Nothing is working, I need help with a trojan/worm

I went to the sticky “What to do if a file is infected” and wrote down all the info I could. I’m just letting you guys know that I know next to nothing about computers so I don’t know how to fix this and won’t understand technical words.

Anyways:

  1. Manual scan one folder with Avast Home Edition. Upon end of download of installation files.
  2. Downloaded from isohunt.com from http://torrents.suprnova.org/1158247/Corel.Paint.Shop.Pro.Photo.X2.v12.0.Multilingual.RETAIL.PROPER.R.1158247.SN.torrent
  3. Today, October 06, 2007, 2:17:03 AM
  4. C:\Documents and Settings\Owner\My Documents\BitTorrent Downloads\Corel.Paint.Shop.Pro.Photo.X2.v12.0.Multilingual.RETAIL.PROPER.READ.NFO-NoPE\setup\PSPP12_Corel_Retail_PF_EN_IE_FR_DE_ES_IT_NL_ESD.exe\WinOS.hlp
  5. Win95:LXD-mIRC [trj]
    Trojan Horse
    000778-5, 10/06/2007

C:\Documents and Settings\Owner\My Documents\BitTorrent Downloads\Alcohol.120.v1.9.6.4719.Retail.WinALL.Cracked-BETAMASTER\Alcohol120_retail 196.4719.exe
Win32:Rbot-ETN [trj]
Trojan Horse
000778-5, 10/06/2007

C:\Documents and Settings\Owner\My Documents\BitTorrent Downloads\Corel.Paint.Shop.Pro.Photo.X2.v12.0.Multilingual.RETAIL.PROPER.READ.NFO-NoPE\setup\PSPP12_Corel_Retail_PF_EN_IE_FR_DE_ES_IT_NL_ESD.exe\Advisory.nfo
VBS:Malware [Gen]
Virus/Worm

Win32:Trojan-gen. {UPX!}

Win32:Hidewindows-B [Tool]
Other potentially dangerous program

The scan stops at 20 files tested.

I tried scanning it at the jotti.org site too but it wouldn’t upload.

I also tried using the virus remover tool but it said it couldn’t scan that file.

If this is correct you downloaded a cracked application and that besides it moral and legal implications if often accompanied by an unwanted gift in the form of a trojan.

C:\Documents and Settings\Owner\My Documents\BitTorrent Downloads\Alcohol.120.v1.9.6.4719.Retail.WinALL.Cracked-BETAMASTER\Alcohol120_retail 196.4719.exe

If the files were sent to the chest than you can’t upload them from there because it is a protected area, you have to export them from there to a temporary location (never to the original location). Though I would have thought that many BitTorrent downloads are somewhat suspect when you are downloading what are in effect retail software whit the obvious possibility of downloading a hacked/cracked piece of software with a trojan in it.

The virus removal tool you should have noticed on the page where you downloaded it only works with real viruses and worms and only a select group. It is also included in the main avast program and if a detection is found that can be trated with the removal tool it would be called by avast.

So beware of cracked.hacked software as there is a high likelihood of it being infected besides the moral/legal issues.

It didn’t get moved to the chest because it made my virus software stop working when I try scanning that file.

Suggest you to use online scanning

Hi, welcome to the forum. Since you’ve identified some of your problems, your time may be better spend downloading and scanning with avg antispy http://www.ewido.net/en/download/ and superantispyware http://www.superantispyware.com/ . Quarintine anything found.

Clear your temp files.There will probably be more to do, but this will at least clean up your system somewhat.

Are all the infected files still in C:\Documents and Settings\Owner\My Documents\BitTorrent Downloads\ … or are you finding them in other locations?

Have you run any of the installation files?

My scanware finally ran all the ways through and cleaned it up. Thanks though!


This site … isohunt … is certainly one everyone should stay away from. >:(


Because of the illegality?

Well that and the free parting gifts you can pick up. :wink: