|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
dragonbreath
Captain

 Joined: Aug 30, 2004 Posts: 406 Location: UK
|
Posted: Thu Oct 14, 2004 7:52 pm Post subject: LOST AV GUARD AFTER A TROJAN WAS DETECTED? |
|
|
Hi there,AVPE was doing its job well!,..2 days ago- tuesday 12th october AVPE detected a TROJAN -.....Dict.Dat Trojan horse detected-TR/DLDR.Win.Sh.AC.04.
Anyway AVPE quarantined it and i eventually deleted it then i lost the AV GUARD COMPLETELY from my toolbar!,nowhwre to be found, tried everything,the main core programme was still there?,so i had to uninstall AVPE and re-install AVPE again?.
Has anyone ever had this kind of problem before?.I have sincedone 3 independant scans with PANDA,HOUSECALL,SYMANTEC,SPYBOT 1.3,ADAWRE PRO. ect ect for TROJANS or viruses,spyware,nothing found CLEAN,any one any clues,if i did not know better from what i have read -maybe a virus located in the TROJAN that was detected DISABLED the AVPE GUARD,before it was quarantned or deleted?
dragonbreath 
|
|
| Back to top |
|
 |
NeO-GhOsT
Trooper

 Joined: Nov 14, 2004 Posts: 17
|
Posted: Sun Nov 14, 2004 2:51 pm Post subject: |
|
|
Heya DragonBreath,
Probebly You had one of those Trojanhorses that kills your AV after removing the Trojan..(but you got lucky it did not removed your whole AV , sometimes it will delete your whole AV and then your vulnerible again) But ok probebly that is what happend...
Your virus and info below here:
Name Troj/Dldr
Type Trojan
Affected operating systems Windows
Side effects Allows others to access the computer
Downloads code from the internet
Reduces system security
Advanced User's info:
Troj/Downldr-EC is a downloader Trojan for the Windows platform that downloads and runs an executable file from a predefined location.
When executed Troj/Downldr-EC downloads and runs appl.exe, which is detected as Troj/Haxdoor-K, from the xxxx//babes.rompl.net/ location.
Edited to inactivate link. Use at own risk! _________________ 13-2-21-1-1-5-8
O, Draconian Devil,
Oh, Lame Saints...
So Dark The Con Of Man
|
|
| Back to top |
|
 |
TopperID
Captain

 Joined: Oct 14, 2004 Posts: 375 Location: UK
|
Posted: Mon Nov 15, 2004 12:48 am Post subject: |
|
|
If the above scenario is correct, it sounds like you had a very narrow squeak indeed!
To ensure that you really are clean, why don't you D/L one of the specialist AT scanners to give your system the once over?
To avoid getting into worse trouble next time you should consider installing ProcessGuard, from DiamondCS, which will help protect your AV/FW etc from trojan attack.
Incidently, I do not approve of including live links, like the one in the above post, in this forum because someone with itchy fingers could inadvertantly click it and end up getting nailed.
|
|
| Back to top |
|
 |
NeO-GhOsT
Trooper

 Joined: Nov 14, 2004 Posts: 17
|
Posted: Mon Nov 15, 2004 8:34 am Post subject: |
|
|
Yes Sorry my bad ,
i forgot to remove the DOT inbetween and some open spaces..
Will not do it again Cheers  _________________ 13-2-21-1-1-5-8
O, Draconian Devil,
Oh, Lame Saints...
So Dark The Con Of Man
|
|
| Back to top |
|
 |
mrrockford
News Admin
 AVPE Host

 Joined: Apr 24, 2004 Posts: 3010
|
Posted: Mon Nov 15, 2004 3:07 pm Post subject: |
|
|
Howdy,
No Problem. _________________ "Anyone who considers protocol unimportant has never dealt with a cat."
L. Long
|
|
| Back to top |
|
 |
dragonbreath
Captain

 Joined: Aug 30, 2004 Posts: 406 Location: UK
|
Posted: Mon Nov 15, 2004 9:08 pm Post subject: re-avpe guard de-activeated re-trojan |
|
|
| NeO-GhOsT wrote: | Heya DragonBreath,
Probebly You had one of those Trojanhorses that kills your AV after removing the Trojan..(but you got lucky it did not removed your whole AV , sometimes it will delete your whole AV and then your vulnerible again) But ok probebly that is what happend...
Your virus and info below here:
Name Troj/Dldr
Type Trojan
Affected operating systems Windows
Side effects Allows others to access the computer
Downloads code from the internet
Reduces system security
Advanced User's info:
Troj/Downldr-EC is a downloader Trojan for the Windows platform that downloads and runs an executable file from a predefined location.
When executed Troj/Downldr-EC downloads and runs appl.exe, which is detected as Troj/Haxdoor-K, from the xxxx//babes.rompl.net/ location.
Edited to inactivate link. Use at own risk! |
Thanks NEO for the very helpful info you provided re-trojan downloader,yes looks like i was lucky !,god know how i got that trojan,maybe when i went out walking the dog my 16 1/2 yr old son was on the pc for 1/2 hr?,considereing the amount of anti-spyware and the AVPE and ewido i have insatlled cannot see how i got it antway i have blocked all porn sites now.
thanks again
dragonbreath
|
|
| Back to top |
|
 |
dragonbreath
Captain

 Joined: Aug 30, 2004 Posts: 406 Location: UK
|
|
| Back to top |
|
 |
mrrockford
News Admin
 AVPE Host

 Joined: Apr 24, 2004 Posts: 3010
|
Posted: Tue Nov 16, 2004 7:05 am Post subject: |
|
|
Howdy,
If you don't already have these programs, for your protection, I suggest you download and install these 2 very small, free programs that you run once and then just occasionally have to check for updates.
SpywareBlaster will block bad ActiveX and malevolent cookies.
http://www.javacoolsoftware.com/spywareblaster.html
IE-SPYAD puts over 4000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
http://www.staff.uiuc.edu/~ehowes/resource.htm#IESPYAD
Please also read this article.
So how did I get infected in the first place? _________________ "Anyone who considers protocol unimportant has never dealt with a cat."
L. Long
|
|
| Back to top |
|
 |
NeO-GhOsT
Trooper

 Joined: Nov 14, 2004 Posts: 17
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|