Welcome to SecurityForumz.com!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

trojan in file?

 
   Security Forums (Home) -> General Discussions RSS
Next:  Run Spyware Automatically  
Author Message
Shepard Tate

External


Since: Jul 05, 2004
Posts: 11



(Msg. 1) Posted: Mon Jul 05, 2004 3:40 pm
Post subject: trojan in file?
Archived from groups: alt>comp>virus (more info?)

We run NAV and Firewall. It does alert normally when an e-mail
contains a virus. However, today, for the first time ever, a virus
scan of the whole computer actually found a virus.
"intinstall_si.exe is infected with the Download.Trojan virus".

NAV said it deleted the file during the scan, but my question is
this...

How is it possible with both NAV and Norton Firewall running and
always updated, that this virus found it's way into this file?

Is it possible that in saving a system restore point and then doing a
registry edit, I caused NAV to think it found a virus? It's strange
that this "Trojan" was found right after I did the edit and in the
above file.

Anyone have any ideas?

Thanks

 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Shepard Tate

External


Since: Jul 05, 2004
Posts: 11



(Msg. 2) Posted: Tue Jul 06, 2004 12:11 am
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Your point is well taken. It was not set to delete until recently. I
have 3 kids who use the computer and I got nervous about what they do
when ever a virus alert pops up.

 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Shepard Tate

External


Since: Jul 05, 2004
Posts: 11



(Msg. 3) Posted: Tue Jul 06, 2004 12:18 am
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Actually, I just checked my settings and I don't have it set to
delete, even though the NAV message said it was deleted. I looked in
the backup of quarantined items and the file is there. What do you
suggest I do with it, if anything?
 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Shepard Tate

External


Since: Jul 05, 2004
Posts: 11



(Msg. 4) Posted: Tue Jul 06, 2004 2:02 pm
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I am still wondering if what I did before this virus alert, (described
below), could have caused NAV to think it found a Trojan?

(Shepard Tate) wrote in message ...
>
> Is it possible that in saving a system restore point, backing up a key and then doing a
> registry edit, I caused NAV to think it found a virus? It's strange
> that this "Trojan" was found right after I did the edit and in the
> above file.
>
> Anyone have any ideas?
>
> Thanks
 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Shepard Tate

External


Since: Jul 05, 2004
Posts: 11



(Msg. 5) Posted: Tue Jul 06, 2004 11:33 pm
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Well, I did get e-mail back from Symantec which is quoted below: This
does not answer my question as to how the infected file came to reside
on my computer when I have NAV running all the time and always have
the latest definitions????
There seems to be no way to get Symantec to answer a question like
this without paying big bucks for phone support. It's unfortunate as
I have been happy for years thinking NAV was preventing infections,
but it seems to have failed big time here! I wonder what this Trojan
would have eventually done if I had not run a manual scan of the whole
computer yesterday?

filename: istinstall_si.exe
machine: DEFUALT-7LSOD9B
result: This file is infected with Download.Trojan

Developer notes:
C:\Program Files\Norton AntiVirus\Quarantine\4CB4206C is a container
file of type NAV_QUARANTINE
istinstall_si.exe is non-repairable threat. NAV with the latest
rapidrelease definition detects this. Please delete this file and
replace it if neccessary. Please follow the instruction at the end of
this email message to install the latest rapidrelease definitions.
This file is contained by C:\Program Files\Norton
AntiVirus\Quarantine\4CB4206C
 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Joe3301955

External


Since: Jul 07, 2004
Posts: 2



(Msg. 6) Posted: Wed Jul 07, 2004 2:01 pm
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

McAfee 8 is the same way, lastest updates, do daily scans...it does not find
all viruses. When I press Alt-Ctrl-Del and see programs running i do not
recognize I "find" the file and usually delete it to the recycle bin. And
internet explorer seems to always have a different start page, even though I
set it to about:blank.

>Subject: Re: trojan in file?
>From: (Shepard Tate)
>Date: 7/7/04 2:33 AM Eastern Daylight Time
>Message-id:
>
>Well, I did get e-mail back from Symantec which is quoted below: This
>does not answer my question as to how the infected file came to reside
>on my computer when I have NAV running all the time and always have
>the latest definitions????
>There seems to be no way to get Symantec to answer a question like
>this without paying big bucks for phone support. It's unfortunate as
>I have been happy for years thinking NAV was preventing infections,
>but it seems to have failed big time here! I wonder what this Trojan
>would have eventually done if I had not run a manual scan of the whole
>computer yesterday?
>
>filename: istinstall_si.exe
>machine: DEFUALT-7LSOD9B
>result: This file is infected with Download.Trojan
>
>Developer notes:
>C:\Program Files\Norton AntiVirus\Quarantine\4CB4206C is a container
>file of type NAV_QUARANTINE
>istinstall_si.exe is non-repairable threat. NAV with the latest
>rapidrelease definition detects this. Please delete this file and
>replace it if neccessary. Please follow the instruction at the end of
>this email message to install the latest rapidrelease definitions.
>This file is contained by C:\Program Files\Norton
>AntiVirus\Quarantine\4CB4206C
>
 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Shepard Tate

External


Since: Jul 05, 2004
Posts: 11



(Msg. 7) Posted: Wed Jul 07, 2004 5:33 pm
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Well there does not seem to be much information available as to
exactly what embioso.exe is and does. Symantec describes it as an
"extended threat of unknown type, possibly adware".

I removed it from the windows\system32 folder, but it keeps coming
back? What's up with that?? I then installed winpatrol which alerts
me every time embioso tries to add itself to startup. At least I can
control it this way, but how do I prevent it from reappearing in the
windows\system32 folder?
 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Shepard Tate

External


Since: Jul 05, 2004
Posts: 11



(Msg. 8) Posted: Fri Jul 09, 2004 12:12 pm
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Anyone have knowlege about this embioso.exe file?

(Shepard Tate) wrote in message ...
> Well there does not seem to be much information available as to
> exactly what embioso.exe is and does. Symantec describes it as an
> "extended threat of unknown type, possibly adware".
>
> I removed it from the windows\system32 folder, but it keeps coming
> back? What's up with that?? I then installed winpatrol which alerts
> me every time embioso tries to add itself to startup. At least I can
> control it this way, but how do I prevent it from reappearing in the
> windows\system32 folder?
 >> Stay informed about: trojan in file? 
Back to top
Login to vote
maria paz

External


Since: Jul 13, 2004
Posts: 2



(Msg. 9) Posted: Tue Jul 13, 2004 2:51 pm
Post subject: Re: trojan in file? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

fdddddddddddddfffffffffffkkkkkkkkkkkk
"Shepard Tate" escribió en el mensaje

> We run NAV and Firewall. It does alert normally when an e-mail
> contains a virus. However, today, for the first time ever, a virus
> scan of the whole computer actually found a virus.
> "intinstall_si.exe is infected with the Download.Trojan virus".
>
> NAV said it deleted the file during the scan, but my question is
> this...
>
> How is it possible with both NAV and Norton Firewall running and
> always updated, that this virus found it's way into this file?
>
> Is it possible that in saving a system restore point and then doing a
> registry edit, I caused NAV to think it found a virus? It's strange
> that this "Trojan" was found right after I did the edit and in the
> above file.
>
> Anyone have any ideas?
>
> Thanks
 >> Stay informed about: trojan in file? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Cant get rid of trojan file - I have Norton Anti-Virus 2002. While running a full scan I found a whole bunch of (11) infected files of the trojan byte verifier class. I am not sure why I keep getting these infected trojan byte verifier files as I have updated all the Microsoft patche...

Can I delete a Windows file to get rid of a Trojan? -

How do I delete a trojan from a Zip file - Hi Guys, Need some advice, I have a zip file with a software program on it, I need to load the program, but my virus checkerNOD32 tells me that it contains a Win323/trojanDropper VB.NAI trojan(when I try to unzip it). How do I delete the trojan so I....

Trojan Horse - Access Denied trying to Delete File - I need some help from you experts out here. I have an XP Pro system that has a Trojan Horse identified by Norton AV - but it can't be deleted by the product (AV).... nor myself when I go directly to the c:\windows directory (file = SAMICRO.DLL) ... ....

Virus/Trojan/Ad/Spy/Malware that modifies hosts file when .. - Does anyone know of a virus/trojan/adware/etc... that modifies the \windows\system32\drivers\etc\hosts file on ANY program that you run? We're using zonelab pro with the "OS firewall" enabled but every time you try to run an application, it tel...
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]