New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1193
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin   Your Favorite ForumsFavForums 

Three "Probable Trojan" files found

 
Post new topic   Reply to topic       All -> FavForums -> TrojanHunter
View previous topic :: View next topic  
Author Message
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3565
Location: Ottawa, Ontario, Canada

PostPosted: Wed Apr 14, 2004 2:16 am    Post subject: Three "Probable Trojan" files found
Reply with quote

I ran a TH scan on my kid's PC and found a two trojans. TH cleaned them out but three "probable trojans" remain. (did add a different extension to inactivate them). I've attached the log file as well as the three files (with orginal .exe extensions) in a zip file.


th.zip
 Description:
Scan Log and three suspect files

Download
 Filename:  th.zip
 Filesize:  73.28 KB
 Downloaded:  29 Time(s)


_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
claire

Site Moderator
Site Moderator
Premium Member
Premium Member


Joined: Apr 21, 2002
Posts: 4878
Location: Belgium

PostPosted: Wed Apr 14, 2004 11:29 am    Post subject:
Reply with quote

Hi Ikeb,

Could you send the files ?

Magnus will answer you asap and tell you if these are real trojans and how to fix it if needed

_________________
Carpe Diem
Back to top
View users profile Send private message
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3565
Location: Ottawa, Ontario, Canada

PostPosted: Wed Apr 14, 2004 2:37 pm    Post subject:
Reply with quote

Done.
_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3565
Location: Ottawa, Ontario, Canada

PostPosted: Fri Apr 16, 2004 4:27 am    Post subject:
Reply with quote

I realized today that there's still some funny business going on. Now when I sign on to an account on this machine, explorer brings up the desktop but then goes away. There's some sort of text msg on a black background screen. Doing the three finger salute gets me to the Task Manager, where I see two applications: Task Manager and Explorer (not responding). When Task Manager is brought up, the task bar appears as well, so I can open a WE window.

When I go to C:\WINNT.XP\system32\ I now find an a.exe and explore.exe as well as the a.exe.tmp and explore.exe.tmp I left there! Same dates as the previous files. No new wnscpsv.exe was placed there though.

Also, when I have Task Manager end the nonresponding Explore task, suddenly my desktop reappears and everything seems normal again. Weird.

BTW, I haven't received a response to my email yet. How long does it normally take to get files analyzed?

_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
Jamming

Colonel
Colonel
Premium Member
Premium Member


Joined: Jun 22, 2002
Posts: 1874

PostPosted: Fri Apr 16, 2004 6:30 am    Post subject:
Reply with quote

It might be monday, before you hear. Usually sooner than that, but with number of new items out there its becoming more of an interest to add potential trojans definitions, rather than communicate often. Trojans and Malware are at an all time high.
Back to top
View users profile Send private message
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3565
Location: Ottawa, Ontario, Canada

PostPosted: Wed Apr 21, 2004 1:24 am    Post subject:
Reply with quote

It's now Wednesday and haven't heard back. Is Magnus taking a vacation perhaps?
_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
Jamming

Colonel
Colonel
Premium Member
Premium Member


Joined: Jun 22, 2002
Posts: 1874

PostPosted: Wed Apr 21, 2004 1:54 am    Post subject:
Reply with quote

I will contact him for you.
Back to top
View users profile Send private message
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3565
Location: Ottawa, Ontario, Canada

PostPosted: Wed Apr 21, 2004 4:14 am    Post subject:
Reply with quote

Thanks Jamming. I'd like to get this resolved since I suspect the system is going downhill and these possible trojans may be the reason.
_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
Jamming

Colonel
Colonel
Premium Member
Premium Member


Joined: Jun 22, 2002
Posts: 1874

PostPosted: Thu Apr 22, 2004 4:00 am    Post subject:
Reply with quote

I don't know what exactly is going on, but I have not heard back from him yet. I'll try again.
Back to top
View users profile Send private message
Magnus

TrojanHunter
TrojanHunter



Joined: Sep 02, 2003
Posts: 46
Location: Sweden

PostPosted: Thu Apr 22, 2004 2:01 pm    Post subject:
Reply with quote

I'm terribly sorry for the long delay - things are insanely busy here at the moment. Here's the data on those files:

wnscpsv.exe: This is adware. Delete the file and/or run an adware remover.

explore.exe and a.exe: This is a worm (Hawawi). See http://securityresponse.symantec.com/av....worm.html for removal instructions.
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> TrojanHunter All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops