CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

LOST AV GUARD AFTER A TROJAN WAS DETECTED?

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
dragonbreath

Captain
Captain


Joined: Aug 30, 2004
Posts: 406
Location: UK

PostPosted: Thu Oct 14, 2004 7:52 pm    Post subject: LOST AV GUARD AFTER A TROJAN WAS DETECTED?
Reply with quote

Very Happy Hi there,AVPE was doing its job well!,..2 days ago- tuesday 12th october AVPE detected a TROJAN -.....Dict.Dat Trojan horse detected-TR/DLDR.Win.Sh.AC.04.
Anyway AVPE quarantined it and i eventually deleted it then i lost the AV GUARD COMPLETELY from my toolbar!,nowhwre to be found, tried everything,the main core programme was still there?,so i had to uninstall AVPE and re-install AVPE again?.
Has anyone ever had this kind of problem before?.I have sincedone 3 independant scans with PANDA,HOUSECALL,SYMANTEC,SPYBOT 1.3,ADAWRE PRO. ect ect for TROJANS or viruses,spyware,nothing found CLEAN,any one any clues,if i did not know better from what i have read -maybe a virus located in the TROJAN that was detected DISABLED the AVPE GUARD,before it was quarantned or deleted?

dragonbreath Rolling Eyes

Back to top
View users profile Send private message
NeO-GhOsT

Trooper
Trooper


Joined: Nov 14, 2004
Posts: 17


PostPosted: Sun Nov 14, 2004 2:51 pm    Post subject:
Reply with quote

Heya DragonBreath,

Probebly You had one of those Trojanhorses that kills your AV after removing the Trojan..(but you got lucky it did not removed your whole AV , sometimes it will delete your whole AV and then your vulnerible again) But ok probebly that is what happend...

Your virus and info below here:

Name Troj/Dldr
Type Trojan

Affected operating systems Windows

Side effects Allows others to access the computer
Downloads code from the internet
Reduces system security

Advanced User's info:

Troj/Downldr-EC is a downloader Trojan for the Windows platform that downloads and runs an executable file from a predefined location.
When executed Troj/Downldr-EC downloads and runs appl.exe, which is detected as Troj/Haxdoor-K, from the xxxx//babes.rompl.net/ location.


Edited to inactivate link. Use at own risk!


_________________
13-2-21-1-1-5-8

O, Draconian Devil,
Oh, Lame Saints...
So Dark The Con Of Man
Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Mon Nov 15, 2004 12:48 am    Post subject:
Reply with quote

If the above scenario is correct, it sounds like you had a very narrow squeak indeed!

To ensure that you really are clean, why don't you D/L one of the specialist AT scanners to give your system the once over?

To avoid getting into worse trouble next time you should consider installing ProcessGuard, from DiamondCS, which will help protect your AV/FW etc from trojan attack.

Incidently, I do not approve of including live links, like the one in the above post, in this forum because someone with itchy fingers could inadvertantly click it and end up getting nailed.

Back to top
View users profile Send private message
NeO-GhOsT

Trooper
Trooper


Joined: Nov 14, 2004
Posts: 17


PostPosted: Mon Nov 15, 2004 8:34 am    Post subject:
Reply with quote

Yes Sorry my bad ,
i forgot to remove the DOT inbetween and some open spaces..
Will not do it again Cheers Wink


_________________
13-2-21-1-1-5-8

O, Draconian Devil,
Oh, Lame Saints...
So Dark The Con Of Man
Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3012

Forums Admin MVP Premium Team F@H

PostPosted: Mon Nov 15, 2004 3:07 pm    Post subject:
Reply with quote

Howdy,

No Problem.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
dragonbreath

Captain
Captain


Joined: Aug 30, 2004
Posts: 406
Location: UK

PostPosted: Mon Nov 15, 2004 9:08 pm    Post subject: re-avpe guard de-activeated re-trojan
Reply with quote

NeO-GhOsT wrote:
Heya DragonBreath,

Probebly You had one of those Trojanhorses that kills your AV after removing the Trojan..(but you got lucky it did not removed your whole AV , sometimes it will delete your whole AV and then your vulnerible again) But ok probebly that is what happend...

Your virus and info below here:

Name Troj/Dldr
Type Trojan

Affected operating systems Windows

Side effects Allows others to access the computer
Downloads code from the internet
Reduces system security

Advanced User's info:

Troj/Downldr-EC is a downloader Trojan for the Windows platform that downloads and runs an executable file from a predefined location.
When executed Troj/Downldr-EC downloads and runs appl.exe, which is detected as Troj/Haxdoor-K, from the xxxx//babes.rompl.net/ location.


Edited to inactivate link. Use at own risk!

Thanks NEO for the very helpful info you provided re-trojan downloader,yes looks like i was lucky !,god know how i got that trojan,maybe when i went out walking the dog my 16 1/2 yr old son was on the pc for 1/2 hr?,considereing the amount of anti-spyware and the AVPE and ewido i have insatlled cannot see how i got it antway i have blocked all porn sites now.

thanks again

dragonbreath

Back to top
View users profile Send private message
dragonbreath

Captain
Captain


Joined: Aug 30, 2004
Posts: 406
Location: UK

PostPosted: Mon Nov 15, 2004 9:12 pm    Post subject: THANKS TO ALL FOR YOUR HELP RE-TROJAN DOWNLOADER
Reply with quote

Very Happy Thanks again all for your helpful info and advice Rolling Eyes

regards

dragonbreath

Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3012

Forums Admin MVP Premium Team F@H

PostPosted: Tue Nov 16, 2004 7:05 am    Post subject:
Reply with quote

Howdy,

If you don't already have these programs, for your protection, I suggest you download and install these 2 very small, free programs that you run once and then just occasionally have to check for updates.

SpywareBlaster will block bad ActiveX and malevolent cookies.

http://www.javacoolsoftware.com/spywareblaster.html

IE-SPYAD puts over 4000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

http://www.staff.uiuc.edu/~ehowes/resource.htm#IESPYAD

Please also read this article.
So how did I get infected in the first place?


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
NeO-GhOsT

Trooper
Trooper


Joined: Nov 14, 2004
Posts: 17


PostPosted: Tue Nov 16, 2004 3:00 pm    Post subject:
Reply with quote

DragonBreath no problemo Very Happy Loved to help you Smile


_________________
13-2-21-1-1-5-8

O, Draconian Devil,
Oh, Lame Saints...
So Dark The Con Of Man
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer