My Trojan Horse is dead, BUT .....

My Trojan Horse is dead, BUT .....

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
My Trojan Horse is dead, BUT ..... Robert 09-20-2006
Posted by Robert on September 20, 2006, 5:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello everyone, Yes the old nag has at last gone to the knacker's yard.
No thanks to Norton, McAfee, Kaspersky, Sysclean, Spybot, A-squared
and other scanners with which my PC has been excoriated for weeks, in
Safe Mode and Normal, and with System Restore held in abeyance.

In fact the Trojan (W32.Qhosts.df) was found using a tiny little
utility, (donation ware from Mike Lin ( www.mlin.net ), and called
StartUp Control Panel. This tool displays what starts up with Windows
and can stop it doing so. Using it I saw the file C:\WINDOWS\System32\
dmyic.exe not having any obvious connection to my usual software so
decided to block its startup. This immediately prevented the
reinstallation of a Registry Value at each bootup. System Restore was
not the culprit, but this little file.

Can anyone tell me, please, whether this System32\dmyic.exe file is a
genuine Windows file with a job to do or simply a stable for the Horse?
I would like to delete it if possible: the ordure remains offensive.
Advice please. Many thanks.
Robert.


Posted by David H. Lipman on September 20, 2006, 6:00 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hello everyone, Yes the old nag has at last gone to the knacker's yard.
| No thanks to Norton, McAfee, Kaspersky, Sysclean, Spybot, A-squared
| and other scanners with which my PC has been excoriated for weeks, in
| Safe Mode and Normal, and with System Restore held in abeyance.
|
| In fact the Trojan (W32.Qhosts.df) was found using a tiny little
| utility, (donation ware from Mike Lin ( www.mlin.net ), and called
| StartUp Control Panel. This tool displays what starts up with Windows
| and can stop it doing so. Using it I saw the file C:\WINDOWS\System32\
| dmyic.exe not having any obvious connection to my usual software so
| decided to block its startup. This immediately prevented the
| reinstallation of a Registry Value at each bootup. System Restore was
| not the culprit, but this little file.
|
| Can anyone tell me, please, whether this System32\dmyic.exe file is a
| genuine Windows file with a job to do or simply a stable for the Horse?
| I would like to delete it if possible: the ordure remains offensive.
| Advice please. Many thanks.
| Robert.

dmyic.exe is not a legitimate OS file.

I suggest you submit a sample to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition,
unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN

When you get the report, please post back the exact results.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by NewScience on September 20, 2006, 6:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Is there any Version information? Right click | Properties | Version.

> Hello everyone, Yes the old nag has at last gone to the knacker's yard.
> No thanks to Norton, McAfee, Kaspersky, Sysclean, Spybot, A-squared
> and other scanners with which my PC has been excoriated for weeks, in
> Safe Mode and Normal, and with System Restore held in abeyance.
>
> In fact the Trojan (W32.Qhosts.df) was found using a tiny little
> utility, (donation ware from Mike Lin ( www.mlin.net ), and called
> StartUp Control Panel. This tool displays what starts up with Windows
> and can stop it doing so. Using it I saw the file C:\WINDOWS\System32\
> dmyic.exe not having any obvious connection to my usual software so
> decided to block its startup. This immediately prevented the
> reinstallation of a Registry Value at each bootup. System Restore was
> not the culprit, but this little file.
>
> Can anyone tell me, please, whether this System32\dmyic.exe file is a
> genuine Windows file with a job to do or simply a stable for the Horse?
> I would like to delete it if possible: the ordure remains offensive.
> Advice please. Many thanks.
> Robert.
>



Posted by David H. Lipman on September 20, 2006, 7:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Is there any Version information? Right click | Properties | Version.
|

What if it is NOT digitally signed but has faked version information ?

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by NewScience on September 20, 2006, 7:51 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
You never know ... does hurt to check.
You also would get Creation, Access, and Modification dates which may jog
some people's memories.

>
> | Is there any Version information? Right click | Properties | Version.
> |
>
> What if it is NOT digitally signed but has faked version information ?
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>



Similar ThreadsPosted
TROJAN HORSE May 29, 2005, 10:45 pm
How to get rid of a Trojan Horse? September 19, 2006, 11:14 am
trojan horse September 25, 2007, 1:40 am
trojan horse May 27, 2008, 8:16 pm
Bla trojan horse & microsoft February 16, 2006, 9:46 am
Trojan horse Clicker.BGC--------- C:\WINDOWS\system32 January 4, 2006, 1:53 am
Trojan Horse Discovered On Samsung Site September 9, 2006, 10:07 pm
Norton 2006 Finds Trojan Horse in MS Fax Console on initialization September 27, 2006, 12:11 pm
Trojan-Horse PUSHU Cannot be deleted using anti-virus software. April 1, 2007, 11:06 pm
2) Trojan-Horse PUSHU Cannot be deleted using anti-virus software April 3, 2007, 5:28 pm

The site map in XML format XML site map

Contact Us | Privacy Policy