Hello, I am quite unfamiliar with trojans and virus removal-- assistance on this would be greatly appreciated! I have contacted the Kaspersky Virus Labs and have yet to receive a response, so I came here.

Yesterday 5/17/10 my Kaspersky Anti-virus 2009 (Kaspersky Internet Security 8.0.0.454 running on Windows Vista) gave about 8 different responses to a detected trojan. 4 of them were deleted and 4 were postponed and untreated. I am unsure what this means. They all originate from the same two files-- where I rebooted my computer in safe mode, after it disinfected, and deleted the folders which only contained "note/readme" files.

I have attached a screenshot of the reports.

Also I have reports of "detected vulnerabilities", but my computer has been running fine with those up until this point where these trojans have been detected.

From what I can tell my computer is running normally, if not a tad slow on the internet (connection here is shoddy), and I have rescanned my computer, but nothing is detected.

I am still worried-- I have read that malware and trojans can hide in the system reboot(?).

What does this particular trojan-- Trojan.Win32.Buzus.Eaji-- do? Where does is originate from (as in how did it get on my computer)? How can I be sure the trojans have been removed?

Hello, and welcome to GeekPolice.

• From this point on, please do not make any more changes to your computer; such as install/uninstall programs, use special fix tools, delete files, edit the registry, etc. - unless advised by the staff I noted above.
• Please do not ask for help elsewhere (in this site or other sites). Doing so can result in system changes, which may not show up in the logs you post.
• We try our best to reply quickly, but for any reason we do not reply in two days, do one of two things:

Reply to this topic with the word BUMP, or
• Lastly, keep in mind that we are volunteers, so you do not have to pay for malware removal. Persist in this topic until its close, and your computer is declared clean.

See the area: Using ComboFix, and when done, post the log back here.

[You must be registered and logged in to see this link.]

See the area: Using ComboFix, and when done, post the log back here.

Ok. Bump.

I'm sorry, the message stated to persist until my computer was free of problems. I still have yet to receive an answer to my original query-- I've never encountered a trojan and I am worried about the damage it may do to my computer.

I won't bump again, I will continue to wait patiently until I get feedback. Sorry about that.

The trojan you write above is a backdoor trojan which gets distributed through email/greeting card messages.

It is also a worm downloader, which installs a worm on to your computer, so it can successfully spread the same trojan to other computers through the means of USB devices, network transfer, etc.

Lastly, it tweaks certain settings in Windows to reduce its functionality, making it rather difficult to remove.

Does that sum it up?

Does that sum it up?

Ah, the Kaspersky will not download because I already have Kaspersky Internet Protection 8.0, so should I disable Kaspersky and try again?

Please run a free online scan with the ESET Online Scanner
• Click Start
• When asked, allow the ActiveX control to install
• Click Start
• Make sure that the options Remove found threats and the option Scan unwanted applications is checked
• Click Scan (This scan can take several hours, so please be patient)
• Once the scan is completed, you may close the window
• Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
• Copy and paste that log as a reply to this topic

Copy and paste that log as a reply to this topic

