CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Trojan Horse Downloader.Inservice.O

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Grisoft AVG [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
tiabobia

Cadet
Cadet


Joined: Aug 23, 2004
Posts: 2
Location: USA

PostPosted: Mon Aug 23, 2004 10:59 pm    Post subject: Trojan Horse Downloader.Inservice.O
Reply with quote

Hi everyone! New to searching for solutions to viruses, usually my fiance does it for me. I figured it was time for me to learn since we are becoming more and more computer based as the years go on. I have this trojan that I mention in the title in this directory on my laptop:

C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP100\A0018382.exe

I have run AVG several times and it finds this little devil everytime and says that it has been deleted but alas it is still showing up when I run AVG. Every time I try to move the virus to the virus vault the program hangs for about 5 mins and then supposedly the file is gone. Does anyone have any information on this trojan? I've been checking in Google and Yahoo and haven't had much luck. I'll continue doing that until I find something or hopefully get some help here!

TIA (<-that's my name and a thanks in advance Very Happy )

Back to top
View users profile Send private message
chidman

Cadet
Cadet


Joined: Aug 09, 2004
Posts: 6
Location: Uk

PostPosted: Mon Aug 23, 2004 11:17 pm    Post subject:
Reply with quote

The file name you give there suggests that the infected file is containted within restore point information. If you turn off system restore on all drives, previous restore point information is deleted. Working on that basis, turning off system restore should solve your problem. You can reinstate it afterwards but bear in mind that you no longer have any restore points.

I can't guarantee that this is correct, just an educated deduction.

Hope this helps.

Chris

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Aug 24, 2004 2:06 pm    Post subject:
Reply with quote

Hi Tia!

You can find instructions for turning off System Restore here: http://www.pchell.com/virus/systemrestore.shtml

chidman's educated guess is accurate. It is still in your Restore Folder and so every time you restart/reboot your computer, the virus is reloaded. Usually antivirus applications cannot make deletions from an active Restore function. You need to turn it off. Then run your AV and remove the virus. Then turn System Restore back on.


Best regards and welcome to Computer Cops! Very Happy


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
tiabobia

Cadet
Cadet


Joined: Aug 23, 2004
Posts: 2
Location: USA

PostPosted: Tue Aug 24, 2004 8:33 pm    Post subject:
Reply with quote

Well it did work!!! I turned off System Restore thru my Control Panel/System icon and the booger is gone!!! Thanks guys

TiaBoBia Very Happy

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Aug 24, 2004 8:49 pm    Post subject:
Reply with quote

Hi TiaBoBia!

You are very welcome! Thumbs Up

Glad we could help. Very Happy


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
mightyatom

Trooper
Trooper


Joined: Jan 28, 2004
Posts: 12
Location: UK

PostPosted: Sat Sep 04, 2004 3:16 pm    Post subject:
Reply with quote

Hi folks!
I also have the trojan 'Downloader.Inservice.0'. (This must have happened only yesterday as I virus check regularly).

It's located in:

C:\RECYCLERS\S-1-5-21-299502267-492894223-839522115-1000\DC62.ZIP:\awi.exe

I have looked for this file but it doesn't seem to exist!

I have win 2000 and use AdAware and AVG 6.0 (free).
Please Please help me get rid of this!

Back to top
View users profile Send private message
Donna

Colonel
Colonel
Premium Member

Joined: Apr 12, 2004
Posts: 2508
Location: Macau
MVP Premium

PostPosted: Sat Sep 04, 2004 4:51 pm    Post subject:
Reply with quote

Hi mightyatom,

C:\RECYCLER is a hidden folder. It is used by the Recycle Bin. To view
Hidden folders, open My Computer. Go to Tools>Folder Options. Click on the view tab and choose show hidden files and folders. Click OK.

Next press F5 in your keyboard for a refresh then empty your recyle bin. See if AVG will find it again.

Note: Please start/create your own topic next time. - Thanks.


_________________
It is common sense to take a method and try it; if it fails, admit it frankly and try another. But above all, try something. --Franklin D. Roosevelt
Back to top
View users profile Send private message Visit posters website
mightyatom

Trooper
Trooper


Joined: Jan 28, 2004
Posts: 12
Location: UK

PostPosted: Sun Sep 05, 2004 12:45 am    Post subject:
Reply with quote

Dearest Donna!

Your advice seems to have worked!
I did as you said and have run AVG umpteen times since (just to make sure! I'm not paranoid you understand: I'm just not used to life being THAT simple! Surprised|)
Result= Whoop-di-whoo - still NO VIRUS!
It cannot be that easy, surely?! (I'd better shhoosh now - better not tempt fate). Note: in my neck of the woods, 'shhoosh - or shoosh' means 'shut up/stay quiet/zip it etc' - you get ma drift.

Anyhoo - natural pessimism aside...
I just have to say You are wonderful!
In fact, you brought to mind my reason for joining this excellent forum in the first place = sanity preservation!
Dunno what I'd do without You and CC!

Respect to all of you.

Thanks sooo much Donna!
Take care - til next time (as I said, I'm not being para - just realistic!)

Back to top
View users profile Send private message
mightyatom

Trooper
Trooper


Joined: Jan 28, 2004
Posts: 12
Location: UK

PostPosted: Sun Sep 05, 2004 1:47 am    Post subject:
Reply with quote

I blew it! I'm seeing double! I apologise for my mistake... Embarassed

Back to top
View users profile Send private message
Donna

Colonel
Colonel
Premium Member

Joined: Apr 12, 2004
Posts: 2508
Location: Macau
MVP Premium

PostPosted: Sun Sep 05, 2004 4:01 am    Post subject:
Reply with quote

It's a-OK now mightyatom. I deleted your duplicate post and you are welcome! Glad we can help.

I'll now close this topic. @tiabobia, please PM a mod or host, if you want to re-open this topic. Others should create a new topic for any question or if you need help.

Thanks!


_________________
It is common sense to take a method and try it; if it fails, admit it frankly and try another. But above all, try something. --Franklin D. Roosevelt
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Grisoft AVG All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer