Re: Downloader-VA trojan??????

From: number1 (number1_at_blazemail.com)
Date: 02/17/05


Date: 17 Feb 2005 08:29:21 -0800

I had been fighting this same problem for the last several days, and
finally found the solution. This trojan seems to attach itself to
Internet Explorer as a helper program, and then when you launch IE, it
reinfects your computer. McAfee does detect the virus, but it does not
disinfect properly, at least it didn't for me.

First, be sure to turn off System Restore, because you will be deleting
some dll and sys files, and they may get restored automatically if you
don't.

Second, get a copy of the program StartupList from
http://www.spywareinfo.com/~merijn/downloads.html
You'll find it in the section labelled "Official Downloads".

Then, run the program. It will give you a lot of information about
programs that are starting up when your computer boots. Most of the
info you can ignore. Look for the section about Browser Helper Objects.
Here is what I found on my computer:

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Adobe\Acrobat
6.0\Reader\ActiveX\AcroIEHelper.dll -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\WINDOWS\system32\xxculexp.dll -
{B2DF6264-FC5B-84D1-094D-3458CCC5331F}
(no name) - C:\WINDOWS\system32\cdafzfyu.dll -
{B3DCBF91-161B-0EC2-0358-4571A56E7459}

In my case, I deleted the two strange programs xxculexp.dll and
cdafzfyu.dll. I suspect that the names are randomly generated, so yours
will probably be different.

Then, check the Microsoft article at:
http://support.microsoft.com/?scid=kb;en-us;894278
and delete files that it refers to that you find. For example, I had
msupd6.exe, as well as cjoxroft.sys, and deleted those. Again, the
names assigned to your particular version of the trojan are probably
different.

Finally, go into Regedit, and delete any instances of any programs that
are like the ones that you deleted. So, I deleted any keys that
referred to xxcuplexp.dll, cdafzfuy.dll, msupd6.exe, and cjoxroft.sys.

Now, close Regedit and reboot the computer. Restart IE, and make sure
everything now works normally. Then turn System Restore back on.

Good luck. This seems to be a very nasty one.

Wouter wrote:
> Hello,
> Since a few days I get a warning from my
> virusscanner McAfee that the file:
> D:\Windows\system\drivers\hlmsfrd.sys
> was infected bij the downloader-VA
> trojan. It occurs everytime I start
> my internet or my mailprogram.
> I could not find where it comes from.
> Please, does anyone know a solution
> for me? Where can i remove it permentley?



Relevant Pages

  • Re: Downloader-VA trojan??????
    ... Number1 thanks for the info on startlist. ... This trojan seems to attach itself to ... Look for the section about Browser Helper Objects. ... Then turn System Restore back on. ...
    (microsoft.public.security.virus)
  • Re: My account was hacked, I would like to share my story to warn others.
    ... guildportal.com got attacked and a trojan was embedded in the welcome messages of some guild's websites. ... Now I keep seeing people saying this only affected people who haven't updated their Internet Explorer in 6 months and didn't have an antivirus program running... ... I have a firewall running on my router, I have Sygate Personal firewall running on this computer, I have AVG Pro, up to date running, and I ALWAYS make sure my Windows updates are current. ... So my wife logged in on her account and checked through the guild list when my character was last online. ...
    (comp.sys.mac.advocacy)
  • Re: GONE! Trojan Horse Downloader.agent.2.BK
    ... I think the trojan is gone! ... disabled system restore according to the instructions, ... Lo and behold, AVG ... >updated antivirus, in safe mode if you want, you ...
    (microsoft.public.security.virus)
  • Re: Torjan and Virus
    ... But how do I know if its in that one folder? ... So If I do a disk cleanup on system restore, will it just get rid of that ... > A trojan is a specific type of virus - a program that pretends to be ... If you want to speed up this process use Disk Cleanup on the ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: MT CHAT - Anyone know what happened?
    ... | It's a trojan bot that's been around on a number of websites - I ... Before the computer went completely down, Ad-Aware said at ... least part of the trojan was in the system restore files, ... which enables me to run IE "natively" in Firefox. ...
    (sci.med.transcription)