Help needed

Help needed

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Help needed Sue Chaisone 03-13-2007
---> Re: Help needed David H. Lipman03-13-2007
Posted by Sue Chaisone on March 13, 2007, 11:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
A few days ago, I noticed that my computer was slowing down.

As I have a very decent Virus Scanner (Avast) and a good Spyware detector, I
didn't suspect any virus intrusion in my computer system.

But when I did a "Windows Task Manager" run, a file showed-up in the running
processes which was not a program that I had installed.

The file was always "drf1173407703.html", but the digits changed every
time the file was loaded into memory.. Strange was the fact that although it
was a HTML file. it appeared in the "Running Processes".

I tried to do a full search of this file, but Windows could only find the
"drf??????????.html" in my Internet Cache.

I did a clear of the Cache and Internet files, but the file kept
reappearing.

This time I did a more detailled search and found that the file was a HTML
file but renamed to an EXE file when downloaded. The originator of the file
was:

http://216.95.196.22/passthru/th204.exe//drf1173407703.html

CAREFUL: THIS WEBSITE MAY CONTAIN A VIRUS

I have tried everything I could think off, but the file keep appearing in my
system.

AVAST, my virusscanner and my spyware detector have not reacted to this
file.

Does anybody know if this is a virus/trojan and most important how to remove
it?

TIA



Posted by JimR on March 13, 2007, 11:39 am
If you were  Registered and logged in, you could reply and use other advanced thread options
>A few days ago, I noticed that my computer was slowing down.
>
> As I have a very decent Virus Scanner (Avast) and a good Spyware detector,
> I
> didn't suspect any virus intrusion in my computer system.
>
> But when I did a "Windows Task Manager" run, a file showed-up in the
> running processes which was not a program that I had installed.
>
> The file was always "drf1173407703.html", but the digits changed every
> time the file was loaded into memory.. Strange was the fact that although
> it was a HTML file. it appeared in the "Running Processes".
>
> I tried to do a full search of this file, but Windows could only find the
> "drf??????????.html" in my Internet Cache.
>
> I did a clear of the Cache and Internet files, but the file kept
> reappearing.
>
> This time I did a more detailled search and found that the file was a HTML
> file but renamed to an EXE file when downloaded. The originator of the
> file
> was:
>
> http://216.95.196.22/passthru/th204.exe//drf1173407703.html
>
> CAREFUL: THIS WEBSITE MAY CONTAIN A VIRUS
>
> I have tried everything I could think off, but the file keep appearing in
> my
> system.
>
> AVAST, my virusscanner and my spyware detector have not reacted to this
> file.
>
> Does anybody know if this is a virus/trojan and most important how to
> remove it?
>
> TIA
>


It sure is a trojan. Try one of the online scanners like Trend Micro
Housecall.

--
Jim


Posted by MAP on March 13, 2007, 1:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sue Chaisone wrote:
> A few days ago, I noticed that my computer was slowing down.
>
> As I have a very decent Virus Scanner (Avast) and a good Spyware
> detector, I didn't suspect any virus intrusion in my computer system.
>
> But when I did a "Windows Task Manager" run, a file showed-up in the
> running processes which was not a program that I had installed.
>
> The file was always "drf1173407703.html", but the digits changed every
> time the file was loaded into memory.. Strange was the fact that
> although it was a HTML file. it appeared in the "Running Processes".
>
> I tried to do a full search of this file, but Windows could only find
> the "drf??????????.html" in my Internet Cache.
>
> I did a clear of the Cache and Internet files, but the file kept
> reappearing.
>
> This time I did a more detailled search and found that the file was a
> HTML file but renamed to an EXE file when downloaded. The originator
> of the file was:
>
> http://216.95.196.22/passthru/th204.exe//drf1173407703.html
>
> CAREFUL: THIS WEBSITE MAY CONTAIN A VIRUS
>
> I have tried everything I could think off, but the file keep
> appearing in my system.
>
> AVAST, my virusscanner and my spyware detector have not reacted to
> this file.
>
> Does anybody know if this is a virus/trojan and most important how to
> remove it?
>
> TIA

Hi Sue, you are correct it is a trojan, this one.
http://www.google.com/search?hl=en&q=win32%2Fdialer.ri+trojan&btnG=Google+Se
arch

you can sumit the file here for a scan
http://www.kaspersky.com/scanforvirus.html

or scan your entire system here
http://www.kaspersky.com/virusscanner

Avast really isn't that good of a scanner, spend a few $ and have peace of
mind get of of these.
http://www.kaspersky.com/trials?chapter=186685140
http://www.nod32usa.com/nod32-antivirus-trial/

--
Mike Pawlak



Posted by David H. Lipman on March 13, 2007, 4:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


|
| Hi Sue, you are correct it is a trojan, this one.
| http://www.google.com/search?hl=en&q=win32%2Fdialer.ri+trojan&btnG=Google+Se
| arch
|
| you can sumit the file here for a scan
| http://www.kaspersky.com/scanforvirus.html
|
| or scan your entire system here
| http://www.kaspersky.com/virusscanner
|
| Avast really isn't that good of a scanner, spend a few $ and have peace of
| mind get of of these.
| http://www.kaspersky.com/trials?chapter=186685140
| http://www.nod32usa.com/nod32-antivirus-trial/
|

Mike:

In the future, plaese try to obfuscate a malicios URL such that the URL is NOT
clickable and
newbies won't get infected by it.

Example:
hxxp://malicious.site.com

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by MAP on March 13, 2007, 6:26 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
David H. Lipman wrote:

> In the future, plaese try to obfuscate a malicios URL such that the
> URL is NOT clickable and newbies won't get infected by it.
>
> Example:
> hxxp://malicious.site.com

Good Point!
--
Mike Pawlak



Similar ThreadsPosted
Virus Help Needed Bad November 12, 2006, 12:20 pm
Help needed ASAP - secure 32 May 18, 2006, 10:54 am
The much anticipated and needed patch will be available in about 2 hours January 5, 2006, 3:00 pm
simulation virus spread, thesis information needed September 20, 2006, 1:16 am

The site map in XML format XML site map

Contact Us | Privacy Policy