Help needed

Help needed

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Help needed Sue Chaisone 03-13-2007
---> Re: Help needed David H. Lipman03-13-2007
Posted by David H. Lipman on March 13, 2007, 5:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| David H. Lipman wrote:
|
>> In the future, plaese try to obfuscate a malicios URL such that the
>> URL is NOT clickable and newbies won't get infected by it.
>>
>> Example:
>> hxxp://malicious.site.com
|
| Good Point!

Believe me, I have made that mistake myself.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Sue Chaisone on March 13, 2007, 11:34 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Sue Chaisone wrote:
>> A few days ago, I noticed that my computer was slowing down.
>>
>> As I have a very decent Virus Scanner (Avast) and a good Spyware
>> detector, I didn't suspect any virus intrusion in my computer system.
>>
>> But when I did a "Windows Task Manager" run, a file showed-up in the
>> running processes which was not a program that I had installed.
>>
>> The file was always "drf1173407703.html", but the digits changed every
>> time the file was loaded into memory.. Strange was the fact that
>> although it was a HTML file. it appeared in the "Running Processes".
>>
>> I tried to do a full search of this file, but Windows could only find
>> the "drf??????????.html" in my Internet Cache.
>>
>> I did a clear of the Cache and Internet files, but the file kept
>> reappearing.
>>
>> This time I did a more detailled search and found that the file was a
>> HTML file but renamed to an EXE file when downloaded. The originator
>> of the file was:
>>
>> http://216.95.196.22/passthru/th204.exe//drf1173407703.html
>>
>> CAREFUL: THIS WEBSITE MAY CONTAIN A VIRUS
>>
>> I have tried everything I could think off, but the file keep
>> appearing in my system.
>>
>> AVAST, my virusscanner and my spyware detector have not reacted to
>> this file.
>>
>> Does anybody know if this is a virus/trojan and most important how to
>> remove it?
>>
>> TIA
>
> Hi Sue, you are correct it is a trojan, this one.
> http://www.google.com/search?hl=en&q=win32%2Fdialer.ri+trojan&btnG=Google+Se
> arch
>
> you can sumit the file here for a scan
> http://www.kaspersky.com/scanforvirus.html
>
> or scan your entire system here
> http://www.kaspersky.com/virusscanner
>
> Avast really isn't that good of a scanner, spend a few $ and have peace of
> mind get of of these.
> http://www.kaspersky.com/trials?chapter=186685140
> http://www.nod32usa.com/nod32-antivirus-trial/

I have Kaspersky Virus Lab on my second partition, and the virus is neither
detected by Kaspersky.

It seems that the virs has some routine to included to turn off the virus
scanners.

In Avast, I have noticed that the HTML files are in the exceptions (no to be
scanned) and there is NO WAY to turn this off.

I also noticed that somefiles which have approximative the same size as the
Virus are suddenly loaded into my computer system.

One of these files is VERCLSID.EXE-3667BD80.pf in the Windows\Prefetch
folder.
Deleting this file, brings them back immediatly.

I have the feeling that the only way to get rid of this Trojan is by
performing a scan of my system from OUTSIDE my system in order to prevent
the Trojan to diasble the virus checker or to have a trojan remover which
cannotbe fooled.

Regards,



> --
> Mike Pawlak
>
>




Posted by MAP on March 14, 2007, 10:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sue Chaisone wrote:


> I have Kaspersky Virus Lab on my second partition, and the virus is
> neither detected by Kaspersky.


Your version must be out of date!




Complete scanning result of "drf1173407703.html", processed in VirusTotal at
03/13/2007 21:41:23
(CET).

