Downloader.Trojan virus - How Do I Get Rid Of It?
Downloader.Trojan virus - How Do I Get Rid Of It?
Author
Discussion

pmanson

Original Poster:

13,388 posts

279 months

Friday 16th April 2004
quotequote all
I booted up my Dad's laptop last night and he's picked up a "Downloader.Trojan" virus

He has Nortan AV 2002 installed but I didn't realise he didn't have any Firewall software.

The trojan is located here.........

C:WINDOWSsystem32serviceswmplayer.exe

I think its one of those trojans that dial premium rate numbers as I disconnected the BB last night while I was trying to delete it and IE kept on popping up on the window.

It seems to have also reset the homepage to coolsearch.com or something similar.

I have tryed deleting "C:WINDOWSsystem32serviceswmplayer.exe" from the registry but it doesn't seem to clear it.

Anyone got any ideas?

Cheers,
Phill

(Going off to download ZoneAlarm while i'm at work)

simpo two

92,134 posts

291 months

Friday 16th April 2004
quotequote all
http://securityresponse.symantec.com/avcenter/venc/data/downloader.trojan.html

Once you know the name, a quick Google usually does the trick.

james_j

3,996 posts

281 months

Saturday 17th April 2004
quotequote all
I got a trojan in my mediaplayer somewhere. My virus checker found it and said it had got rid of it.

However, whenever I used mediaplayer again, the virus re-appeared. The viruschecker spotted it and got rid of it again. This kept happening.

So, and you may need to do this, I guessed the nasty was in mediaplayer somewhere, so I uninstalled mediaplayer and then reinstalled mediaplayer via a new copy from Microsoft and now all is well.

psypher

37 posts

281 months

Saturday 17th April 2004
quotequote all
if its coolwebsearch thats hijacked the browser (or one of its aliases) just download cwshredder.exe which will remove al traces of it. www.majorgeeks.com/download4086.html

pmanson

Original Poster:

13,388 posts

279 months

Saturday 17th April 2004
quotequote all
psypher said:
if its coolwebsearch thats hijacked the browser (or one of its aliases) just download cwshredder.exe which will remove al traces of it. www.majorgeeks.com/download4086.html



I found that on www.computercops.us

IT got rid of it without a problem, have installed ZoneAlarm to hopefully stop it coming back in again

psypher

37 posts

281 months

Saturday 17th April 2004
quotequote all
Unfortunately a firewall wont stop this one, as i run zonealarm already, its actually an exploit in microsoft VM (java), installing an updated version of java (from sun) along with all the windows updates from microsoft, wont stop it from installing on your pc but will stop it downloading anything. AVG picked it up after i clicked on a link from google which gave a whole load of pop-ups.