytes is just scanning and then it can remove what it finds - it is not operating in real time to protect your system so you should definitely leave Kaspersky enabled even during the Malwarebytes scan if you intend to go online (just make sure it isn't scheduled to scan and if so, disable the scan or delay it or whatever is necessary to keep it from starting until the Malwarebytes scan is complete).

    In fact, you may want to keep Malwarebytes installed and update and run Malwarebytes every few weeks or month or so just as a backup to catch anything that might have been missed. I do that myself (though my primary program is MSE). It rarely catches anything because MSE is very good, but sometimes it does and so I'm happy to have it and glad I have this good habit.

    I hope this helps and that the above suggestions and Malwarebytes resolve the problem. If not, there are other options available - so don't worry, we'll get rid of this infection (and perhaps other infections not noticed at the same time). The mere fact that it has been idenfied is an excellent sign as solutions for identified variants are easier to locate and are often included in some of the more common anti-malware tools already. I suspect that may be at least one of the reasons why this product was recommended (besides the fact that it is very good in general).

    Good luck!

    Last edited by Lorien; 05 Sep 2010 at 02:23 PM. Reason: clarification
      My System SpecsSystem Spec

  5. #5



    Banned
    Join Date : Sep 2010
    Posts : 10
    vista home premium 32 bit
    Local Time: 08:03 AM


      Thread Starter

    Re: kaspersky found trojan virus

    Thank you for your response lorien. I ran malwarebytes and it did find 6 infected objects which i removed.

    Here is the log from it like Jacee asked, attached

      My System SpecsSystem Spec

  6. #6



    Account Suspended

    Join Date : Aug 2010
    Laytonsville, Maryland, USA
    Posts : 2,212
    Vista Business 32bit SP2 (build 6002)
    Local Time: 07:03 AM
    usa us maryland

     

    Re: kaspersky found trojan virus

    I'm nowhere near a malware cleanup expert so I have nothing to offer here in terms of resolving the problem when someone like Jacee is already involved, but from viewing other threads on the subject, the expert often likes to see another MBAM log after the cleanup (if something was found) to confirm that nothing else is found or remains. Perhaps while waiting for Jacee, you could re-run MBAM and attach an updated log to verify how it now looks after the cleanup. I'm in no way trying to take over her job here - I'm just suggesting something to do while awaiting her reply that may assist her (and shouldn't be much trouble to do).

    I hope this helps both of you.

    Good luck!

      My System SpecsSystem Spec

  7. #7
    Jacee's Avatar

    Security


    Join Date : May 2010
    Posts : 676
    Windows 7 Ultimate Vista Business SP2
    Local Time: 05:03 AM
    usa us washington

     

    Re: kaspersky found trojan virus

    Change all your passwords using a known 'clean' computer. Do not use the infected one to do this.

    Please download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.

    Save any unsaved work. TFC will close ALL open programs including your browser!
    Using Vista/Windows 7 right-click on the file and choose Run As Administrator.
    Click the Start button to begin the cleaning process and let it run uninterrupted to completion.

    Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

    TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder. It also cleans out the %systemroot%\temp folder and checks for .tmp files in the %systemdrive% root folder, %systemroot%, and the system32 folder (both 32bit and 64bit on 64bit OSs). It shows the amount removed for each location found (in bytes) and the total removed (in MB). Before running, it will stop Explorer and all other running apps.
    TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. Depending on how often someone cleans their temp folders, their system hardware, and how many accounts are present, it can take anywhere from a few seconds to a minute or more. TFC will completely clear all temp files where other temp file cleaners may fail.

    Rescan with Malwarebytes' and post a fresh log.

      My System SpecsSystem Spec

  8. #8



    Banned
    Join Date : Sep 2010
    Posts : 10
    vista home premium 32 bit
    Local Time: 08:03 AM


      Thread Starter

    Re: kaspersky found trojan virus

    OK done. Is it really necessary for me to do another full malwarebyte scan since it deleted everything it found already, just wondering.

      My System SpecsSystem Spec

  9. #9
    Jacee's Avatar

    Security


    Join Date : May 2010
    Posts : 676
    Windows 7 Ultimate Vista Business SP2
    Local Time: 05:03 AM
    usa us washington

     

    Re: kaspersky found trojan virus

    If it was my computer with a Zbot Trojan, I'd gladly run a deep scan again!

      My System SpecsSystem Spec

  10. #10



    Banned
    Join Date : Sep 2010
    Posts : 10
    vista home premium 32 bit
    Local Time: 08:03 AM


      Thread Starter

    Re: kaspersky found trojan virus

    Ok will do. Also do you know its a Zbot trojan from the virus i posted or from my hijack file and how certain is it/are you, just basically wondering about it thats all.
    running a new malware scan at the moment too

      My System SpecsSystem Spec

Page 1 of 3 123 LastLast
kaspersky found trojan virus problems?

Similar Threads
Thread Thread Starter Forum Replies Last Post
Kaspersky touts Anti-Virus for Mac. JMH System Security 0 10 Oct 2009
Kaspersky® Virus Removal Tool JMH System Security 0 28 Aug 2009
Kaspersky Virus Removal Tool JMH System Security 0 02 Aug 2009
Kaspersky Anti-virus Rodnod Vista General 27 07 Feb 2009