Symantec and it keeps comming back

Discussion in 'Malware Help (A Specialist Will Reply)' started by Giabella, Sep 14, 2006.

  1. Giabella

    Giabella Private E-2

    My antivirus quarintines a Trojan "downloader". I can delete it at that point but on each boot up it requarintines it.
    I have run all the programs you have suggested and it looks like Bitdefender it the only program that finds anything. Symantec does not see this trojan when I do a manual scan.
    Upon doing all the scans. It seems that this problem is not reappearing. I have at this point disabled system restore as I think the trojan is no longer present. Hope that was correct as I believe the problem has been cured. Hopefully you will be able to fill me in on that.
    I have attached files from Bitdefender, PandaActivescan and Hijack This. Let me know if you need additional ones. Sorry I did not save Bitdefender as Tabdelimited. If that is a problem let me know and I will do the scan again.
    Thank you for your time.
    This process is very interesting. Just wish I new a lot more to fully do this myself!
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First thing I notice is that your running more than one antivirus, you need to pick one and uninstall the other as running more than one will cause conflicts on your computer.

    Once you have addressed this issue, reboot and run the scan below.

    Click on the link below and run the online scan...

    Kaspersky Anti-Virus Online Scan

    • Click on "Kaspersky Online Scanner"
    • Click Accept to procede...
    • If you get a popup askiing if you want to Install Kaspersky's ActiveX Control, click Yes to install it.
    • If you get a Security Warning popup asking if you want to install and run kavwebscan_unicode.cab, click Yes to install it.
    • After all updates are downloaded, click NEXT to continue...( Note it will take awhile to download these updates based on your connection speed).
    • Click Scan Settings and select extended and make sure both boxes are checked at the bottom, Click OK to continue.
    • Now click on My Computer and let it run!
    • This scan may take a while but it is very thorough. After the scan is complete save the log as a txt file and attach it to your next post.
     
  3. Giabella

    Giabella Private E-2

    Thank you. I am now running only one virus protection and I have now run "Kaspersky Online Scanner" and it found some things. One called "not a virus hoax" and other items that were locked.
    I will appreciate your follow up help.
    Attached is the Kaspersky file.
    Thanks
     
    Last edited: Sep 15, 2006
  4. Giabella

    Giabella Private E-2

    Here is the attachment.
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First thing you need to do is reboot into Safe Mode and delete everything in the folder below.

    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine

    Once you have removed this items, reboot back to normal mode and run CCleaner to cleanup any junk/temp files.

    Then I need you to disable/renable System Restore to flush any bad points.

    Once you have completed this, reboot a few times and see if you still get the message about the Trojan Downloader.
     
  6. Giabella

    Giabella Private E-2

    Thank you for your help. There was nothing in that folder. Nothing seems to be comming back. It seems like the problem has been cleaned up. My one confusion is the following:
    In using the Kaspersky Online Scanner what was the finding of "Infected: no-virus :Hoax.Swf.Alerter. Only Kaspersky found that item.
    Thank for you help again
     
  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If you ran CCleaner it should have cleaned that out. Do you know how to manually remove the items in the quarantine folder thru the antivirus? If so, please do so.
     
  8. Giabella

    Giabella Private E-2

    It's all done and cleaned out. Thank you very much for your efforts.
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds