Re: Trojan horse Downloader.Generic.ML
From: Jim Byrd (jrbyrd_at_spamlessadelphia.net)
Date: 06/15/05
- Next message: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- Previous message: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- In reply to: Ron Reaugh: "Trojan horse Downloader.Generic.ML"
- Next in thread: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- Reply: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 15 Jun 2005 12:02:20 -0700
Hi Ron - You might want to download and run the free or trial version of A2
Personal, here: http://www.emsisoft.com/en/ UPDATE, then run from a Clean
Boot or Safe Mode with Show Hidden Files enabled. This is a MUCH better
piece of software for detecting Trojans than AVG.
Directions for a Clean Boot and Show Hidden Files in my Blog, addy in
Signature.
-- Regards, Jim Byrd, MS-MVP My, Blog Defending Your Machine, here: http://defendingyourmachine.blogspot.com/ "Ron Reaugh" <ron-reaugh@worldnet.att.net> wrote in message news:EKYre.963481$w62.31381@bgtnsc05-news.ops.worldnet.att.net > It's the file C:\NULL > > Suddenly shortly after cold boot my fully updated(WinUp) and patched > W98se PC reported the above noted infection. It's Grisoft free AVG > with the latest updates. This PC is also protected by ZoneAlarm, > Belkin WiFi router with firewall, SpyBot(resident). A normal > Shutdown was done 12 hours earlier with no indication of any > problems. There are still no indications of any problems EXCEPT that > AVG claims it's found this trojan. There have been no floppy > operations/mounts, no CD operations/mounts and no downloads and > installs of anything since an hour before shutdown last night and > now. > > From the DOS prompt I can see a file C:\NULL that has a 5/5/05 date. > Since 5/5 both a full manual AVG and Trend HouseCall 6 run have been > done on this PC finding nothing. > > So where and how did this file C:\NULL that AVG claims is Trojan horse > Downloader.Generic.ML appear from? Was it really there since 5/5 but > went unnoticed by both AVG and Trend HouseCall 6 and then this > morning AVG suddenly downloaded a new definition file which started > seeing this trojan? OR did something penetrate all the firewalls and > suddenly spawn this file which AVG quickly recognized? > > What likely happened here? > > The operation I was in the middle of when AVG popped up was reading a > text only no attachment NG message in OE 6.00.2800.1123.
- Next message: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- Previous message: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- In reply to: Ron Reaugh: "Trojan horse Downloader.Generic.ML"
- Next in thread: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- Reply: Ron Reaugh: "Re: Trojan horse Downloader.Generic.ML"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|