Trojans... HELP
Author
Discussion

Fish

Original Poster:

4,026 posts

299 months

Sunday 18th January 2004
quotequote all
Right it looks like I have a trojan on the PC. Symptons - I have had a number of blocked access atempts by the Norton firewall, also running a NATS hardware firwall. This seemed odd as I've never had them before. Anyhow I've now found a directory on the C drive with a stupid name which I don't recognise. When you scan it with norton it classes it as a single boot file...No it's got 4 subfolders etc this seems wrong.

I can't delete it even as administrator and it won't let me open the subfolders. I've even tried it in Dos I can't erase delete or remove the directories.

ANY Thoughts.

The directory is called:C:76d3c2a84542bfdec38ab15f659554fc
and the subdir areownload, ip, new, and lang


I'm sure it shouldn't be there..

_DJ_

5,024 posts

271 months

Sunday 18th January 2004
quotequote all
Did you manage to decipher what it was trying to do when accessing the Internet (i.e which server/port it was trying to access?). It may be easier to identify it from that. Failing that, there's a number of free tools available to check for Trojans (do a google search)

DJ

edited to say: http://1spybot.com/ claims to be able to scan and advise on Trojan removal

>> Edited by _DJ_ on Sunday 18th January 21:32

simpo two

89,683 posts

282 months

Sunday 18th January 2004
quotequote all
Maybe go to a reputable site like www.symantec.com and do an online scan?

coach

1,103 posts

269 months

Sunday 18th January 2004
quotequote all
God, I should charge for the

Fishy m'boy, do the following.

Assuming reasonable software AV and firewall such as Norton Internet security suite (open to debate)..

Downlaod and run Spybot and adaware.

Go to www.spywareinfo.com and dowload hijackthis, run it and post the logfile onto the forum that is on that site in the removal help section.

They will then post back with the final stages of removal of the trojans & spware that all the other have missed.

I have personaly wrestled with 5 pieces of this crap over christmas and I should consider myself to know better, being in the industry.

Mail me if you need anymore help.

Now give me a ride in ya T350!

Coach

>> Edited by coach on Sunday 18th January 22:57

kojak69

4,546 posts

270 months

Monday 19th January 2004
quotequote all
simpo two said:
Maybe go to a reputable site like www.symantec.com and do an online scan?


Thats where I go if I have a virus that I cant get rid.

tuffer

8,909 posts

284 months

Monday 19th January 2004
quotequote all
kojak69 said:

simpo two said:
Maybe go to a reputable site like <a href="http://www.symantec.com">www.symantec.com</a> and do an online scan?



Thats where I go if I have a virus that I cant get rid.

Thats were I go to.....................work!

fish

Original Poster:

4,026 posts

299 months

Monday 19th January 2004
quotequote all
Well I may be speaking to you later as I'm going to give symantec a call about it today before I waste any more time on it.

tuffer

8,909 posts

284 months

Monday 19th January 2004
quotequote all
Have you updated your AV software, if not do a live update and scan again. Then do a screen capture of the problem and mail it to me direct via my profile.

simpo two

89,683 posts

282 months

Monday 19th January 2004
quotequote all
fish said:
Well I may be speaking to you later as I'm going to give symantec a call about it today before I waste any more time on it.

As I understand it, viruses are a bit different from spyware, so antivirus software doesn't remove spyware. That's why you need to keep up to date on anti-software for *both* sets of nasties.

ErnestM

11,621 posts

284 months

Monday 19th January 2004
quotequote all
Fish - what are the permissions on those folders? Have you tried to replace the permissions yet?

ErnestM

Thumper

174 posts

281 months

Tuesday 20th January 2004
quotequote all
tuffer said:
Thats were I go to.....................work!


In that case, tell me what file ccApp.exe does, and why I've had to disable the thing to stop it interrupting everything my computer ever seems to want to do! As far as I'm concerned, Norton Antivirus is a complete nightmare and always has been. I've tried to live with it, one way or another, for more than ten years, and never yet had the thing work properly. Ho hum.

Godfrey H

145 posts

266 months

Tuesday 20th January 2004
quotequote all
Thumper you might like to take a look at:
www.kaspersky.com/ A bit more expensive than NAV. I use it because it has certain features that NAV
does very badly. I once emailed a technical query on a Sunday thinking I would get back to me on the Monday
- they got back to me in 10 minutes. Perhaps you get what you pay for.

tuffer

8,909 posts

284 months

Tuesday 20th January 2004
quotequote all
Thumper said:


tuffer said:
Thats were I go to.....................work!




In that case, tell me what file ccApp.exe does, and why I've had to disable the thing to stop it interrupting everything my computer ever seems to want to do! As far as I'm concerned, Norton Antivirus is a complete nightmare and always has been. I've tried to live with it, one way or another, for more than ten years, and never yet had the thing work properly. Ho hum.



I do not work in the AV arm of Symantec but Google did manage to find this in around 1/3 of a second:
info
Sounds like you may have a layer 8 problem as I have used NAV for the last 3 years and never had any problems or a Virus! Kaspersky etc may be just as good if not better, I only use it as it's free.

>> Edited by tuffer on Tuesday 20th January 14:15

Thumper

174 posts

281 months

Wednesday 21st January 2004
quotequote all
Thanks for the advice. I still use NAV, but can't set anything on automatic - I just carry out regular checks for viruses. So far (touch wood) I've had very few, and caught all of them before they've done anything nasty.

fish

Original Poster:

4,026 posts

299 months

Wednesday 21st January 2004
quotequote all
Upshot is I'm doing a full rebuild, can't copy it to send to NAV, tried reseting permisions was on read only etc but it just won't do anything.