Serious Trojan Question

Xath

Honorable
May 10, 2013
1
0
10,510
Hello, all.

I somehow had a trojan on my system in the last two days, and am not completely sure it actually hit my system or if it was totally removed. Just to put my mind at ease, I wanted to ask your opinions.

I've no idea how I even got it, as I'm always running MSE and have ABP on with FF (except once, it had to be turned off in order to deal with AdSense's webpage which doesn't work with it on) but it doesn't appear to have actually hit my system and I deleted it with MSE.

The trojan was: Win32/Urausy.C which is supposedly a bad trojan.

However, I had absolutely no symptoms.

I only found it because I happened to scan, which I do about every two days.

It was located nowhere else except in the \Users\AppData\Temp folder, two strings of it in the temp folder: 0xthqGPE.exe.part and tqcfHDY.exe.part and located nowhere else.

Supposedly, it will show up in the following ways:

- massive pop-up page that blocks you from your system as "ransomware" and you're unable to get past it
I never had this happen.

- runs as a process "random.exe"
I did not have this process running.

- registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\Trojan:Win32/Urausy.C
I did not find it anywhere in the registry.

- several places it's said to show up (all AppData folder locations), but I found absolutely no evidence of it anywhere

I removed it with MSE and have seen no sign in any Reg key or folder I've looked in, but supposedly it can also attack kernels on your system and it's good at hiding itself.

I think that's my biggest concern, if it attacked a kernel somewhere that cant be seen.

I also scanned with MBAM and it found nothing. Looked manually through everything but found nothing.

But, since it was only found in a temp folder, and no other places, signs or symptoms, I wanted to ask if people thought it had been caught before it hit my system and if MSE actually trashed what there was of it on my system.

I'm trying to avoid reformatting (I just recently did) but if I need to, I will.

Thanks in advance for you opinions/advice.
 

namdlo

Honorable
Jun 20, 2012
451
0
10,860
I think as with any virus/malware you're assuming the risk that you've completely removed it if you don't reformat. In my experience "single" infections within the temp directories "typically" don't cause as much concern as infected system files.

You're the only person that can weigh the risk/"reward" of not reformatting.
 

gamingboy

Honorable
May 5, 2012
257
0
10,810
If you did a full scan with MBAM, then you're probably clean. But if you have the time and the patience to format and re-install windows, then you might want to do that. But it's not completely necessary.
 
If you have the file but the the symptopms, it might be in a dormant state so you might not of suffered any damage.

Just to be sure run malwarebytes /roguekiller

and do eset / kapersky online scan. If you got nothing more from there I would not worry.

Also you should get rid of java and its file
(delete manually by searching for java and sun. but just delete installation folder and temps folders, not the scripts or folder found in other programs such as pdf.)