Re: Trojan.Dropper: tempms.exe

Re: Trojan.Dropper: tempms.exe

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Re: Trojan.Dropper: tempms.exe chuck 01-09-2007
Posted by chuck on January 9, 2007, 4:28 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for your help. I have run the scan in safe mode with Symantec AV.
Nothing found.
I then reboot. Install and scan with SpyBot. There are several registry
entries found and destroyed. But the winxx.exe still got replicated like
crazy in my "\Documents and Settings\,user name>\local settings\temp folder.
I then installed Node32. I scanned the hard disk with Nod32. No threat was
found.

Now I keep having a dialog popping up from Nod32.

http://www.ucdq.com/k.exe
Probably unkonown NewHeur_PE virus

I chose to terminate it. But the dialog keeps coming up. I keeps killing it.

Have you heard of this virus?

I checked Google for www.ucdq.com. All the articles are in Chinese. It looks
like a Asian virus.



> "chuck" wrote:
>
>> My Symantec Antivirus always warns me of a Trojan.Dropper in
>> c:\Windows\System32\tempms.exe. But I could not find that file in that
>> folder.
>>
>> Does anyone know what went wrong? Is it related to the replicating
>> winxx.exe
>> files in my temp folder as I post in a different post?
>>
>>
>
>
> Hello .
>
> Boot your computer in Safe Mode . Disable System Restore and perform full
> scan with Symantec AV .
>
> After you reboot , perform the Malware removal instructions here
> http://pandaman.my.contact.bg
>
> Let us know what happened :-)
>
>
> --
> Panda_man
> Silver level Contributor
>>
>>
>>



Posted by =?Utf-8?B?UGFuZGFfbWFu?= on January 9, 2007, 5:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options
"chuck" wrote:

> Thanks for your help. I have run the scan in safe mode with Symantec AV.
> Nothing found.
> I then reboot. Install and scan with SpyBot. There are several registry
> entries found and destroyed. But the winxx.exe still got replicated like
> crazy in my "\Documents and Settings\,user name>\local settings\temp folder.
> I then installed Node32. I scanned the hard disk with Nod32. No threat was
> found.
>
> Now I keep having a dialog popping up from Nod32.
>
> http://www.ucdq.com/k.exe
> Probably unkonown NewHeur_PE virus
>
> I chose to terminate it. But the dialog keeps coming up. I keeps killing it.
>
> Have you heard of this virus?
>
> I checked Google for www.ucdq.com. All the articles are in Chinese. It looks
> like a Asian virus.
>


Hello . This pop-up comes from IMON , the internet monitoring of NOD32 .
Most likely you have a trojan-dropper trying to drop something nasty . NOD32
detects the dropped part but cannot detect the exact dropper . This (Probably
unkonown NewHeur_PE virus) is a new unknown virus which NOD32 detects thanks
to emulation , its advanced heuristics . Thanks for it , I'll submit it to
ESET and other vendors .

In the meantime , you need to open VirusTotal http://www.virustotal.com
and submit this file "winxx.exe" and everyother you suspect . Browse to that
file and follow the instructions . VirusTotal is a free service which allows
you to scan files with lots of reputable AV vendors with latest definitions .

Then , use Ewido Micro which I offer you in the page
http://pandaman.my.contact.bg , it could detect this trojan dropper .

Post again what programs detect winxx.exe and what happended with Ewido's scan



--
Panda_man
Silver level Contributor

Posted by =?Utf-8?B?UGFuZGFfbWFu?= on January 9, 2007, 6:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> "chuck" wrote:

> > Now I keep having a dialog popping up from Nod32.
> >
> > www.ucdq.com/k.exe
> > Probably unkonown NewHeur_PE virus


Hello chuck . Just to let you know I have updated registered NOD32 and when
I clicked that link NOD32 detected is a known trojan Legendmir . I submitted
it to VirusTotal . It seems your trial NOD32 is not up-to-date so need to
update it.Try thr other suggestions .


--
Panda_man
Silver level Contributor

Similar ThreadsPosted
Re: Trojan.Dropper: tempms.exe January 9, 2007, 4:08 pm
Trojan Dropper Agent 8 B Help August 9, 2005, 9:21 pm
Re: Trojan Dropper Agent 8 B Help August 9, 2005, 10:44 pm
Re: Trojan Dropper Agent 8 B Help August 10, 2005, 12:39 pm
Re: Trojan Horse Dropper.small.28.AU virus May 20, 2006, 12:13 am
Trojan August 2, 2005, 8:42 pm
Trojan August 19, 2005, 6:31 pm
trojan by icq November 4, 2005, 6:40 am
Trojan November 7, 2005, 3:45 pm
trojan November 8, 2005, 3:46 pm

The site map in XML format XML site map

Contact Us | Privacy Policy