[ file data ]
* name: drf1173407703.EXE
* size: 10414
* md5.: a3712b5f7f0af3c53e12aa7f26b01199
* sha1: da4a28a85256c76587248f59d44704e28b3646f5

[ scan result ]
AntiVir 7.3.1.41/20070313 found [TR/Dialer.RI]
Authentium 4.93.8/20070313 found [W32/Trojan.SSN]
Avast 4.7.936.0/20070312 found nothing
AVG 7.5.0.447/20070313 found [Dialer.CKN]
BitDefender 7.2/20070313 found [Trojan.Dialer.RI]
CAT-QuickHeal 9.00/20070313 found [Trojan.Dialer.ri]
ClamAV devel-20060426/20070313 found [Dialer-731]
DrWeb 4.33/20070313 found nothing
eSafe 7.0.14.0/20070313 found [suspicious Trojan/Worm]
eTrust-Vet 30.6.3474/20070313 found nothing
Ewido 4.0/20070313 found [Trojan.Dialer.ri]
F-Prot 4.3.1.45/20070313 found [W32/Trojan.SSN]
F-Secure 6.70.13030.0/20070313 found [Trojan.Win32.Dialer.ri]
FileAdvisor 1/20070313 found nothing
Fortinet 2.85.0.0/20070313 found nothing
Ikarus T3.1.1.3/20070313 found [Trojan.Win32.Dialer.ri]
Kaspersky 4.0.2.24/20070313 found [Trojan.Win32.Dialer.ri]
McAfee 4983/20070313 found nothing
Microsoft 1.2306/20070313 found nothing
NOD32v2 2113/20070313 found [Win32/Dialer.RI]
Norman 5.80.02/20070313 found [W32/Dialer.AXLX]
Panda 9.0.0.4/20070313 found [Dialer.ITP]
Prevx1 V2/20070313 found [Downloader.Drev.A]
Sophos 4.15.0/20070313 found [Dial/Dialer-DY]
Sunbelt 2.2.907.0/20070310 found nothing
Symantec 10/20070313 found [Dialer.Generic]
TheHacker 6.1.6.074/20070312 found [Trojan/Dialer.ri]
UNA 1.83/20070313 found [Trojan.Win32.Dialer.9E10]
VBA32 3.11.2/20070313 found [Trojan.Win32.Dialer.ri]
VirusBuster 4.3.19:9/20070312 found [Trojan.Dialer.UY

--
Mike Pawlak



Posted by David H. Lipman on March 13, 2007, 4:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| A few days ago, I noticed that my computer was slowing down.
|
| As I have a very decent Virus Scanner (Avast) and a good Spyware detector, I
| didn't suspect any virus intrusion in my computer system.
|
| But when I did a "Windows Task Manager" run, a file showed-up in the running
| processes which was not a program that I had installed.
|
| The file was always "drf1173407703.html", but the digits changed every
| time the file was loaded into memory.. Strange was the fact that although it
| was a HTML file. it appeared in the "Running Processes".
|
| I tried to do a full search of this file, but Windows could only find the
| "drf??????????.html" in my Internet Cache.
|
| I did a clear of the Cache and Internet files, but the file kept
| reappearing.
|
| This time I did a more detailled search and found that the file was a HTML
| file but renamed to an EXE file when downloaded. The originator of the file
| was:
|
| http://<snip>
|
| CAREFUL: THIS WEBSITE MAY CONTAIN A VIRUS
|
| I have tried everything I could think off, but the file keep appearing in my
| system.
|
| AVAST, my virusscanner and my spyware detector have not reacted to this
| file.
|
| Does anybody know if this is a virus/trojan and most important how to remove
| it?
|
| TIA
|

That is a malicious URL. Whenever posting a possible malicious URL obfuscate it
such as...

hxxp://malicious.site.com

This way it is NOT clickable and won't infect newbies!

Complete scanning result of "drf1173407703.html", processed in VirusTotal at
03/13/2007 21:41:23
(CET).

[ file data ]
* name: drf1173407703.EXE
* size: 10414
* md5.: a3712b5f7f0af3c53e12aa7f26b01199
* sha1: da4a28a85256c76587248f59d44704e28b3646f5

