?
Solved

clean trojan psw in win-7

Posted on 2010-11-20
6
Medium Priority
?
928 Views
Last Modified: 2013-11-30
How to remove Trojan PSW infected objects in Win-7 environment?
0
Comment
Question by:wimbre042
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 32

Accepted Solution

by:
willcomp earned 2000 total points
ID: 34180336
Trojan PSW is a generic term for password stealing trojans and encompasses a number of different variants.

Do you have a more specific description and which AV program identified it?

Without further information, I recommend that you try using MalWareBytes AntiMalware (MBAM). The free version is sufficient. http://www.malwarebytes.org/mbam.php

0
 
LVL 14

Expert Comment

by:leoahmad
ID: 34180359
1) The associated processes of  Trojan-PSW.Win32.LdPinch.arxm to be stoped are listed below:

   %Temp%\dzp1.tmp\PPTVIEW.EXE


2) The registry entries of Trojan-PSW.Win32.LdPinch.arxm that need to be removed are listed as follows (Take Note: Back up the Windows registry before editing it, so that you can quickly restore it later if something goes wrong.):

    %Temp%\dzp1.tmp\INTLDATE.DLL
    %Temp%\dzp1.tmp\msvcm80.dll
    %Temp%\dzp1.tmp\msvcp80.dll
    %Temp%\dzp1.tmp\MSVCR80.dll
    %Temp%\dzp1.tmp\OGL.DLL
    %Temp%\dzp1.tmp\PPVWINTL.DLL
    %Temp%\dzp1.tmp\SAEXT.DLL
    %Temp%\dzp1.tmp\microsoft.vc80.crt.manifest
    %Temp%\dzp1.tmp\PPTVIEW.EXE
    %Temp%\dzp1.tmp\pptview.exe.manifest
    %Temp%\dzp1.tmp\[filename of the sample #1 without extension].pps
0
 

Expert Comment

by:alfaro
ID: 34180394
If this infection is stopping you from running Malwarebytes or other cleaners then Combofix is worth trying. http://www.bleepingcomputer.com/download/anti-virus/combofix

If you can't run Combofix or any spyware/virus programs because of this infection i often remove the drive and install it in another computer and manually remove the entries such as those shown above, or by running something like Malwarebytes and scanning the drive in that other computer. Just select the drive letter assigned (say G for arguments sake) and that should remove it.

Software like Knoppix or Bart's PE are also good for booting the infected machine and removing the infection manually that way.
0
Learn how to optimize MySQL for your business need

With the increasing importance of apps & networks in both business & personal interconnections, perfor. has become one of the key metrics of successful communication. This ebook is a hands-on business-case-driven guide to understanding MySQL query parameter tuning & database perf

 
LVL 32

Assisted Solution

by:willcomp
willcomp earned 2000 total points
ID: 34180412
ComboFix (CF) will not run on a 64 bit OS. If you have 64 bit Win7, CF is not an option.
0
 

Author Closing Comment

by:wimbre042
ID: 34181084
Recovery: Installed MBAM from flash drive while in SAFE Mode. Fullscan located 1 Trojan, e.g., SecurityTool Fraud!Gen4 --- deleted file
Rebooted and installed Norton Anti-Virus 2011 -- repeated scan and located Variant Trojan -- 05367.exe in the following directory: Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Security Tool.lnk which pointed to SecurityToolFraud!Gen4
Norton QUARANTINED the file 05367.exe

ComboFix would not work as stated, e.g., 64Bit processor

Problem is resolved -- Thanks
0
 
LVL 32

Expert Comment

by:willcomp
ID: 34181212
Glad you got it resolved.

MBAM is a valuable tool in fighting malware. I do recommend that you run it in normal mode when possible or use safe mode with networking to allow for installing updates.
0

Featured Post

Ransomware Attacks Keeping You Up at Night?

Will your organization be ransomware's next victim?  The good news is that these attacks are predicable and therefore preventable. Learn more about how you can  stop a ransomware attacks before encryption takes place with our Ransomware Prevention Kit!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
I previously wrote an article addressing the use of UBCD4WIN and SARDU. All are great, but I have always been an advocate of SARDU. Recently it was suggested that I go back and take a look at Easy2Boot in comparison.
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Finding and deleting duplicate (picture) files can be a time consuming task. My wife and I, our three kids and their families all share one dilemma: Managing our pictures. Between desktops, laptops, phones, tablets, and cameras; over the last decade…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question