Downloader.AQW trojan removal

Downloader.AQW trojan removal

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Downloader.AQW trojan removal markp 03-17-2006
Posted by markp on March 17, 2006, 12:56 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi All,

I'm making this post for others who may have the same problem.

Recently I gained a trojan on my XP Home machine. I have several anti-virus
scanners, but AVG was the only one of my set that recognised it as a problem
(it could heal, but not remove the problem). The symptom is that a file is
created in the Windows\System32 directory named Idxxxx.tmp where xxxx is a
random character string which AVG recognised as a trojan. Further more this
file gets opened and associated with winlogon.exe and so cannot be deleted.

A bit of Googling revealed that this is a downloader trojan, McAfee
describes it of type Downloader.AQW and that a registry entry is made:

http://vil.mcafeesecurity.com/vil/content/v_137110.htm

Sure enough, there was indeed an entry in the registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\policies\explorer\run
"wininet.dll"="dfrgsrv.exe"

This had to be deleted in safe mode, otherwise it just got put right back.
Since then the problem has not returned.

Mark.

(for the benefit of search engines: Id????.tmp <random string>.tmp virus)



Similar ThreadsPosted
Help with Trojan Removal June 20, 2005, 12:31 am
SpamThru Trojan detection and removal...?? November 24, 2006, 12:03 am
Virus removal help requested -- Trojan.Bat.Noshare.K August 30, 2005, 10:02 pm
Trojan.downloader.BHO.req August 27, 2005, 8:54 pm
Downloader.Trojan December 7, 2005, 5:35 am
How to get rid of trojan downloader July 21, 2006, 10:02 pm
Downloader.Trojan August 25, 2006, 9:43 am
Trojan horse Downloader.Generic.ML June 15, 2005, 4:32 pm
Trojan-Downloader.Win32.Agent.abj January 9, 2006, 5:52 pm
Trojan Horse Downloader.Generic2.CCY Help Please! June 21, 2006, 12:13 pm

The site map in XML format XML site map

Contact Us | Privacy Policy