[ scan result ]
AntiVir 7.3.1.41/20070313 found [TR/Dialer.RI]
Authentium 4.93.8/20070313 found [W32/Trojan.SSN]
Avast 4.7.936.0/20070312 found nothing
AVG 7.5.0.447/20070313 found [Dialer.CKN]
BitDefender 7.2/20070313 found [Trojan.Dialer.RI]
CAT-QuickHeal 9.00/20070313 found [Trojan.Dialer.ri]
ClamAV devel-20060426/20070313 found [Dialer-731]
DrWeb 4.33/20070313 found nothing
eSafe 7.0.14.0/20070313 found [suspicious Trojan/Worm]
eTrust-Vet 30.6.3474/20070313 found nothing
Ewido 4.0/20070313 found [Trojan.Dialer.ri]
F-Prot 4.3.1.45/20070313 found [W32/Trojan.SSN]
F-Secure 6.70.13030.0/20070313 found [Trojan.Win32.Dialer.ri]
FileAdvisor 1/20070313 found nothing
Fortinet 2.85.0.0/20070313 found nothing
Ikarus T3.1.1.3/20070313 found [Trojan.Win32.Dialer.ri]
Kaspersky 4.0.2.24/20070313 found [Trojan.Win32.Dialer.ri]
McAfee 4983/20070313 found nothing
Microsoft 1.2306/20070313 found nothing
NOD32v2 2113/20070313 found [Win32/Dialer.RI]
Norman 5.80.02/20070313 found [W32/Dialer.AXLX]
Panda 9.0.0.4/20070313 found [Dialer.ITP]
Prevx1 V2/20070313 found [Downloader.Drev.A]
Sophos 4.15.0/20070313 found [Dial/Dialer-DY]
Sunbelt 2.2.907.0/20070310 found nothing
Symantec 10/20070313 found [Dialer.Generic]
TheHacker 6.1.6.074/20070312 found [Trojan/Dialer.ri]
UNA 1.83/20070313 found [Trojan.Win32.Dialer.9E10]
VBA32 3.11.2/20070313 found [Trojan.Win32.Dialer.ri]
VirusBuster 4.3.19:9/20070312 found [Trojan.Dialer.UY]

[ notes ]
packers: UPX
packers: UPX
packers: UPX
Prevx info: http://fileinfo.prevx.com/fileinfo.asp?PXC=d0e081584451


As you can see from the above Virus Total report, Avast does NOT recognize this.
I will submit this Trojan Dialer to Avast on your behalf.

Sophos and Kaspersky recognize this Trojan Dialer.

Start with the Sophos module in the below Multi AV Scanning Tool.

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *




--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Sue Chaisone on March 14, 2007, 11:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options

<snipped>

> That is a malicious URL. Whenever posting a possible malicious URL
> obfuscate it such as...
> hxxp://malicious.site.com
> This way it is NOT clickable and won't infect newbies!

Sorry, I didn't know that.
Thanks for the tip.

> As you can see from the above Virus Total report, Avast does NOT recognize
> this.
> I will submit this Trojan Dialer to Avast on your behalf.

I did send an email to AVAST, but without response from AVAST (see below).
So far from their "services".

Subject: Trojan Horse?
Date: Sat, 10 Mar 2007 08:51:49 +0700

Dear Sirs,

I have installed Avast Anti-Virus a few months ago thinking that my computer
would be safe.

Last week my computer was slowing down, getting on the Internet was a realy
next to impossible and my ISP provider was disconnecting me becuase my
bandwith was exceeded.

So, I tried to find out what was causing this slowdown and found a strange
file in my Internet Explorer cache.

I have tried to delete the file, but it kept coming back after a delete.

A search of the location of the file shows 8 files located in the directory
216.95.196.22 but there is no such directory on my harddisk.

The link to this file is:

http://216.95.196.22/passthru/th204.exe//drf1173407703.html

I would like to know:

1. Why is this file not detected by my Anti-Virus software?
2. How do I remove this file permanently] and posible other viruses?
3. Is there a way to find out where this "Trojan Horse Dialer" was sending
the files to in order to sue the perpetrator?

Regards,



Similar ThreadsPosted
Virus Help Needed Bad November 12, 2006, 12:20 pm
Help needed ASAP - secure 32 May 18, 2006, 10:54 am
The much anticipated and needed patch will be available in about 2 hours January 5, 2006, 3:00 pm
simulation virus spread, thesis information needed September 20, 2006, 1:16 am

The site map in XML format XML site map

Contact Us | Privacy Policy