Jump to content

64-Bit Windows 7 infected with Trojan.Dropper:Win32/Dunik!rts


Recommended Posts

Hello, I am running the 64-bit Edition of Windows 7 Premium (OEM). I have recently been infected by what Windows Security Essentials identified as "Trojan.Dropper:Win32/Dunik!rts". I am able to remove it, and the trojan is unable to deliver its payload due to being auto-quarantined by Windows Security Essentials (thus, no pop-ups, CPU clogging, or redirecting). However, it regenerates itself every time I reboot the machine. I can continue to remove it, but it keeps coming back.

I asked for advice here because of two reasons.

a). Windows Security Essentials is the only antivirus I have been able to detect this virus with. Malwarebytes' Anti-Malware has been unable to detect it, even after updating to the most recent database.

b ). ComboFix, my usual heavy-duty utility, is not designed for 64-bit OSes, and thus I am afraid to run it.

Included is a HijackThis log, as per protocol. Thank you.

hijackthis_9_08_2010.txt

Link to post
Share on other sites

Hi,

ComboFix, my usual heavy-duty utility, is not designed for 64-bit OSes, and thus I am afraid to run it.

Please note: ComboFix is an extremely powerful tool which should only be used when instructed to do so by someone who has been properly trained. ComboFix is intended by its creator to be "used under the guidance and supervision of an expert". It is NOT for unsupervised use. Please read Combofix's Disclaimer.

Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Check the box that says Scan All Users.
  • Download the following file scan.txt to your Desktop. Click here to download it. You may need to right click on it and select "Save"
  • Double click inside the Custom Scan box at the bottom
  • A window will appear saying "Click Ok to load a custom scan from a file or Cancel to cancel"
  • Click the Ok button and navigate to the file scan.txt which we just saved to your desktop
  • Select scan.txt and click Open. Writing will now appear under the Custom Scan box
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic

Link to post
Share on other sites

  • 2 weeks later...

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.