PDA

View Full Version : downloader trojan virus


blues
01-07-04, 06:28 PM
Does anyone have an email address for Norton (Symantec) technical support?

I have Norton Personal Firewall and Norton SystemWorks, purchased directly from Symantec

I was notified this morning of a "virus definition update" being available. I okayed its download to my system

A short time later, I received an alert that the "downloader trojan" virus had been detected, but that Norton was unable to repair.

I did a virus scan, which detected that virus and, again, said it could not repair it. I clicked on "more details."

Before realizing I was supposed to disable "System Restore," I used that program to restore my system to yesterday (before the Norton update).

When my computer was restarted, I got an alert that the virus had been deleted.

I did a virus scan, which, this time, found no viruses.

My questions:

1. Is the virus truly gone, or might it still be in my system, now undetectable? (In "System Restore?")

2. Is there anything I should do now? (Keep it simple please)

3.If I have done e-mailing today, sending and receiving, but with no attachments, are those people's systems at risk?

4. Is there any problem now with sending or receiving e-mail, with or without attachments?

Thanks

Blues

Norm
01-07-04, 07:59 PM
If you've followed the instructions on this site http://securityresponse.symantec.com/avcenter/venc/data/downloader.trojan.html

You should be ok.

Never hurts to use a different virus scanner though, as a second opinion. There are a few online scans that are free to use.

blues
01-07-04, 08:22 PM
Thanks Norm

I had gotten to that Symantec site initially, but, didn't read it thoroughly (computer literate less than a year, my eyes start rolling back in my head when stuff gets too complex for my experience) regarding System Restore, which I used instead of disabling it.

Given the Symantec caveat, that System Restore may now back up the virus or Trojan on the computer, is there any way I can find out if it's in there? Could it be in there and not be detected?

And are you saying I should do each of the Symantec steps anyway?

blues

Norm
01-07-04, 08:32 PM
You could disable system restore, then boot to safe mode and do a scan.
Make sure you re-enable system restore once you boot back into windows normally. (Unless you don't want system restore running)

btw - When you disable system restore, it deletes all the backed up restore points. Once you feel your system is clean, make a new restore point manually.

Just to be on the safe side, check again for any updates to Norton, in case your restore action set it back to before your last update (just a precaution, I'm not sure what the restore feature actually backs up, and restores other than system files and registry)

blues
01-07-04, 08:40 PM
Thanks again, Norm

I was in my "whine" mode when I asked if I really have to go through all those steps, but I knew I need to do it, just to be safe.

If I can't get to it for a couple of days (I need more time, because things like "safe mode" and "navigating to keys" (?) are all unknowns to me), any problem with continuing to use email and the internet, in the interim. Might I possibly screw up friends' sytems?

blues

Norm
01-07-04, 08:53 PM
I'll bet the virus is gone. If Norton can't find it after updating, then 10-1 it's gone.

For future...
To boot to safe mode, just hit your F8 key during boot. You'll get a menu with a few options. One will be "safe mode"
Use your arrow keys to move up and down the menu. When "safe mode" is the one highlighted, click your [enter] key.
Only minimal drivers drivers get loaded in safe mode, so don't let your screen resolution scare you :)

"To boot to safe mode, just hit your F8 key during boot"

This can be tricky.
When you boot, you'll notice you are in a black screen before windows loads up. Just keep hitting the F8 key repeatedly.
There is a small window of opportunity between when the BIOS posts, and when windows starts to load. If you can judge that "window" you only need to hit F8 once.

jday8480
09-21-06, 07:50 AM
i have a registered norton anti virus and i am getting a alert message for a downloader that norton cant fix or delete. i have followed every step on the help page for this warning several times. it dosent work and i cant find any other way to get rid of this.

please help.

the error reads:

Object name: c:\windows\g6275974.dll
virus name: downloader
Action taken: unable to repair this file.

mnosteele52
09-21-06, 02:15 PM
Holy threads from the past :eek:

Prior to doing anything XP users MUST disable System Restore!!! You can re enable it after you are clean.

1. Download, install and run CrapCleaner (http://www.ccleaner.com) to remove any temporary and junk files.

2. Download Ad-Aware SE 1.06 (http://www.majorgeeks.com/download506.html) and set it up as shown HERE (http://www.drtweak.com/index.php?topic=40.0).

3. Download SpyBot Search & Destroy 1.4 (http://www.safer-networking.org/index.php?page=download) and set it up as shown HERE (http://www.drtweak.com/index.php?topic=41.0).

4. Download SUPERAntiSpyware (http://www.superantispyware.com), update and do a full system scan.

5. Download Ewido Anti-Malware 4.0 (http://www.ewido.net/en/download), update and do a full system scan.

6. Download and run CWShredder (http://www.trendmicro.com/cwshredder).

7. Do a FREE online virus scan from BitDefender Online Scan (http://www.bitdefender.com/) and remove all that it finds.

8. If you aren't currently using a firewall or anti-virus profram then I suggest you install Comodo Firewall (http://www.personalfirewall.comodo.com/) and Active Virus Shield (http://www.activevirusshield.com/antivirus/freeav/index.adp?) - (setup instructions HERE (http://www.drtweak.com/index.php?topic=157.0)), both are FREE and offer excellent protection.

9. It it also a good idea to run the Winsock Fix (http://www.snapfiles.com/get/winsockxpfix.html) to repair your TCP/IP stack. (you will have to redo any tweaks for your connection if this is used)

10. If after doing ALL of the above and you are still having problems please scan with HijackThis 1.99.1 (http://www.majorgeeks.com/download3155.html) as shown HERE (http://www.drtweak.com/index.php?topic=58.0) and post a log here in this forum for us to look at.

11. You may also need to download Sysinternal's Autoruns (http://www.sysinternals.com/Utilities/Autoruns.html) to find the problem and remove it.

12. Download SpywareBlaster 3.5.1 (http://www.javacoolsoftware.com/spywareblaster.html) and set it up as shown HERE (http://www.drtweak.com/index.php?topic=42.0) to help stay spyware free.

13. Make sure you have ALL of the latest Windows Updates.

:D