2 Replies Latest reply on May 4, 2011 8:42 PM by burnsr

    Deleted trojan running on computer

      Running VirusScan Enterprise + AntiSpyware Enterprise 8.7.0i on a Windows XP desktop. The 'On-Access Scanner log displays that two executables were deleted 3 times on the machine but the first executable listed 'ldMFchcXrFP.exe' was running on the machine and not deleted. Then later in the log there was another detection and deletion recorded of the same items.

       

      I logged onto the machine using a local administrator profile and renamed the executeable to stop it being triggered at logon by the machine's user. But then ran a 'Full Scan" of the computer which failed to find the executable at all.

       

      Is this trojan only detected by name or is there a piece of code within the executable that should identify it as virus?

       

      ----------------------------------------------- log extract ----------------

       

      3/05/2011 9:44:41 AM Deleted  BOM\skb C:\Documents and Settings\All Users\Application Data\ldMFchcXrFP.exe C:\Documents and Settings\All Users\Application Data\17620788.exe FakeAlert-FAB!5CA812E931DD (Trojan)

      3/05/2011 9:45:03 AM Deleted  BOM\skb C:\Documents and Settings\All Users\Application Data\ldMFchcXrFP.exe C:\Documents and Settings\All Users\Application Data\17620788.exe FakeAlert-FAB!5CA812E931DD (Trojan)

      3/05/2011 9:45:12 AM Deleted  BOM\skb C:\Documents and Settings\All Users\Application Data\ldMFchcXrFP.exe C:\Documents and Settings\All Users\Application Data\17620788.exe FakeAlert-FAB!5CA812E931DD (Trojan)

       

      -------------------------------------------------------------------------------

       

      regards Robert Burns

        • 1. Re: Deleted trojan running on computer

          Hi Burnsr,

           

           

          Chances are that the trojan is already deleted from your system but its just a crippled remnant of it in the registry. Thus the moment McAfee is finding it in the system, its triggering a delete action. What I would suggest you to do is, check your auto start and remove any mention of an unknown program that you sure about and then clean up your registry.

           

          This should take care of the issue.

           

           

          Thank you

           

           

          Sameer

          • 2. Re: Deleted trojan running on computer

            Hi Sameer,

                                  No... the 'ldMFchcXrFP.exe'  executatble was running within the machine despite being listed in the McAfee log as beng deleted and was still there in the user's profile I believe because it was running it could not be deleted.

             

            I renamed the executable logged onto the machine using and administrator level account, rebooted and logging on as the user was able then to remove the run command from the user's profile at  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] within the registry.

             

            As the executable was still there but 'renamed' and not running I was surprised that McAfee didn't find it at all and delete it when I later ran a 'Full Scan' with McAfee. I'd like to know if this Trojan is delected in a system by McAfee looging for the executable's name and not some key code within teh executable to ID it as it never found the renamed Trojan?

             

            The 'Trojan' made the (running user's) and (all users) and 'program files' directories hidden and deleted all the program shortcuts from the (all users) start menu.

             

            ------------

            regards Robert Burns