»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 07-29-2003, 12:08 PM   #1 (permalink)
Registered User
 
Join Date: May 2003
Location: Morehead City, NC
Posts: 219
ChrisK2972 is on a distinguished road
Do you have this folder?

Will anyone with W2K Pro check your WINNT folder for me and see if you have a folder listed named: autoupd

I scanned with House call last night and it identified a trojan in that folder called Small.J I allowed House call to delete the file and now I am wondering what it was. I have another machine here that is running W2K and that folder is not on that machine at all. The file that was deleted was named: upd.exe

thanks

ChrisK2972 is offline   Reply With Quote
Old 07-29-2003, 12:10 PM   #2 (permalink)
Registered User
 
Martoch's Avatar
 
Join Date: Mar 2002
Location: Ft. Walton Beach, FL
Posts: 4,056
Martoch is on a distinguished road
Send a message via AIM to Martoch
No such folder on ANY of our 2K Pro systems here...over 30 total too. Bye bye folder!


Mike
Martoch is offline   Reply With Quote
Old 07-29-2003, 12:19 PM   #3 (permalink)
Guest
Guest
 
Posts: n/a
http://www.trendmicro.com/vinfo/viru...e=TROJ_SMALL.J thats the description of the virus. maybe its makes the folder itself?
  Reply With Quote
Old 07-29-2003, 12:49 PM   #4 (permalink)
Registered User
 
Join Date: May 2003
Location: Morehead City, NC
Posts: 219
ChrisK2972 is on a distinguished road
Groundzero3, I think you are right. House call probablly got rid of the trojan itself, but, left the folder behind. I have scanned with several other virus scanners as well as several dedicated trojan scanners and nothing. So, I am going to delete the folder and see what happens. It is not empty; has some ocx and dll files and such. But, the machine has a very small program configuration right now and I know it was not deposited by any legit program that I have. So, wish me luck....

Thanxs, Martoch, for checking. I really appreciate it.
__________________
ChrisK> Certified computer crash dummy. Got a tweak you've never tried? Give it to me; if I can't crash it, it cannot be crashed!
ChrisK2972 is offline   Reply With Quote
Old 07-29-2003, 12:59 PM   #5 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
may want to check the registry for those files

.ocx is an activex control that can be called from other applications.

make sure there's nothing in the RUN key of the registry
__________________
<< Insert exceedingly large and overly verbose message of how 1337 you are here including full specs of every vehicle you've ever driven and PC you've owned >>
vass0922 is offline   Reply With Quote
Old 07-29-2003, 01:20 PM   #6 (permalink)
Registered User
 
Join Date: May 2003
Location: Morehead City, NC
Posts: 219
ChrisK2972 is on a distinguished road
yeah, I just checked it. The registry is clear. Just in case, I have not removed the folder from the recycle bin. Want to make sure all is ok. However, it stands to reason that if the folder was created by the trojan itself, then anything within would be related. Is that logical?

I am pretty sure where I picked it up. When I grabbed the Omega Drivers for my nVidia card, there was a warning about a mirror site that installed a "dialer.exe" file. I think I must have clicked the wrong site and boom, it got me. I went there today and they must have deleted the mirror because the warning is gone. Oh well, it appears to be ok. Luckily it had not been fully executed. I am concerned, however, that my Panda Titanium AV did not catch it. This is the first thing that I know of that has gotten past it. I usually do house call once a week in conjunction with Panda. So, I guess I cannot complain. But, it is not listed in their virus file, so I emailed them.

Thanxs again for the quick responses and help!!!
__________________
ChrisK> Certified computer crash dummy. Got a tweak you've never tried? Give it to me; if I can't crash it, it cannot be crashed!
ChrisK2972 is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 01:42 AM.