| |
Antivirus World Forum
Re: Cracking Downloader-yh
Posted By: Frank In Response To: Re: Cracking Downloader-yh (Marawan)
Date: Monday, 18 April 2005, at 1:57 a.m.
For what it is worth to you folks who have a lot more knowledge about computers than I, this observation may or may not be important. In trying to download some cowboy music for my grandsons on or about April 7th, a prompt appeared saying I needed to download a plugin, did I want to? I said yes and all hell broke loose. ZoneAlarm said a program wanted to go out so I said OK. When it happened again, within 5-10 seconds, I became suspicious and shut down all Internet traffic. Long story made short, a Unicast site had downloaded at least six ad programs, which were not straightforward to uninstall, and over 500 malware and tracking cookies as detected by AdAware, Spybot and the AOL Sypware program. (I run these programs once a week and they usually pick up a total of a half dozen tracking cookies so this large number of programs and cookies where not on my computer prior to this adventure.)When I booted up the next morning, Dowloader-YH was present, could not be killed by McAfee which warned of its presence all day long. Next morning on bootup, McAfee said it was gone but as you all have experienced, it was not. Definition files dated 4/13 (4468) were unable to detect the Trojan. In searching for the Downloader-YH file, came across an association with a program called adcontroller. That lead me to a folder deep inside Java with all sorts of files and folders coming from Unicast. The path was C:\Documents and Settings\Admins folder name\Application Data\Sun\Java\Deployment\Cache\Javapi\v1.0\Jar\Adco\com\Unicast\Adcontroller\Core. Windows Explorer only showed through \Jar. The remainder of the path came from working backword from the Adcontroller files found in searching for Adcontroller. I deleted the Jar folder and replaced its contents from a two month old backup. Then downloaded and ran Trojan Hunter. Did not find Downloader-YH but did find two other trogans which it cleaned up. All seems to be OK for at least the past couple of hours. Do not know if this is part of the Downloader saga or just more confusion. Hope not.
| |
Antivirus World Forum is maintained by Administrator with WebBBS 5.12.