PC Review


Reply
Thread Tools Rate Thread

Downloader.AQW trojan removal

 
 
markp
Guest
Posts: n/a
 
      17th Mar 2006
Hi All,

I'm making this post for others who may have the same problem.

Recently I gained a trojan on my XP Home machine. I have several anti-virus
scanners, but AVG was the only one of my set that recognised it as a problem
(it could heal, but not remove the problem). The symptom is that a file is
created in the Windows\System32 directory named Idxxxx.tmp where xxxx is a
random character string which AVG recognised as a trojan. Further more this
file gets opened and associated with winlogon.exe and so cannot be deleted.

A bit of Googling revealed that this is a downloader trojan, McAfee
describes it of type Downloader.AQW and that a registry entry is made:

http://vil.mcafeesecurity.com/vil/content/v_137110.htm

Sure enough, there was indeed an entry in the registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\policies\explorer\run
"wininet.dll"="dfrgsrv.exe"

This had to be deleted in safe mode, otherwise it just got put right back.
Since then the problem has not returned.

Mark.

(for the benefit of search engines: Id????.tmp <random string>.tmp virus)


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
java/ByteVerify, trojan downloader removal star Windows XP General 4 30th Mar 2008 02:04 AM
Trojan.Downloader.Small.popcorn64 Trojan, PWS Pinch Stealer =?Utf-8?B?cHVwcHkta2liYmxl?= Security and Anti-Spyware Community 4 4th Nov 2005 11:26 PM
Trojan Downloader TargetSavers (Trojan)? Paul Security and Anti-Spyware Community 1 18th Jun 2005 02:11 AM
Trojan Horse Downloader Lookme.A Removal Connie Windows XP Security 1 4th May 2004 10:46 PM
TROJAN DOWNLOADER ELNA Windows XP Security 0 9th Feb 2004 07:31 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 08:42 PM.