It is currently Tue Sep 01, 2026 4:09 pm


Can't get rid of Program 123946.dlr/.exe and Com.exe HELP!!!

Discuss security related topics in here (Hacking, Cracking, and Protecting)
Do not post HJT Logs here

Moderator: PCguy

Postby Geekgirl » Wed Jul 07, 2004 6:47 pm

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby turbostangman » Wed Jul 07, 2004 6:50 pm

User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby turbostangman » Wed Jul 07, 2004 6:57 pm

Check this out, SOunds like it is pretty recent.

A virus identity (IDE) file which provides protection is available now from the Latest virus identities section, and is incorporated into the July 2004 (3.83) release of Sophos Anti-Virus.
At the time of writing, Sophos has received just one report of this Trojan from the wild.


Looks like I am #2, :|
User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Wed Jul 07, 2004 7:04 pm

OK listen up, Update/Run Norton if you havent already. Then run HJT and post your log here. We will let brad look at your log to see what else is going on.
Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby turbostangman » Wed Jul 07, 2004 7:15 pm

I will do that as soon as housecall is done...again.

Check this out though, TORJ_PORNDIAL.BP but it says "Non-Cleanable".

So these two I have to remove myself manually I guess?
User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Wed Jul 07, 2004 7:27 pm

This may be the one that causes your modem to dial

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby turbostangman » Wed Jul 07, 2004 8:02 pm

Last edited by turbostangman on Wed Jul 07, 2004 8:19 pm, edited 1 time in total.
User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Wed Jul 07, 2004 8:07 pm

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby turbostangman » Wed Jul 07, 2004 8:22 pm

User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby turbostangman » Wed Jul 07, 2004 8:35 pm

OK, Trendmicro is done running. Now can I just click on the file and then "Delete" to the right and does that get rid of it? Or not?
User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Wed Jul 07, 2004 8:40 pm

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

AHHH HA!!!

Postby turbostangman » Wed Jul 07, 2004 8:45 pm

Trend also found this, Troj_small.Y

Went to Sophos and they skip the "Y" and go from X-Z. But here is the skinny on "X";

Trojan.Win32.Small.i, TROJ_SMALL.XC.
A virus identity (IDE) file which provides protection is available now from the Latest virus identities section, and is incorporated into the July 2004 (3.83) release of Sophos Anti-Virus.
At the time of writing, Sophos has received just one report of this Trojan from the wild.

Troj/Small-X is a Trojan which downloads and executes EXE files from remote URLs without the user's knowledge.
The Trojan drops its downloading component (a DLL with a temporary filename and a TMP extension) in the temporary folder and creates the following registry entry to attempt to run itself on system logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
msmc= <Windows system>\msmc.exe


So it looks like this little booger was going out and uploading the 123946.exe file without me knowing, that is why it kept coming back.

I went and looked at X and Z and the file names for removing it are different so I am sure those are going to be different than Y.

I wonder if Micro has the info on eliminating the Small.Y virus.
User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby turbostangman » Wed Jul 07, 2004 8:50 pm

User avatar
turbostangman
Geek
Geek
 
Posts: 36
Joined: Wed Jul 07, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Wed Jul 07, 2004 10:55 pm

Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Wed Jul 07, 2004 11:52 pm

Post your HJT Log File.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

PreviousNext

Return to Security

Who is online

Users browsing this forum: No registered users and 1 guest

cron