Показано с 1 по 5 из 5.

'Trojan-Downloader.WMA.GetCodec.u' detected

  1. #1
    Junior Member Репутация
    Регистрация
    28.04.2007
    Сообщений
    12
    Вес репутации
    62

    'Trojan-Downloader.WMA.GetCodec.u' detected

    I got an Acer Laptop (German Vista) from a friend with several infection in WMA and MP3 files. The reason for the infection were obviously P2P downloads using Limewire.
    The virus removal tool woked fine but I have problems with the scan of AVZ (analysis and malware removal). The scan seems to remain in a loop in the folder c:\ Documents and Settings \ All Users \
    Anwendungsdaten \ Anwendungsdaten....
    (Anwendungsdaten = application data). I stopped this scan as after 6 hours a remaining time
    of 122 hours was shown.
    AVZ with "analysis scan" did work and the syscheck.zip was created.
    After I run HJT.
    Did I something wrong? Can you help me even if there are only the two files available.
    Looking with a Linux Live CD I see a folder but in Vista I see a link but can not access.

    Many thanks
    copperray
    Вложения Вложения
    _______
    copperray

  2. #2
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Numb
    Регистрация
    04.10.2005
    Сообщений
    2,118
    Вес репутации
    870
    Hello.
    Are you sure you've launched AVZ utility using "runas" option of the context menu? Even though you're working under administrator's account, you should use "runas" option to get correct results in your logs. Anyway I don't see anything harmful in your logs. There are some suspicius files there. If you want them of being checked, please, execute the script:
    Код:
    begin
    QuarantineFile('C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe','');
     QuarantineFile('c:\windows\plfseti.exe','');
    BC_ImportquarantineList;
    BC_Activate;
    RebootWindows(true);
    end.
    After restart, upload quarantine using the link http://virusinfo.info/upload_virus_eng.php?tid=54763 , as it's described in the app.3 of the rules.
    As for this suspicious folder, I think it's normal - it's the way that Vista's protection works, but you can try to gain access to it using takeown command and look what is inside.

  3. #3
    Junior Member Репутация
    Регистрация
    28.04.2007
    Сообщений
    12
    Вес репутации
    62
    Hi,
    I followed your instructions. I run AVZ using "runas" a second time but same result. Can it be possible that Trojans create such links to disturb Antivirus scanning? For comparison, I do not have suchs directory links in another Vista system.
    I uploaded the file list created with your script. AFAIK the "plfseti.exe" is link to the webcam of the laptop.

    Additional question: How can I set password to the virus.zip? Nothing found with Windows nor 7zip.

    Thanks

    copperray
    _______
    copperray

  4. #4
    Senior Member Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Репутация Аватар для Numb
    Регистрация
    04.10.2005
    Сообщений
    2,118
    Вес репутации
    870
    Hello.
    Everything is possible of course, but I still think it's one of the Vista's tricks. There are many examples of "protection by obfuscation" in Vista. Did you try to gain access to this folder using "takeown" command?
    You don't need to set password if you create virus.zip using AVZ tool - It will be set automatically.

    Добавлено через 26 минут

    But may be you'd better check this laptop with a live CD, such as DrWeb live CD for example, just to be sure that there is nothing harmful there that has been missed for the first check.
    Последний раз редактировалось Numb; 17.09.2009 в 01:18. Причина: Добавлено

  5. #5
    Junior Member Репутация
    Регистрация
    28.04.2007
    Сообщений
    12
    Вес репутации
    62
    Hello Numb,

    the "takeown" command did not help to access. Using the Win console I can go into these directories and see some subdirectories.
    The scan with DrWeb-Live-CD is still running. Using "default mode" the program stops with the boot screen, so I'm using "safe mode".

    Добавлено через 59 минут

    Hello,

    scan finished. Nothing found.
    Seems this story can be closed now.

    Thanks for the help.
    Последний раз редактировалось copperray; 18.09.2009 в 01:16. Причина: Добавлено
    _______
    copperray

Похожие темы

  1. Ответов: 3
    Последнее сообщение: 12.06.2009, 23:17
  2. Ответов: 11
    Последнее сообщение: 22.02.2009, 03:45
  3. Ответов: 4
    Последнее сообщение: 22.02.2009, 03:31
  4. Ответов: 1
    Последнее сообщение: 20.08.2008, 12:58
  5. Ответов: 22
    Последнее сообщение: 22.05.2007, 11:54

Метки для этой темы

Свернуть/Развернуть Ваши права в разделе

  • Вы не можете создавать новые темы
  • Вы не можете отвечать в темах
  • Вы не можете прикреплять вложения
  • Вы не можете редактировать свои сообщения
  •  
Page generated in 0.00766 seconds with 20 queries