Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 5th, 2004, 04:55 AM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Trojan Downloader

Hello,

My friend has Windows XP Home, which I am not very familier with.

Every time he connects to IE , an alert box from Norton informs that Trojan Downloader is in his:-

C Windows-Temp Internet Files.

I did an online scan with Trend and it found three infected Temp Int. files but could not clean so I deleted.

I followed all the removal instructions from Symantec,
Updated Norton Anti virus
Ran a full system scan (this came up clean-no infection found)
Followed rest of instructions from Symantec
no reference to Trojan Downloader was found in the registry keys that Symantec advised to check.

However when connection to IE is made, the alert box still appears saying Downloader Trojan is in his Windows Temp Internet files

Norton activity log shows at every IE connection (with time and date)
access denied and removal unsuccessful.

Now, my friend never empties his Temp Internet files.
If I open Norton and do a Web Clean Up should this delete the offending files from his pc or should it be done online through tools>options>delete files??

Ijust hope that deleting his Temp Internet Files will get rid of the Trojan, as it is no longer being detected in the Norton full system scan.

As it is not my pc, I am reluctant to do anything without first asking your advice and whether to use Norton Web Clean Up or through IE.

Thank you so much for any advice/support.

Rosie
  #2  
Old June 5th, 2004, 05:19 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: Trojan Downloader

Rosie,

Make sure to disable System Restore on the system in question and run a full system scan once more, preferably in the Safe Mode. In case of a clean bill of health, clean out/delete the temp files in question. After doing so, reboot as usual and enable System Restore again.

regards.

paul
  #3  
Old June 5th, 2004, 05:50 AM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Thank you so much,

Is it best to clean out the files through Norton Web Clean Up or through Internet Explorer Tools>Options>Delete Files.

Regards

Rosie
  #4  
Old June 5th, 2004, 05:54 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: Trojan Downloader

My pleasure Rosie.

You can clean up through IE first, and let NWCleaner do its job after that as a double check.

regards.

paul
  #5  
Old June 5th, 2004, 05:57 AM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Thank you,

Will not see him again until Monday, I will let you know how it goes.

Rosie
  #6  
Old June 5th, 2004, 06:14 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: Trojan Downloader

Looking forward to it

regards.

paul
  #7  
Old June 5th, 2004, 06:27 AM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Paul,

I am sorry, one more question.

How can I delete IE temp Internet Files in Safe Mode as I will not be able to get an Internet Connection in Safe Mode?

Sorry to be a pain

Rosie
  #8  
Old June 5th, 2004, 07:27 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re: Trojan Downloader

Rosie,

There's no need for an internet connection - perform all off-line.

No need to feel embarassed .

regards.

paul
  #9  
Old June 5th, 2004, 09:43 AM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Thanks

Rosie
  #10  
Old June 9th, 2004, 10:33 AM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Hello,

Did all of the above and all went well.

Norton full system scan was clear, however when connecting to the internet, a red dialog box still appears stating pc is infected with downloader trojan.

Went back into Norton to review reports and two different files are showing as having the trojan.

FirstOne:-
C:\Documentsand Settings\PCUser Name\Local Settings\Temporary Internet Files\Content.IE5\MZ6ZY9YZ\EXPLOITS(1).CHM

Details:- Downloader Trojan

Second One:-
Exactly the same apart from the Number which is \MZ6ZY9YZ\.CHM

Details-Downloader Trojan

Both with same date of login.

Any advice/help would be very much appreciated.

Many thanks

Rosie
  #11  
Old June 11th, 2004, 03:49 PM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Anyone

Rosie
  #12  
Old June 12th, 2004, 05:17 PM
Arin's Avatar
Arin Arin is offline
Frequent Poster
 
Join Date: May 2004
Location: India
Posts: 997
Default Re: Trojan Downloader

dear Rosie, please check your autostart programs and give us the list. also tell us when that red box appears, when he connects to the Net or just surfing the Net. sometimes when we visit a webpage a trojan gets downloaded in our system. the Temporary Internet Files is the folder where its downloaded. try this link to get an autostart viewer.
  #13  
Old June 12th, 2004, 08:10 PM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Hello amrx

Thank you for replying to my plea.

My friend gets the red warning box, on his 'Home Page', just after he has connected to the net.

I will not be able to get an auto start list now, until I see him again, probably later next week.

I will post the list as soon as I can get one. It is no good contacting him to get the list himself as he nearly passes out if he is asked to do anything like downloading.

Thanks anyway.

Rosie
  #14  
Old June 13th, 2004, 01:43 PM
Arin's Avatar
Arin Arin is offline
Frequent Poster
 
Join Date: May 2004
Location: India
Posts: 997
Default Re: Trojan Downloader

we are here to help and learn. by the way changing his Home Page will do the trick.
  #15  
Old June 14th, 2004, 01:32 PM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

If we change his 'Home Page' I assume that the warning box will re-appear at subsequent visits to that page?

Thanks

Rosie
  #16  
Old June 14th, 2004, 02:58 PM
Arin's Avatar
Arin Arin is offline
Frequent Poster
 
Join Date: May 2004
Location: India
Posts: 997
Default Re: Trojan Downloader

dear Rosie, the answer is yes if the webpage in question is the root of all trouble. why don't you remove this homepage and see for yourself.
  #17  
Old June 14th, 2004, 05:55 PM
Rosie Rosie is offline
Infrequent Poster
 
Join Date: May 2003
Location: United Kingdom
Posts: 44
Default Re: Trojan Downloader

Hi,

Thanks, I will do that when I next see him, I will let you know what happens.

Rosie
  #18  
Old June 21st, 2004, 05:53 AM
arch arch is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 1
Default Re: Trojan Downloader

I got the similiar problem.
After I change homepage address, it automatically open the wrong link again.
I've followed the instructions on Norton website to kill this, however it can't detect the infected file during the scan.
Any suggestions? Thanks!!!!!
  #19  
Old July 16th, 2004, 09:14 AM
cmo
 
Posts: n/a
Default Re: Trojan Downloader

Hello, I have a server and a good number of my clients have the forum from yabbse. Everytime when someone connects to the forum the Norton Antivirus will alert virus activity. This is the same for the photo galeries and chat rooms.

We checked the linux server for trojan and nothing was found.

We noticed that the forum has a hidden link to a site in another server that is inffected with the virus.

So far, we couldn't find the hidden link.

Anyone with same problem?

Carlos
  #20  
Old July 18th, 2004, 12:33 AM
Kc7LGT
 
Posts: n/a
Default Re: Trojan Downloader

Man I got the Trojan Exploit-ByteVerify what ever you do keep updating you AV software. It came in thru a number of email attachments from someone I know on Ham radio. He is from England and one day he sent me an attachment so I emailed back out of courtesy that I thought it was funny ( It really wasnt) anyway withinn a weeks time he sent about 40 more and I finaly got the Trojan, so I emailed back and thanked him for that. As it stands right now is I cant get rid of it and I use this computer for business. I went thru the registrey and and a bunch of other things with no success at the time I was using AVG and it was updated but it didnt catch it. AVG is a good VS and it runs off of F-prot which is mainly used by alot of ISP's. Well being I using Win 98 secound addition there is not much support out there for the ByteVerify Trojan for 98. I may have to pull all my needed files from the com and do a complete format on the HD.

Joe. Washington State.
  #21  
Old September 7th, 2004, 01:35 AM
kc7lgt
 
Posts: n/a
Default Re: Trojan Downloader

its a bad trojan
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:47 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums