Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 26th, 2004, 05:10 AM
marvik marvik is offline
Infrequent Poster
 
Join Date: Jan 2004
Posts: 3
Default Trojan - win32/psw.narod

Ran Nod32 on WinXP - results showed a Trojan called win32/psw.Narod. Nod32 could not remove the malware - a general search on the net points to Nod32 site but they don't have anything on this trojan.
I've done a lot searching but can't find anything. Does anyone know what this Trojan is, what it does and most importantly - how to get rid of it?
Thanks a lot - Marv


  #2  
Old January 26th, 2004, 05:17 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,718
Default Re:Trojan - win32/psw.narod

Hi marvik,

Welcome at Wilders.
Do you have a filename for the file that NOD flags as the trojan?
Maybe that helps.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #3  
Old January 26th, 2004, 05:29 AM
marvik marvik is offline
Infrequent Poster
 
Join Date: Jan 2004
Posts: 3
Default Re:Trojan - win32/psw.narod

The best I can find is (I don't know if this will help much)
File C:\WINDOWS\SYSTEM32\systemie.exe is infected with trojan Win32/PSW.Narod.A.
File C:\WINDOWS\SYSTEM32\sysie.dll is infected with trojan Win32/PSW.Narod.A. NOD32 cannot clean this infiltration.
trojan Win32/PSW.Narod.A found in operating memory.

Thanks
Marv
  #4  
Old January 26th, 2004, 05:40 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,718
Default Re:Trojan - win32/psw.narod

Hi Marvik,

Sure it helps.
Please copy the part in bold belwow to Notepad. Name the file as keylogbegone.reg (set it to save as all files). Double click on keylogbegone.reg and confirm you want to merge it with the registry.
This will prevent it from starting at next boot.

***
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3D1228C9-F556-4158-BC0B-D3FF4F3F3E1B}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
"systemie"=-***


Reboot after doing so, preferably into safe mode and delete:

systemie.exe
sysie.dll
systemie.dll
systemie.dat

After it is removed you will need to change any passwords and all passwords or sensitive infomration you may have typed into a form. This is a Keylogger and that information could have been transmitted to someone.

Regards,

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #5  
Old January 26th, 2004, 06:08 AM
marvik marvik is offline
Infrequent Poster
 
Join Date: Jan 2004
Posts: 3
Default Re:Trojan - win32/psw.narod

Thanks a lot! I'll do it now.
Marv
  #6  
Old January 26th, 2004, 06:13 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,718
Default Re:Trojan - win32/psw.narod

OK. Keep us posted.

Pieter
__________________
Regards,

Pieter
Itīs nice to be important, but itīs more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #7  
Old January 27th, 2004, 10:38 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re:Trojan - win32/psw.narod

http://vil.nai.com/vil/content/v_100477.htm


Narod is a password stealing trojan

removal info at the link.
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #8  
Old January 27th, 2004, 11:02 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,605
Default Re:Trojan - win32/psw.narod


The mcafee stinger utilitie will remove pws narod can be downloaded at the link


http://vil.nai.com/vil/stinger/
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #9  
Old June 14th, 2004, 12:54 PM
bobby dias
 
Posts: n/a
Cool Re: Trojan - win32/psw.narod

I renamed systemie.exe to oldsystemie.exe and I renamed systemie.dll to
oldsystemie.dll, restarted the computer and then deleted oldsystemie.exe and
oldsystemie.dll. Never saw them again.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:33 PM.


Powered by vBulletinŪ Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright Đ2002 - 2013, Wilders Security Forums