blog of Guganeshan.T

June 4, 2008

Infected with a Trojan

Filed under: Featured Articles,Privacy and Security — Tags: , , , — Guganeshan.T @ 1:01 pm
  1. Do you see one or more of the following files getting created in the root of every drive you access?:
    • autorun.inf
    • autorun.ini
    • fun.exe
    • download.exe
    • coursework.exe
    • crazya.exe
    • oalvm.com [EDITED ON 10th JUNE]
  2. Do you see any of the executables mentioned above (the ones with the .exe or .com extension) running in the ‘processes’ list of the task manager?
  3. Do you get an ‘Open with’ dialogue box when you double-click a drive in “My Computer”, instead of it getting opened?
  4. Do you see any of the above mentioned executable files in the “C:\Documents and Settings\All Users\Application Data” folder?
  5. Do you see the words: “gods must be creazy” in the title bar of Internet Explorer? yeah you read it right, it must be written as “crazy” but the creator has written it as “creazy”! 🙂

Then its time to panic! (a little). Because the computer is infected with a Trojan…

I am used to the practice of suspending anti-virus software to conserve memory (specially when using memory intensive software like Microsoft Visual Studio) and got the computer infected with a Trojan when I shared my thumb drive with another person!

I thought its just a poor old Trojan that I can remove in a second using the existing anti-virus software, but it didn’t even detect it.

Terminating the process named crazya.exe was impossible (I even tried the “TaskKill” DOS command repeatedly in a loop with the /f option to force the termination, but no use.

The biggest surprise came when I Googled the file name “crazya.exe”… I got only 7 results in Google!. Out of which, 1 is from a Chinese web site, and 1 from Sri Lanka itself. That meant trouble for me because it means, either it has no cure or its a new Trojan. But I confirmed its a Trojan only from those 7 results I found (Non of them had a tool to clean it… but one of them mentioned the well-known HijackThis diagnostic tool)

One site named it as: “Trojan horse Generic8.GHY”. And another one said its from the malware group named: “Trojan.agent.gen”.

Anyway, what I did to get rid of it was:

  1. Ran HijackThis (its a free diagnostic tool)
  2. In the list of processes and registry entries it lists, I selected all the entries that had the word “crazya.exe” (other executable names were not there for me)
  3. Clicked on the “Fix Checked” button
  4. Deleted the files I mentioned, manually from the root of every drive

That’s it… it was gone.

Warning: They recommend users to create a HijackThis log from the tool and to post it in anti-adware/malware forums to let the experts diagnose the problem. If you don’t know what you are doing, you might delete important registry entries using the excellent HijackThis tool.

[EDIT: In another PC, HijackThis tool alone was not enough, and I had to restart the PC in ‘Safe Mode’ and delete the files (mentioned at the beginning of the post) in the root of every drive. Because the files were running in memory.]

Hope this helps someone

UPDATE [on 10th February 2009]:

I tried the latest “Kaspersky Anti-Virus 2009 Free 30 Day Trial” with an infected thumb drive, and the software detects and deletes the Trojan files. Hope this helps someone (download and try the Kaspersky Anti-Virus 2009 free trial from “trials” page here: http://www.kaspersky.com/trials

And thank you very much for the comments.

5 Comments »

  1. HEY…. Great post there. I have the same stupid virus and its really buggin me. Nice to see you are a lankan too. I live in SL as well

    Comment by Mahela007 — August 16, 2008 @ 11:50 am

  2. Thanks Mahela007,

    My opinion is, it is best to use a tool such as “SpyBot Search And Destroy” (which is free) to protect against any unknown threats (While also having an anti-virus tool). It will prevent many headaches for you.

    Comment by Guganeshan.T — August 19, 2008 @ 7:18 am

  3. hey! thanx a lot 4 ur post man! did help me finding out wt was wrng with my machine…. had i not found this, must have lost my head!!!

    Comment by Nouman — November 20, 2008 @ 7:05 pm

  4. You are welcome Nouman… hope you manage to get rid of it.

    Comment by Guganeshan.T — November 26, 2008 @ 8:05 am

  5. Hey!! Thank you so much for this entry. I have been getting the gods must be creazy thing too and it’s been very annoying. I have had 4 antiviruses AND spybot and none of them caught it :s

    Am downloading HJT now. Thank you again

    Comment by darkmanifestation — February 8, 2009 @ 4:41 am

RSS feed for comments on this post. TrackBack URL

Leave a comment

CommentLuv badge

Powered by WordPress