Adramalech
April 17th, 2005, 09:02 AM
Hi
XMON has detected a Virus called Win32/TrojanDownloader.Small.ZL
Time Module Object Name Virus Action User Info
4/16/2005 17:56:38 PM XMON email message from: sender to: Recipient with subject dated 04/16/2005 17:56 Attachment: Fairy_tale_4534.zip Win32/TrojanDownloader.Small.ZL trojan deleted
The more detailed log of XMON was saying:
1. Action: Deleted
2. Action: Error while cleaning – operation unavailable for this type of object – error while deleting - operation unavailable for this type of object – was part of the deleted object
So far so good, but every once in a while, AMON (probably after a signature update or something) is detecting a file with the same Virus, and it’s always in the %systemroot%\temp Folder with a NOD prefix.
4/17/2005 13:38:27 PM AMON file C:\WINDOWS\TEMP\NODA234.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
4/17/2005 7:01:11 AM AMON file C:\WINDOWS\TEMP\NODF1D0.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
4/17/2005 0:00:38 AM AMON file C:\WINDOWS\TEMP\NOD996B.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
4/16/2005 21:19:17 PM AMON file C:\WINDOWS\TEMP\NOD84.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
So it seems that NOD didn’t get rid of the Virus completely. What can I do? I also ran a manual scan and a deep scan but nothing.
Thanks
Adra
XMON has detected a Virus called Win32/TrojanDownloader.Small.ZL
Time Module Object Name Virus Action User Info
4/16/2005 17:56:38 PM XMON email message from: sender to: Recipient with subject dated 04/16/2005 17:56 Attachment: Fairy_tale_4534.zip Win32/TrojanDownloader.Small.ZL trojan deleted
The more detailed log of XMON was saying:
1. Action: Deleted
2. Action: Error while cleaning – operation unavailable for this type of object – error while deleting - operation unavailable for this type of object – was part of the deleted object
So far so good, but every once in a while, AMON (probably after a signature update or something) is detecting a file with the same Virus, and it’s always in the %systemroot%\temp Folder with a NOD prefix.
4/17/2005 13:38:27 PM AMON file C:\WINDOWS\TEMP\NODA234.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
4/17/2005 7:01:11 AM AMON file C:\WINDOWS\TEMP\NODF1D0.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
4/17/2005 0:00:38 AM AMON file C:\WINDOWS\TEMP\NOD996B.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
4/16/2005 21:19:17 PM AMON file C:\WINDOWS\TEMP\NOD84.tmp Win32/TrojanDownloader.Small.ZL trojan NT AUTHORITY\SYSTEM
So it seems that NOD didn’t get rid of the Virus completely. What can I do? I also ran a manual scan and a deep scan but nothing.
Thanks
Adra