Computing.Net > Forums > Security and Virus > Downloader.Trojan virus

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Downloader.Trojan virus

Reply to Message Icon

Original Message
Name: JackKing
Date: October 8, 2006 at 00:28:53 Pacific
Subject: Downloader.Trojan virus
OS: XP
CPU/Ram: P4 2.8 1 GB
Model/Manufacturer: HP
Comment:

Greetings,
Have had this for a few days now >>>The compressed file epl.exe within C:documents and Settings\Temp\Temporary Internet Files\Content.IE5\09A7WHY3\epl84bd [1].cab is infected with the Downloader.Trojan virus.
Norton reads that it has quarantined it but " Can Not Delete: ".
Any answers or Suggestions please?
As always, many thanks in advance!

Best regards,
Jack


"You can walk around this town without brains. . . But you can't walk around without money!"


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: October 8, 2006 at 08:03:11 Pacific
Reply: (edit)

We should be able to help, but will need to look at your system to see what we are dealing with.

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.

Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.

Exit Hijack This. Rename hijackthis.exe as that sometime helps locate the baddies. Go to start> search> files and folders> type in the top space "hijackthis.exe" without the quotes> click search> when it is found in the right pane (looks like a pile of dynamite)>right click on it> click rename> rename it "show.exe" without the quotes> click a blank space on the screen.

Run Hijack This again, click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

This looks for a particular baddie. !!!!! Only run option #1 as the other options will damage the desktop of an uninfected computer. !!!!!

Please download SmitRemFix from this link http://siri.urz.free.fr/Fix/SmitfraudFix.zip Then extract the contents to your desktop.

Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd"
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

We will need the following tool for clean-up later.

Please download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/view/19/2/ We will need it later in safe mode

Download and install Ewido Security Suite We will need this later in safe mode

Be sure to update Ewido

Download Killbox to your desktop from this link Killbox by Option^Explicit. If you already have "Killbox" update to this newer version. We will need it later in safe mode


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 5 Days.
Discuss in The Lounge
Poll History




Data Recovery Software