View previous topic :: View next topic |
Author |
Message |
Terra (Red) Trick Member
Joined: 24 Jan 2002
|
0. Posted: Tue Dec 21, 2004 12:36 am Post subject: Important concerning DDR Freak & Pop-ups (Trojan) |
|
|
My AVG free edition just detected a trojan virus from a pop-up.
"Trojan Horse Downloader.SecondThought.A"
The path was:
C:\DOCUME~1\Lance\LOCALS~1\Temp\adlinstallwin32.exe
12/21/04 at 3:06am est
File is adlinstallwin32.exe, file size is 93.5kb.
It came up as a browser plugin of some sort I believe. I hope this helps you guys too. |
|
Back to top |
|
|
J Dogg Administrator
Joined: 16 Jan 2002 Location: Sunnyvale, CA |
1. Posted: Tue Dec 21, 2004 12:49 am Post subject: |
|
|
any URL you can provide? _________________
|
|
Back to top |
|
|
Terra (Red) Trick Member
Joined: 24 Jan 2002
|
2. Posted: Tue Dec 21, 2004 1:07 am Post subject: |
|
|
I'm looking thru AVG right now. This is about all I can find as of now.
C:\Documents and Settings\Lance\Local Settings\Tempoary Inenternet Files\Content.IE5\8523O92Z\id201{1}.exe
This is from what AVG called a backup copy. |
|
Back to top |
|
|
eyebrowsoffire Trick Member
Joined: 23 Sep 2004 Location: Santa Barbara, CA |
3. Posted: Tue Dec 21, 2004 2:47 pm Post subject: |
|
|
Same thing happened to me. Stupid Internet Explorer and Windows XP. I can't wait until I get back to my own computer, with Firefox and Linux... _________________
|
|
Back to top |
|
|
Terra (Red) Trick Member
Joined: 24 Jan 2002
|
4. Posted: Thu Dec 30, 2004 6:52 pm Post subject: |
|
|
Here's a pic of the damned thing here:
|
|
Back to top |
|
|
VxJasonxV Maniac Member
Joined: 08 Feb 2002 Location: Castle Rock, CO |
5. Posted: Thu Dec 30, 2004 7:37 pm Post subject: |
|
|
You should have moved the installer window so we could see the banner ad too . _________________
|
|
Back to top |
|
|
RevenG-D Trick Member
Joined: 07 Nov 2004
|
6. Posted: Thu Dec 30, 2004 8:52 pm Post subject: |
|
|
yea this also happned to me i turned off my antivirus program for a bit.. then i visited this site and i had about 12 new icons on my dekstop and a ton of installer crap showing up... i got rid of it though _________________
|
|
Back to top |
|
|
[DMB]dman.exe Trick Member
Joined: 28 Mar 2003
|
7. Posted: Sun Jan 02, 2005 11:25 am Post subject: |
|
|
I got the same Trojan - with that same popup and same secruity thing. _________________
hi |
|
Back to top |
|
|
rampage Administrator
Joined: 24 Jan 2002 Location: Redmond, WA |
8. Posted: Thu Jan 06, 2005 2:21 pm Post subject: |
|
|
.. and shame on you guys for not running XP SP2. |
|
Back to top |
|
|
Spike Administrator
Joined: 17 Jan 2002 Location: Denver |
9. Posted: Thu Jan 06, 2005 3:37 pm Post subject: |
|
|
rampage wrote: | .. and shame on you guys for not running XP SP2. |
That thing made a couple of my programs not work. I deleted it instead of bothering to figure out how to get said programs to work. Yay for nothing bad happening. _________________
|
|
Back to top |
|
|
Mr. A Trick Member
Joined: 20 Oct 2003 Location: INTERNET |
10. Posted: Fri Jan 07, 2005 7:24 am Post subject: |
|
|
With all due respect (to the above person- what the hell is/was your name?) and not to sound like schadenfreude, isn't this the second or third time this happened?
Anyways, does anyone know the specific security settings or registry tweak (besides the SP2 thing, that would probably fix it, or Firefox) for MSIE to kill those damn things? BTW, did this infection require you to confirm through an installer like that or was it more automatic?
How bad was the infection, was it cleanable? I'm fairly sure (not 100% certain, to be fair) got dyfuca from here on two computers, very nasty infection. |
|
Back to top |
|
|
VxJasonxV Maniac Member
Joined: 08 Feb 2002 Location: Castle Rock, CO |
11. Posted: Fri Jan 07, 2005 1:47 pm Post subject: |
|
|
Alpha (WYE Style) wrote: | Anyways, does anyone know the specific security settings or registry tweak (besides the SP2 thing, that would probably fix it, or Firefox) for MSIE to kill those damn things? BTW, did this infection require you to confirm through an installer like that or was it more automatic? | The only tweak is to use Firefox or Opera or something BETTER .
Because the fault lies at IE's core, with ActiveX controls and such.
SP2 knocks out a good amount, but there are still vulnerabilities.
I won't comment on the infection, because I wouldn't know. _________________
|
|
Back to top |
|
|
Mr. A Trick Member
Joined: 20 Oct 2003 Location: INTERNET |
12. Posted: Fri Jan 07, 2005 4:14 pm Post subject: |
|
|
Hmm. I agree re: Firefox. I downloaded the new Microsoft scanner, looks pretty decent actually. |
|
Back to top |
|
|
|