PC Review Forums Newsgroups Hardware Anti-Virus Downloader.AQW trojan removal

Reply

Downloader.AQW trojan removal

 
Thread Tools Rate Thread
Old 17-03-2006, 05:56 PM   #1
markp
Guest
 
Posts: n/a
Default Downloader.AQW trojan removal


Hi All,

I'm making this post for others who may have the same problem.

Recently I gained a trojan on my XP Home machine. I have several anti-virus
scanners, but AVG was the only one of my set that recognised it as a problem
(it could heal, but not remove the problem). The symptom is that a file is
created in the Windows\System32 directory named Idxxxx.tmp where xxxx is a
random character string which AVG recognised as a trojan. Further more this
file gets opened and associated with winlogon.exe and so cannot be deleted.

A bit of Googling revealed that this is a downloader trojan, McAfee
describes it of type Downloader.AQW and that a registry entry is made:

http://vil.mcafeesecurity.com/vil/content/v_137110.htm

Sure enough, there was indeed an entry in the registry:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\policies\explorer\run
"wininet.dll"="dfrgsrv.exe"

This had to be deleted in safe mode, otherwise it just got put right back.
Since then the problem has not returned.

Mark.

(for the benefit of search engines: Id????.tmp <random string>.tmp virus)


  Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off