PDA

View Full Version : Got a Trojandownloader. Spyware or something wana Be Free.. HOW?


bomango
January 7th, 2008, 05:53 PM
Hello Sir its khurram.....
i hve Got a Threat from last one month ..
trying to remove it but dont know where da hell its hidden i did ma Window 8 times .. and on every new installation i installed nod32 firstly and update it Even i dont installed any driver becuze of in danger, that virus might be on that .EXE file for example MSN.EXE Or msgrus.exe yahoo and msn setups.....
when i Scanned Firslty i got that a Virus threat been detected.. but NOD qurantined it but dont remove it..... Y
Every time i open And IE Page the two threats messages been Alert me YYY
Examples Logs Are

Module Object Name Threat Action User Information
1/7/2008 0:46:22 AM AMON file C:\Documents and Settings\khurram\Local Settings\Temporary Internet Files\ContentJS/Exploit.RealPlay.E trojan quarantined - deleted KHURRAM-BIG\khurram Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.

Time Module Object Name Threat Action User Information
1/7/2008 0:46:22 AM IMON file JS/Exploit.RealPlay.E trojan quarantined - Connection terminated KHURRAM-BIG\khurram

Time Module Object Name Threat Action User Information
1/7/2008 0:46:15 AM AMON file C:\Documents and Settings\khurram\Local Settings\Temporary Internet Files\Content.IE5\ a variant of Win32/TrojanDownloader.Ani.Gen trojan quarantined - deleted KHURRAM-BIG\khurram Event occurred on a file modified by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
1/7/2008 0:46:15 AM AMON file C:\Documents and Settings\khurram\Local Settings\Temporary Internet Files\Content.IE5\KWUSL0IS\6[1].gif JS/Exploit.RealPlay.E trojan quarantined - deleted KHURRAM-BIG\khurram Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
1/7/2008 0:46:15 AM IMON file JS/Exploit.RealPlay.E trojan quarantined - Connection terminated KHURRAM-BIG\khurram
1/7/2008 0:43:40 AM IMON file a variant of Win32/TrojanDownloader.Ani.Gen trojan KHURRAM-BIG\khurram
1/7/2008 0:43:17 AM IMON file a variant of Win32/TrojanDownloader.Ani.Gen trojan KHURRAM-BIG\khurram
1/7/2008 0:43:15 AM AMON file C:\Documents and Settings\khurram\Local Settings\Temporary Internet Files\Content.IE5\ JS/Exploit.RealPlay.E trojan quarantined - deleted KHURRAM-BIG\khurram Event occurred on a new file created by the application: C:\Program Files\Windows Live\Messenger\msnmsgr.exe. The file was moved to quarantine. You may close this window.
1/7/2008 0:43:14 AM IMON fileJS/Exploit.RealPlay.E trojan quarantined - Connection terminated KHURRAM-BIG\khurram
1/7/2008 0:43:04 AM IMON filea variant of Win32/TrojanDownloader.Ani.Gen trojan KHURRAM-BIG\khurram
1/7/2008 0:43:04 AM AMON file C:\Documents and Settings\khurram\Local Settings\Temporary Internet Files\Content.IE5\a variant of Win32/TrojanDownloader.Ani.Gen trojan quarantined - deleted KHURRAM-BIG\khurram Event occurred on a file modified by the application: C:\Program Files\Windows Live\Messenger\msnmsgr.exe. The file was moved to quarantine. You may close this window.


m Very Upset Please Do some Favour and Tell me What should i do Burn ma Hard disk Or PC>? or Format ma important Data HELP Me...
Help will be Appreciated thknZ

dont know da user name becuze i hve got nod32t From ma Friend? where it is written Huh

Several malware links removed. Do not post links to malware on this forum. Ever. - Ron

chrisf8657
January 7th, 2008, 06:06 PM
Either you have an active Trojan running in the background attempting to download things, or you have/are visiting sites you shouldn't...

Delete your IE History & Cache to start.

If you don't know what this means, you need to contact Eset Support for guidance, and since you said you got it from a "friend",
I suggest you purchase your own copy of it since what you are using is pirated.