• Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

MyAntiSpyware

Menu
  • Downloads
  • Threats
    • Adware
    • Browser Hijacking
    • Phishing
    • Ransomware
  • Questions and Answers
  • Recover Encrypted Files
  • Free Malware Removal Tools

How to remove sshnas.dll or sshnas21.dll trojan (Remove trojan FakeAlert)

Myantispyware team December 2, 2009    

sshnas.dll or sshnas21.dll is a component of trojan FakeAlert. The trojan come from malicious websites that ask users to download an Adobe Flash Player update or player needed to view a movie online. The filename of the trojan is flash-HQ-plugin. Once started, the trojan will download and install core components: c.exe, msa.exe and sshnas.dll (sshnas21.dll). When downloaded, it will be configured to start automatically when Windows starts. Trojan FakeAlert may display many popups and fake security alerts, hijack Internet Explorer, disable Windows Task Manager and Registry editor.Also it is usually installed in conjunction with a rogue antispyware programs.

If your computer is infected, then use these removal instructions below, which will remove sshnas.dll (sshnas21.dll) trojan and other components of trojan FakeAlert for free.

Symptoms in a HijackThis Log

O4 – HKCU\..\Run: [Videohost] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\c.exe
O4 – HKCU\..\Run: [SSHNAS] rundll32.exe C:\Windows\system32\sshnas.dll,DllWork
O4 – HKCU\..\Run: [LosAlamos] rundll32.exe C:\Windows\system32\sshnas.dll,AddConsoleAliasAW
O4 – HKCU\..\Run: [LosAlamos] rundll32.exe C:\Windows\system32\sshnas21.dll,AllocConsoleA
O4 – HKCU\..\Run: [Halo2] rundll32.exe C:\Users\username\AppData\Local\Temp\sshnas21.dll,GetMainWnd

Use the following instructions to remove sshnas.dll (sshnas21.dll) trojan and other components of trojan FakeAlert

Step 1.

Please download OTM by OldTimer from here and save it to desktop.

Run OTM. Copy, then paste the following text in “Paste Instructions for Items to be Moved” window (under the yellow bar):

:services
SSHNAS

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Videohost"=-
"SSHNAS"=-
"LosAlamos"=-
"Halo2"=-

:files
%windir%\msa.exe
%windir%\system32\sshnas.dll
%windir%\system32\sshnas21.dll
%windir%\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
%windir%\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

:Commands
[emptytemp]
[Reboot]

Click the red Moveit! button. When the tool is finished, it will produce a report for you. If you are asked to reboot the machine choose Yes.

Step 2.

Download MalwareBytes Anti-malware (MBAM). Once downloaded, close all programs and windows on your computer.

Double-click on the icon on your desktop named mbam-setup.exe. This will start the installation of MalwareBytes Anti-malware onto your computer. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to “Update Malwarebytes’ Anti-Malware” and Launch “Malwarebytes’ Anti-Malware”. Then click Finish.

MalwareBytes Anti-malware will now automatically start and you will see a message stating that you should update the program before performing a scan. If an update is found, it will download and install the latest version.

As MalwareBytes Anti-malware will automatically update itself after the install, you can press the OK button to close that box and you will now be at the main menu. You will see window similar to the one below.

malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Make sure the “Perform quick scan” option is selected and then click on the Scan button to start scanning your computer. This procedure can take some time, so please be patient.

When the scan is finished a message box will appear that it has completed scanning successfully. Click OK. Now click “Show Results”. You will see a list of infected items similar as shown below.
Note: list of infected items may be different than what is shown in the image below.

sshnas remover
Malwarebytes Anti-malware, list of infected items

Make sure all entries have a checkmark at their far left and click “Remove Selected” button. MalwareBytes Anti-malware will now remove all of associated Trojan FakeAlert files and registry keys and add them to the programs’ quarantine. When MalwareBytes Anti-malware has finished removing the infection, a log will open in Notepad and you may be prompted to Restart.

Note: if you need help with the instructions, then post your questions in our Spyware Removal forum.

Trojan FakeAlert creates the following files and folders

C:\WINDOWS\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
C:\WINDOWS\msa.exe
C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
%UserProfile%\Local Settings\temp\a.exe
%UserProfile%\Local Settings\temp\b.exe
%UserProfile%\Local Settings\temp\c.exe
C:\WINDOWS\system32\sshnas.dll

Trojan FakeAlert creates the following registry keys and values

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS
HKEY_CURRENT_USER\SOFTWARE\XML
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sshnas
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sshnas
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\videohost
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sshnas

Trojan Tutorials - HowTo

 Previous Post

How to remove Personal Security (Uninstall instructions)

Next Post 

Remove Worm.Win32.Netsky Fake Spyware Alert (winhelper86.dll, winupdate86.exe, winlogon86.exe trojans)

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

460 Comments

  1. marga
    ― May 15, 2011 - 11:06 pm  Reply

    good information, it works for me…thanks a lot.

  2. Sander
    ― June 19, 2011 - 6:22 pm  Reply

    I believe I finally got rid of that bothering dialogue box. Thanks a lot!

  3. SUPER HAPPY noname user
    ― July 22, 2011 - 10:12 pm  Reply

    OH MY GOD!! THANK YOU VERY MUCH!! NO MORE ALERTS!!
    You’re surely a HERO for all users who got sshnas.dll or sshnas21.dll errors ;-D

  4. Alex
    ― July 28, 2011 - 12:37 am  Reply

    Mil gracias por esta solución, mi equipo quedo limpio del todo, cabe comentar que la pantalla queda un rato en negro al reinisiarla OTM, no se espanten como yo, dejen que termine el proceso. Y si es necesario hacer el paso 2, MBAM encontro otros troyanos que tenia mi sistema. Confien en esta solución. Saludos!!!!!!!!!!!!!!!!!!!

  5. Radhika Bambhania
    ― July 29, 2011 - 7:45 pm  Reply

    Hi.. thnk you so much for the help.. all the steps worked perfectly n my laptop is trojan free.. 😀 thnk you so much.. !!!

  6. Jm Galvez
    ― August 29, 2011 - 2:16 am  Reply

    Thanks to this. But i recommend all of you to use ESET smart security 4 🙂

  7. Mani
    ― September 13, 2011 - 2:22 am  Reply

    Wonderfull. this is really helpful…now my computer is free from trojan! thank you so much!

  8. Raynelle
    ― October 13, 2011 - 10:21 am  Reply

    worked like a charm

  9. Martin
    ― March 17, 2013 - 6:49 am  Reply

    Sos un genio!!!!

  10. Thanks
    ― July 9, 2013 - 6:24 pm  Reply

    Thankssssssss XD :-))))))))

« Previous 1 … 14 15 16

Leave a Reply to Alex Cancel reply

New Guides

STDEI GLP 1 Review, Stdei GLP-1 Weight Loss Oral Solution Scam
scam alert
GOTEEX.com Review: Promo Code Scams Exposed
Olygee Cooling Ace Review, Don’t Be Fooled by False Promises and Misleading Ads
Suzuki Moorai Robot Dog Vehicle Real or a Scam, What You Need to Know
Liketonline Cooling Ace Review, Scam or Legit? What You Need to Know

Follow Us

Search

Useful Guides

adwcleaner
AdwCleaner – Review, How to use, Comments
Files encrypted by ransomware become useless
How To Recover Encrypted Files (Ransomware file recovery)
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
Tech Support Scam
Remove Tech Support Scam pop-up virus [Microsoft & Apple Scam]
How to reset Mozilla Firefox (Updated Apr. 2018)

Recent Guides

How to remove Personal Security (Uninstall instructions)
How to remove AntiAdd (Uninstall instructions)
How to remove RESpyWare (Uninstall instructions)
How to remove Antivir (Uninstall instructions)
How to remove REAnti (Uninstall instructions)

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2024 MASW - Myantispyware.com.