This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Download.trojan Infection

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there,
My Norton AntiVirus reports Download.Trojan.
I run full scan - no avail.
I scan on-line - with Trendmicro House Call - no result.

Here is my HijackThis Logfile.

Help Please!!

Brgds
AtanasLogfile of HijackThis v1.98.2
Scan saved at 08:41:11, on 06/11/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\OBMSservice.exe
C:\WINNT\system32\regsvc.exe
c:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\internat.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\HiJack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: OBMS.lnk = C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS2\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

O4 - HKCU\..\Run: [internat.exe] internat.exe



Reboot afterwards in SAFE MODE. If you don't know how click here
Delete the following file(s) and folder(s) listed

internat.exe

Some of these files and folders might have the hidden atribute
How to show hidden files and folders in Windows Instructions here

Then Download System Security Suite. Extract it from the zip file into a folder.
http://www.igorshpak.net/software/3ssetup104.zip
Under "items to clear" click all. Then click "clear selected items"

Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves at the moment.
Hi, instructions followed, after running System Security Suite 1.04
Error message received:

Access violation at address 0047616B in module 'sss.exe'.
Read of address 00000000.

Nothing unusual in computer behavier, there was nothing before
that also, only I kept on receiving randomly warning from Norton
AntiVirus that Download.Trojan was detected, file name :
C:\winnt\system32\ .pif and that the file was deleted.

Already 20 min since the reboot in normal mode I have not received
message that Download.Trojan has been detected.

Here is the new HiJackThis Logfile:

Logfile of HijackThis v1.98.2
Scan saved at 12:52:27, on 06/11/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\OBMSservice.exe
C:\WINNT\system32\regsvc.exe
c:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\mobsync.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\HiJack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - Global Startup: OBMS.lnk = C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS2\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62


Tks in advance

BRGDS

Atanas
Log looks clean.

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
These keys all relate to registry entries which allow you to access the Alexa search feature while in Internet Explorer

key:HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}\ is the "What's related links" feature on your Internet Explorer toolbar. It's not a big deal, if you don't use it , you can delete it.
Alexa technology does use a 'web crawler' (bot) that records the information found on Web Pages accessed when the 'What's related feature' is being used in Internet Explorer. If you click 'Tools' in your Browsers toolbar, you will see 'What's Related'. If you click it, an Alexa search box will open up on the side of your browser.

When searching with the 'What's Related' feature the URL's you visit and information entered into forms is collected and sent to Alexa.

NO information is sent if the search box isn't open. It's only sent when Alexa is being used to visit web sites.
So if you choose not to use Alexa, NO info on your surfing habits will be collected or transmitted.



Access violation at address 0047616B in module 'sss.exe'.
Read of address 00000000.

Did you run it in safe mode?
Hi again,

Yes I did run it in safe mode.

Anyway, I again received the message from Norton AntiVirus 5-6 minutes
after my previous post:

Download.Trojan detected Name of file : C:\WINNT\system32\.pif

I noticed, that absolutely at the same time a MS-DOS file c.bat is
created in c:\WINNT\system32.
When I rename or delete it after awhile it again pops up there.
I am not so experienced and don't know is it some system feature
or virus? I have been doing this for 1 day (approx. 10 times), without
noticing any changes in computer's behavier.

Meanwhile, I deleted key:HKEY_LOCAL……"What's related links"
and here is my new HiJackThis Log file:

Logfile of HijackThis v1.98.2
Scan saved at 13:53:56, on 06/11/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\mobsync.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
C:\HiJack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - Global Startup: OBMS.lnk = C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS2\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62


Once again tks very much

BRGDS

Atanas
Hi again, Yes C:\Program Files\Marlink… is a directory with communication program for satellite and cellular e-mail (dial-up). tks Brgds Atanas
Please read through the ideas and free software listed below that will help to keep your computer clean.
Some of these you may already have installed or may have done already.

Install a firewall.ZoneAlarm FREE

Make sure you have the latest critical updates from windows update.

SpywareBlaster will prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests.

IE-SPYAD puts over 4000 known 'bad' sites into your IE restricted zone so that they cannot install malware on your PC.

Google toolbar has a very good built in popup blocker with a nice search bar. To provide privacy, select disable advanced features when installing.

Check your system for latest virus definitions with an online virus scan every week or two.
TrendMicro HouseCall
eTrust AntiVirus Web Scanner
Panda ActiveScan

Check your system for latest trojan definitions with an Online trojan scan also every week or two.

And also see this link for additional security information.
So how did I get infected in the first place?

Please consider using Firefox
http://texturizer.net/firefox/index.html

Please read this
Hi,

Sorry, I had to go away.
OK, I will try some of Your suggestion.
Some I already did try.
I'll keep You posted,

For now, here is the latest HiJackThis LogFile, after running
System Security Suite in normal mode and no error messages this
time:


Logfile of HijackThis v1.98.2
Scan saved at 15:24:15, on 06/11/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\OBMSservice.exe
C:\WINNT\system32\regsvc.exe
c:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\HiJack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_5_7_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - Global Startup: OBMS.lnk = C:\Program Files\MARLINK\@SEA(mail) 2000 for Networks\seamail4.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\System32\msjava.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst_current.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS1\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
O17 - HKLM\System\CS2\Services\Tcpip\..\{4426A568-67C3-4D7E-856D-8544239E2633}: NameServer = 209.198.244.2,21.226.222.62
If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI