What is this? [spyware, trojan?]

For general computer discussion & help, come here

Moderators: Bakhtosh, EvilHomer3k

Post Reply
User avatar
Zekester
Posts: 6613
Joined: Fri Oct 15, 2004 12:37 pm
Location: Pittsburgh

What is this? [spyware, trojan?]

Post by Zekester »

My Norton A/V keeps catching the same "installer2.exe" trojan dropper, but it keeps coming back.
It says it's installed in my temp folder, but I can't find it there.

And my firewall has been getting "intruded" pretty often lately by random IP's

What the hell might be going on?
Name the 3 branches of the US Government: "Judicial, legislative....I can twerk"
User avatar
Smoove_B
Posts: 57194
Joined: Wed Oct 13, 2004 12:58 am
Location: Kaer Morhen

Post by Smoove_B »

Symantec thinks you've got something. Well..not that you've got something. Probably this redirect is trying to install but NAV is stomping it every time.
Maybe next year, maybe no go
User avatar
Jeff Jones
Posts: 2768
Joined: Tue Oct 19, 2004 7:24 pm
Location: Florida

Re: What is this? [spyware, trojan?]

Post by Jeff Jones »

Zekester wrote:My Norton A/V keeps catching the same "installer2.exe" trojan dropper, but it keeps coming back.
It says it's installed in my temp folder, but I can't find it there.
It could be hidden in your System Restore.

I believe if you disable System Restore on all drives, it will kill all the stored backup files (where trojans and viruses often hide). This is worth a shot anyway.
User avatar
Zekester
Posts: 6613
Joined: Fri Oct 15, 2004 12:37 pm
Location: Pittsburgh

Post by Zekester »

I've had system restore disabled on all drives since this computer was new.
Thanks anyway, Jeff :wink:

Does running a full scan in safe mode work for something like this?
Name the 3 branches of the US Government: "Judicial, legislative....I can twerk"
User avatar
Greggy_D
Posts: 1654
Joined: Wed Nov 03, 2004 3:58 pm
Location: Michigan

Post by Greggy_D »

It might be in Startup or the RUN section of the registry.

Run "msconfig" and look in the startup tab.
"Whoaaaaaa man. You're totally covered in glass salad." .....Smooth B's stoned neighbor
User avatar
Zekester
Posts: 6613
Joined: Fri Oct 15, 2004 12:37 pm
Location: Pittsburgh

Post by Zekester »

I did find some foreign chit in my startup, and disabled it.

So far, so good.
Name the 3 branches of the US Government: "Judicial, legislative....I can twerk"
User avatar
Bakhtosh
Forum Moderator
Posts: 10900
Joined: Wed Oct 13, 2004 12:24 pm
Location: The First Avenger
Contact:

Post by Bakhtosh »

you can always go to symantic or mcafee's site to see if there's a cleaner available for that particular trojan.
“I prefer dangerous freedom over peaceful slavery.” -Thomas Jefferson
Finding Red Riding Hood well-armed, the wolf calls for more gun control.
Post Reply