Register a free account
Posted 26 February 2011 - 04:11 AM

I stupidly opened a .exe file and instantly Avast! popped-up and told me there was a trojan but it took care of it, but every 5-10 seconds the trojan re-appears in C:/Windows/SysWOW64/Spynet as service.exe and Avast just keeps throwing it back into the vault.

I'm not too worried about it stealing my information.. i just need to know how to remove it permantly.

DDS (Ver_10-12-12.02) - NTFS_AMD64
Run by Nick at 4:10:07.05 on Sat 02/26/2011
Internet Explorer: 9.0.7930.16406 BrowserJavaVersion: 1.6.0_23
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4095.1040 [GMT -5:00]

AV: avast! Internet Security *Enabled/Updated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Internet Security *Enabled/Updated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: avast! Internet Security *Enabled* {FB460EB6-4C6D-E564-6BF5-EEEF2B44B473}

Thanks guys, i appreciate it.

EDIT: Please be patient. There are over 200 unanswered topics in this forum at present and the current average wait time to receive help is 7 days.

Posted 04 March 2011 - 09:55 AM

Hi XxNickTxX, and welcome to Bleeping Computer.

  • Please launch Malwarebytes' Anti-Malware, click the Update tab, and then Check for Updates.
  • Then choose the Scanner tab and select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Download OTL.exe by OldTimer to your Desktop.

  • Close all windows and double click OTL.exe.
  • In the "Custom Scans/Fixes" window (under the light green bar) paste the following in bold:

    %systemroot%\*. /mp /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click Run Scan and let the program run uninterrupted.
  • When the scan completes, it will open two Notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Post both logs in this thread.
  • You may need to use two posts to get it all.

Posted 04 March 2011 - 11:04 PM

Hey, thanks for the help.

I ran MBAM as instructed and came up with 131,000 infected files (That's alot i'm guessing). I got rid of all of them, restarted and it seemed to get rid of the problem. I don't want it coming back so i continued and ran OTL as instructed and it freezes when scanning my firefox settings...

I'm not sure if you want me to continue working on this as it SEEMS to be resolved (Not sure, i'd much rather be safe than sorry though.)

I've included a snippet of my log from MBAM, as it is litterly the same thing over and over again for 131,000 lines just with slightly different names.

Malwarebytes' Anti-Malware

Database version: 5954

Windows 6.1.7600
Internet Explorer 9.0.7930.16406

3/4/2011 8:13:34 PM
mbam-log-2011-03-04 (20-13-34).txt

Scan type: Quick scan
Objects scanned: 184388
Time elapsed: 57 minute(s), 48 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 131077

Posted 05 March 2011 - 05:52 AM

Hi again XxNickTxX!!.. :)

I ran MBAM as instructed and came up with 131,000 infected files (That's alot i'm guessing). I got rid of all of them, restarted and it seemed to get rid of the problem. I don't want it coming back so i continued and ran OTL as instructed and it freezes when scanning my firefox settings...

Yep, that's indeed a lot!!..
If you were using the latest version of OTL (, and no malware problem remains, I guess a fresh DDS scan will do...

So, firstly,
We need to update outdated programs (with security vulnerabilities) on your machine:

- Adobe Acrobat Reader:

You've got a PRO version installed of Adobe Acrobat:
Adobe Acrobat 9 Pro Extended - English, Franšais, Deutsch
Adobe Acrobat 9.3.4 - CPSID_83708

--> Help --> Check for updates - let it update to the newest version...

You've got also a free version of Adobe Reader 9.3.3 installed... I highly recommend you update it: --> Help --> Check for updates - let it update to the newest version... And, if possible, consider updating it to the tenth version:

Adobe Reader X

Note: I suggest you uncheck an optional, third-party download (eg. McAfee Security Scan Plus).

After successfully installing Adobe Reader X, see this article on how to make this program more secure: Adobe Reader X secures itself by playing in the sandbox.

- Java

Go to Start -> Control Panel -> Programs and Features, highlight a program to see the available option on the toolbar for it. Choose Uninstall for:
Java™ 6 Update 20
Java™ 6 Update 23

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says Java Platform, Standard Edition / "Java SE 6 Update 24".
  • Click the "Download JRE" button to the right.
  • In the Window that opens, select Windows, your Language, check the "agree" box and click Continue.
  • Click on the link to download Windows Offline Installation and save to your Desktop.
  • Close any programs you may have running - especially your web browser.
  • Then from your desktop double-click on jre-6u24-windows-i586.exe that you downloaded to install the newest version.

- Mozilla Firefox (3.6.13) --> Help --> Check for updates - let it update to the newest version - 3.6.15

- Adobe Flash Player:

To make sure you have the latest version of Adobe Flash Player installed:
1. To uninstall an older version, download this file to your Desktop: uninstall_flash_player.exe
2. Quit ALL running applications, including all Internet Explorer or other browser windows, and messenger applications (like AOL Instant Messenger, Yahoo Messenger, MSN Messenger.
3. Double-click on the file you've downloaded to uninstall Flash.
4. If uninstalled successfully, go to this site: Install Adobe Flash Player, and choose Agree and install now. This will install the newest version of Flash for your browser (note: Flash plugins for IE and Firefox must be installed separately).
Note: I recommend you uncheck an optional install (Free McAfee Security Scan or Free Google Toolbar).

Secondly, run an online scan:
Please run a free online scan with the ESET Online Scanner
Note: You will need to use Internet Explorer (32 bit version - Start --> All programs --> Internet Explorer) for this scan. Internet Explorer must be run as administrator - right click and choose: Run as administrator.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the ActiveX control to install
  • Click Start
  • Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  • Click Scan
    Wait for the scan to finish
  • Use Notepad to open the logfile located at C:\Program Files (x86)\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic

Run a fresh scan with DDS (as instructed in the FAQ), post the contents of DDS.txt in your reply (no need for Attach.txt)...
Posted 20 March 2011 - 03:40 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.
