Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 20th, 2003, 01:56 AM
Kroc Kroc is offline
Infrequent Poster
 
Join Date: Jun 2003
Posts: 1
Default help please

Hi Everyone, Im not sure if im posting in the right place or not but i would like some assistance with a problem im having. If im not in the right place could someone refer me on .....thanks

ok im running windows xp
have nortons anti virus 2002 with the latest updates

I clicked on a web site and my nortans sent up an Alert reading as follows

Date: 20/06/2003, Time: 8:53:32,
The file
C:\WINDOWS\System32\aupdate.exe
is infected with the Download.Trojan virus.
Unable to repair this file.

and then this

Date: 20/06/2003, Time: 8:53:32,
The file
C:\WINDOWS\System32\aupdate.exe
is infected with the Download.Trojan virus.
Access to the file was denied.

I went looking for the file and couldnt find it
I then went and checked symantics web pages and after about 3 hours of shere frustration downloaded a couple of Trojan scanners and did a scan.

Neither Trojan Scanner picked it up
I ran nortans thru about 5 more full scans as well as pointing nortons to any file with the file name of aupdate........

my question is this....

Is the virus still present ?

If so how do i find out for sure ?

How do i get rid of it ?

Hoping someone can help

Thanks

Kroc




  #2  
Old June 20th, 2003, 02:07 AM
Dan Perez's Avatar
Dan Perez Dan Perez is offline
Global Moderator
 
Join Date: May 2003
Location: Sunny San Diego
Posts: 1,495
Default Re:help please

Hi Kroc,

Welcome aboard!

Could you please go to

http://www.diamondcs.com.au/index.php?page=asguard

and download and extract the freeware AutoStart viewer utility.

When you run it can you go to the "Main" menu and make sure the top three options are checked. Once this is done select Save from that menu, it will create an asviewer.txt file in the same directory you ran it from and paste the contents of that file here.

Also, are you sure that the AV did not quarantine the file? You might want to look in your quarantine directory and/or check you AV log.

Dan
__________________
"Whan alle tresors arn tried, Treuthe is the beste." Piers Plowman (William Langland)
  #3  
Old June 20th, 2003, 02:39 AM
Pieter_Arntz's Avatar
Pieter_Arntz Pieter_Arntz is offline
Spyware Veteran
 
Join Date: Apr 2002
Location: Netherlands
Posts: 12,719
Default Re:help please

Hi Kroc,

Could be this one:
http://www.doxdesk.com/parasite/TinyBar.html

Regards,

Pieter
__________________
Regards,

Pieter
It´s nice to be important, but it´s more important to be nice.

It's human to make mistakes. It's even more so to blame the computer for it.
  #4  
Old June 20th, 2003, 05:04 AM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re:help please

Yep those are the ones, its technically a webdownloader and detected by TDS and most if not all AV's too.

Turn off ActiveX, clean it and its friends who have surely come along too with spyware removers
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:24 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums