PDA

View Full Version : TROJ_SMALL.FO can't find how to get rid of it or what damage it can do


srschulz@execulink
May 1st, 2004, 10:32 PM
undefined
Sorry for any mistakes. I'm new at this.

I just updated my Virus-Scan yesterday. Today I decided to do an overall virus-check and came up with the TROJ_SMALL.FO (at least it looks like a period between the L and F). I have been unable to find this virus listed in the usual places. When I looked for the file that it is in, found several mentions of a similar virus in the same file at this site: WINDOWS/TEMP/XWXLOAD.EXE (I know they should all be backslashes but I have no driver at the moment for my international keyboard and some things just aren't available.)

Can anyone tell me what this virus might do and especially how I might get rid of it? So far I can't see that it has interfered with anything that I've tried to do. But who knows what's going on in the background. I'm very new at getting rid of viruses, so I'll need very explicit instructions if necessary.

Thanks to anyone that can help.

dvk01
May 2nd, 2004, 02:11 AM
please follow instructions here
http://www.wilderssecurity.com/showthread.php?t=15913
and post a hjt log in the hiajck forum

Pilli
May 2nd, 2004, 02:12 AM
This maybe the Worm also known as sasser, for more information try here:
http://www.sophos.com/virusinfo/analyses/w32sassera.html

It may be useful if you follow the instructions here: http://www.wilderssecurity.com/showthread.php?t=15913

If you find any files on your PC relating to the worm would you please zip them up and email to submit@diamondcs.com.au

Thank and I hope this helps - Pilli

Jooske
May 2nd, 2004, 04:43 AM
Googled around a bit more. I see only trendmicro mentioning that filename in it's definitions at the moment, but no description about it.
So i googled on your filename too.
Seems it might be a downloader, eventueally, which we dealth with recently if it is the same kind: TrojanDownloader.Win32.Small.eh, W32/Lowx.A@dl
(see Gavin's explanation on the other small.ff
http://www.wilderssecurity.com/showthread.php?t=27747
The file is TrojanDropper.Win32.Small.ff, and drops ADWARE known as TrojanDownloader.Win32.Rameh.b - which is related to F1organiser.com)
so probably family of it.
http://computercops.biz/modules.php?name=Forums&file=viewtopic&p=122431
http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?id=58333&VName=TROJ_LOWX.A&VSect=T
Does the trendmicro description make any sense? Anyway, please first of all post your HJT log so we can see what more to be done and look for.
And to be sure, please locate the file and zip it and send it to submit@diamondcs.com.au just like Pilli said, there might be more involved reading the trendmicro story IF it is the same.

Gavin - DiamondCS
May 3rd, 2004, 04:01 AM
Small isn't a family, its a generic name given to trojans, downloaders, droppers, whatever - when they are SMALL in size :)

Just wait on the ASViewer or HJThis log, all will be revealed. If I get a sample of it I'll let you know just WHAT it does