Author Topic: Elusive folder...  (Read 745 times)

Sandrine

  • Guest
Elusive folder...
« on: October 19, 2005, 08:08:07 AM »
Hi there! I am hoping to get somebody's good ideas on this one.....

I have updated my anti-virus (Antivir PE) and ran a scan... It has given me 2700 alerts (!!!!). All relate to 1 folder which seems to contains a vast number of .zip archives files ("naughty" type of files which I really really don't want on my pc and that i definitely haven't downloaded myself...!!!). All the alerts are for the following: TR/Drop.WinAD.H and are contained in the following folder: C:\Documents and Settings\Sandrine Mauduit\Complete

But can I find this folder??? NO!!! I have search high and low for it but i can't find it even amongst the hidden files and folders of my pc...What am I supposed to do?

I run Windows XP.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Elusive folder...
« Reply #1 on: October 19, 2005, 09:40:49 PM »
You will have to post a hijackthis log
Back to this thread
one requirement I ask is that you register to the forum
Please, Read this

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Bas Vogel

  • Guest
Elusive folder...
« Reply #2 on: October 24, 2005, 10:07:29 AM »
Hee hello Sandrine....

I'm a Dutch guy with the same problem as you.... Would you be so kindly To Help me out... Thats if you figger it out.... You can mail me at krachtpropEmail Removed
Thank you....
ps. Sorry fore my pore Englisch

[quote name=\'Sandrine\' date=\'Oct 19 2005, 07:08 AM\']Hi there! I am hoping to get somebody's good ideas on this one.....

I have updated my anti-virus (Antivir PE) and ran a scan... It has given me 2700 alerts (!!!!). All relate to 1 folder which seems to contains a vast number of .zip archives files ("naughty" type of files which I really really don't want on my pc and that i definitely haven't downloaded myself...!!!). All the alerts are for the following: TR/Drop.WinAD.H and are contained in the following folder: C:\Documents and Settings\Sandrine Mauduit\Complete

But can I find this folder??? NO!!! I have search high and low for it but i can't find it even amongst the hidden files and folders of my pc...What am I supposed to do?

I run Windows XP.
[post=\"64274\"]<{POST_SNAPBACK}>[/post]
[/quote]

lapijo

  • Guest
Elusive folder...
« Reply #3 on: October 25, 2005, 01:29:39 PM »
hello,

I have the same problem, working on it, seems that it has something to do with java (?)


[quote name=\'Bas Vogel\' date=\'Oct 24 2005, 09:07 AM\']Hee hello Sandrine....

I'm a Dutch guy with the same problem as you.... Would you be so kindly To Help me out... Thats if you figger it out.... You can mail me at krachtpropEmail Removed
Thank you....
ps. Sorry fore my pore Englisch
[post=\"65529\"]<{POST_SNAPBACK}>[/post]
[/quote]

lapijo

  • Guest
Elusive folder...
« Reply #4 on: October 25, 2005, 03:33:02 PM »
That´s a strange thing.
I´ve absolutely the same problem about this trojan.

After my Antivir found these trojan, I found out that the folder "incomplete", which is used by "lime wire", was full of zips, named with porn-names. I didnt check them but deleted them all (with tune-up shredder).
I have no idea how they got there, they seemed to be those trojans, had all the same size but different porn-names.

But my Antivir still alerts, still finding more than 1200 files of the same trojan, still porn-names, still at this point: C:\Documents and Settings\myname\Complete - and Complete doesn´t exist. I checked everything in the application files - folder, but there is nothing.
Antivir says it cannot delete them, but found some more viruses/ trojans at some other places, which could be deleted.
 
Because the anti-spy-programm "ad-aware" (custom scanning options) also found this trojan, and always stopped at the point: C:\Documents and Setting\myname\application files\Sun,  I thought it´d have  something to do with Java.
I deleted Java completely, in the application files and at the program-files, but still my Antivir finds this trojan.
Ad-Aware now is detecting it at C:\Documents and Setting\myname\application files.
After finding it a file is generated in the cache-folder of Lavasoft-Ad-Aware. I can delete it in this folder, but then it comes again and again when Ad Aware finds it again and again...
maybe I should try do delete it more than 1200 times...?


Now I don´t know what to do, does anybody know?
Why is this the only site which google announces, when typing in the name of this trojan?




[quote name=\'lapijo\' date=\'Oct 25 2005, 12:29 PM\']hello,

I have the same problem, working on it, seems that it has something to do with java (?)
[post=\"65907\"]<{POST_SNAPBACK}>[/post]
[/quote]

Guest_guest_*

  • Guest
Elusive folder...
« Reply #5 on: October 26, 2005, 05:25:35 PM »
helps:

download kaspersky anti virus (trial version), update,
run