Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 18th, 2005, 09:52 PM
Q-Bert23 Q-Bert23 is offline
Infrequent Poster
 
Join Date: Jul 2005
Location: In the deep south.
Posts: 6
Exclamation ~~Help !!! Trojan.moo infected

Hey peeps, I was infected yesterday with the Trojan.moo, it is located in

C:\Documents and Sett\wv[1].ani

My norton AV caught it, but couldnt repair the file. I just downloaded TDS-3
and Trojancleaner but havent run them yet. My os is

MS WinXP
Home Edition
Version 2
Service Pack 2

HP Pavillion
AMD Athlon, 2800+
2.08 GHz, 448 MB of RAM

Also, Norton AV, Spy Sweeper, CCleaner, BHR, Slap,Ad Aware, Safe Windows,Counter Spy and EZ RegCleaner.
So, after i run these definitions and cleaners will that help any?


Q-Bert
  #2  
Old July 18th, 2005, 10:28 PM
Ailric
 
Posts: n/a
Default Re: ~~Help !!! Trojan.moo infected

Here's what Synmantec (Norton) has to say about trojan.moo.
http://securityresponse.symantec.com...rojan.moo.html

If that is the only problem, couldn't you just delete wv[1].ani?
  #3  
Old July 19th, 2005, 04:33 PM
Don Pelotas's Avatar
Don Pelotas Don Pelotas is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 2,257
Default Re: ~~Help !!! Trojan.moo infected

Kaspersky also detects this one, you can use the free Kaspersky Webscanner (link in my signature).
__________________
Errare humanum est
  #4  
Old July 19th, 2005, 08:19 PM
Q-Bert23 Q-Bert23 is offline
Infrequent Poster
 
Join Date: Jul 2005
Location: In the deep south.
Posts: 6
Default Re: ~~Help !!! Trojan.moo infected

Hey thanks for the quick posting guys. I really appreciate it.

Ailric: I already checked the Symantec Security Response. They dont offer much help when you've already been infected. I downloaded new definitions made specifically for the Trojan.moo( or Hacktool.Jpeg) and ran my Norton AV, which didnt work. So i downloaded the same definitions from a clean PC, and added them in which also didnt work. ?

Don Pelotas( great friggin name btw) : Im going to try the link in your sig, these Kaspersky ppl are trusted right? I'll try anything once. But i went to the Symantec Security Sweep and ran that, which also didnt work. Ive downloaded TrojanHunter and TDS-3( dont know how to use it yet though, or add new def for it) which also havent worked.

O yeh, I found the file it is in( Index.Dat) but I wasnt sure if I should delete this file since it is a valid Windows file.
It was located in

Cocuments and Settings\Owner\Local Settings\Temp Internet Files\ Content.IE5\YF24CEOS\wv[1].ani





Does anyone here no how to read HJT logs? Thanks for any help given.


Q-Bert23
  #5  
Old July 19th, 2005, 08:36 PM
Ailric
 
Posts: n/a
Default Re: ~~Help !!! Trojan.moo infected

Quote:
these Kaspersky ppl are trusted right?
As trusted as you can get. They have the best scanner out there.

If I was you, this is what I would do.

1. Download Microworld Toolkit (it uses Kaspersky engine and updates)
http://www.spywareinfo.dk/download/mwav.exe

2. Turn off System Restore.

3. Reboot in Safe Mode. Scan and clean with Microworld.
  #6  
Old July 19th, 2005, 08:50 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: ~~Help !!! Trojan.moo infected

Quote:
Originally Posted by Q-Bert23
O yeh, I found the file it is in( Index.Dat) but I wasnt sure if I should delete this file since it is a valid Windows file.
It was located in

Cocuments and Settings\Owner\Local Settings\Temp Internet Files\ Content.IE5\YF24CEOS\wv[1].ani
Delete your Temporary Internet File cache and that should remove it....leaving your Index.dat file intact.
  #7  
Old July 19th, 2005, 11:02 PM
Q-Bert23 Q-Bert23 is offline
Infrequent Poster
 
Join Date: Jul 2005
Location: In the deep south.
Posts: 6
Default Re: ~~Help !!! Trojan.moo infected

Quote:
Originally Posted by Bubba
Delete your Temporary Internet File cache and that should remove it....leaving your Index.dat file intact.


Hey thanks for your concern Bubba. I downloaded Dr.Delete yesterday and turned off system restore. And like you said Bubba,I deleted the file and it disapeared so I thought I got rid of it....but lo' I have failed. While the wv[1].ani has been deleted, I cant seem to delete the whole Temp. Internet Folder. I get a popup saying that windows needs that folder to operate properly. And now my javascript isnt working so well. I play video pool alot, and now instead of the Yahoo pool screen I get a small white box with a red X in the middle. friggin weird....

Q-Bert23
  #8  
Old July 19th, 2005, 11:07 PM
Q-Bert23 Q-Bert23 is offline
Infrequent Poster
 
Join Date: Jul 2005
Location: In the deep south.
Posts: 6
Default Re: ~~Help !!! Trojan.moo infected

Hey Ailric, I heard it isnt good to have 2 AV's running at the same time...so should i still download the MicroWorld AV and try and chunk my Norton AV?


ps...If I delete the whole Temp. Internet Files Folder with Dr.Delete, will my Windows still be able to run?



Q-Bert23
  #9  
Old July 22nd, 2005, 06:11 AM
Don Pelotas's Avatar
Don Pelotas Don Pelotas is offline
Very Frequent Poster
 
Join Date: Jun 2004
Posts: 2,257
Default Re: ~~Help !!! Trojan.moo infected

Quote:
Originally Posted by Q-Bert23
Hey Ailric, I heard it isnt good to have 2 AV's running at the same time...so should i still download the MicroWorld AV and try and chunk my Norton AV?


ps...If I delete the whole Temp. Internet Files Folder with Dr.Delete, will my Windows still be able to run?



Q-Bert23
Thats correct, but only if we are talking real-time monitoring, on-demand scanners you safely use two or three if you like a second opinion, if you use onlinesanners or a standalone scanner like DrWeb CureIt, just one at a time.

Unfortunately it seems that Microworld has decided to discontinue their free version 4.47 which both clean/delete's.http://www.wilderssecurity.com/showt...308#post514308

Yes, Kaspersky is a very trustworthy vendor with arguably the best overall detection, all the scanners in my signature is safe to use, and free!!
__________________
Errare humanum est
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:53 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums