Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need help after Avira suddenly found a trojan


  • This topic is locked This topic is locked
8 replies to this topic

#1 sn0w

sn0w

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:50 PM

Posted 03 May 2017 - 04:15 PM

Hello everyone,
 
today while using Wallpaper Engine (I started a video downloaded from the steam workshop) I suddenly got a virus alert from Avira stating that "h264encoder.exe" is supposed to be infected by a trojan named "TR/Swrort.cgyml". I don't know if it was just random timing or if it has something to do with Wallpaper Engine or the video. I've had the encoder on my PC for almost a year now, though I didn't really use it, and never had any similar issues. The object is now quarantined. While Avira was doing a quick scan like it always does after finding a threat, I got a warning about a "suspicious file" in my temp folder: "jre-8u131-windows-au.exe". I don't know how that one got there, but that might just have been part of me installing Netbeans a couple of days ago.
 
Anyway, when I google the name of the trojan ("TR/Swrort.cgyml") I can't find any entries that have to do with my issue at all. There is also no entry on the Avira Virus Lab website. When I check the report it also says something along the lines of "FP-Server reports status "NO false alarm" (I'm German so I don't know what it actually says in the English version). But it apparently said the same thing about Tom Clancy's Rainbow 6 once too which obviously was a false-positive.
 
 
 
By the way, I am using Windows 7 x64. I've already run a free scan with MBAM which found nothing, but I assume that it was just a quick search. I'm currently doing a full scan using Avira but that seems to be taking a lot of time... Also, that's why I haven't rebooted yet.
 
Another issue I've been having lately that might be worth mentioning is that getting into the login screen's been taking extremely long. I'm talking about the time where you usually might have a short black screen and then the login mask appears. I can only see my cursor on the black background for quite some time and after waiting half a minute or so (at least it feels like it) I get to the login screen. Furthermore, I have the non-aero cursor for some reason.
 
Well, that's about it. I'm really paranoid that my PC is still infected or has been the whole time. I also thought about it being some kind of weird false-positive but I would really appreciate some help with this issue. Thank you for taking your time :)
 
PS: As mentioned above, I'm not a native English speaker so I hope you're able to figure out what I'm trying to say. Also, this is my first time posting, so I hope I did everything correctly. If not please point out anything I can do to make myself or my problem more clear.
 
Thanks a lot!


BC AdBot (Login to Remove)

 


#2 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:50 PM

Posted 04 May 2017 - 04:17 AM

Hello sn0w and welcome to Bleeping Computer.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please follow these instructions in the order given.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

Please download Junkware Removal Toolto your desktop.
  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista/7/8/10, instead of double-clicking, right-mouse click JRT.exe and select ‘Run as Administrator’
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

================================================

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt


Thanks

Satchfan


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#3 sn0w

sn0w
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:50 PM

Posted 04 May 2017 - 02:15 PM

Hello satchfan,

 

thank you for replying. I have a quick question before I proceed with the scans. How am I supposed to upload them? Should I attach them or something or just paste them as a reply?



#4 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:50 PM

Posted 04 May 2017 - 03:08 PM

Please just copy/paste them into your reply.


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#5 sn0w

sn0w
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:50 PM

Posted 06 May 2017 - 03:35 PM

First of all, sorry for not replying earlier It's been a kinda stressful week.

 

I uploaded the quarantined files to the Avira Virus Lab as it might have just been a false-positive. I received a mail in which they stated that the file is supposedly clean. When I rescanned it nothing was found, so I guess it was just a false-positive. Not sure if I should still post the logs since no program found anything. The only bad thing left is the extremely long black screen before I get to see the login screen with an aero-themed mouse cursor.



#6 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:50 PM

Posted 06 May 2017 - 04:26 PM

I'm glad that that problem is no longer showing up but it would still be worth running those scans to be sure that nothing else has caused it.

 

If want to do so I'll keep this open.

 

If I hear nothing in 24 hours I'll assume that all is well and close the topic.

 

Satchfan


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#7 sn0w

sn0w
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:50 PM

Posted 06 May 2017 - 04:33 PM

Like I said the problem having that long loading screen still occurs, but that should be another issue I'll somehow have to figure out. I've already run all scans but they didn't find anything worth mentioning I guess. Do you still want to look at any of the logs?



#8 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:50 PM

Posted 06 May 2017 - 04:53 PM

Yes please.


My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.


#9 satchfan

satchfan

  • Malware Response Team
  • 2,659 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Devon, UK
  • Local time:03:50 PM

Posted 08 May 2017 - 02:15 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

My help is always free of charge. If you are happy with the help provided, if you wish you can make a donation to buy me a beer.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users