Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection

Reply
 
LinkBack Thread Tools Display Modes
Old 04-06-2004, 12:58 AM   #1 (permalink)
Junior Techie
 
Join Date: Apr 2004
Posts: 69
Default TrojanClicker.win32.stomcc

I have detected this trojan on my PC with Trend Micros Free Virus Scan and Digital Patrol Scanner 5.0. Funny thing though, I am running Norton System Works 2003 with updates and it wasn't detected by my Norton scan. I began feeling a little suspicious that something (other than the typical spyware) was present so I went to Trend Micro and did a free scan and it detected two files on my PC that were infected with this version. Trends free version and Digi Patrol can not clean it so I am wondering if anyone has a link for the appropriate cleaning method or has had this problem before and can offer some advice. My PC still runs clean except for the occasional overheat. Still haven't quite figured that one out either. I did search a little for any info on this trojan, but I could not really find much ( in english ). Has anyone ever heard of a Trojan that causes your system to run hot ??? Because up until about a week and a half ago my PC ran perfect. Also, when I run a virus scan, about half way through my PC starts getting hot...hmm...any thoughts ? Also, I consistently run Ad-aware 6, Spy Bot Search and Destroy and Spyware Blaster, Bazooka Spy Scanner, Hijack This, CW Shredder and Norton System Works 2003 ( not that it mattered in this case ) so my PC is regularly scanned.

P4 2.8
800 mhz FSB
512 Corsair PC3200
Radeon 9200 8XAGP
90 gb Hitachi
Iomega external CD Burner
DFI 865PE ( i think ? )
daddy_ray is offline   Reply With Quote
Old 04-06-2004, 07:25 PM   #2 (permalink)
Junior Techie
 
Join Date: Apr 2004
Posts: 69
Default

Hey guys, I think I figured it out. I ended up finding 3 files infected with this trojan and I simply deleted the files, I ran both the scanners again and it was unable to find then again...hence the problem seems fixed. I did have another problem though. Last night I would try to open Norton System Works and I kept getting a " NMain is not a valid Win32 app " ...Hugh ?? Exqueeze me...baking powder ??? Confused and bewildered I simply removed Norton and did a re-install. Then I was getting this long error message stating that someone possible an attacker was changing the settings on my Norton so that i would not be able to run it. Weird... or what ? So I ran live update and to no avail. I ended up running my pc in selective startup and removing Norton again, then I reinstalled again ran live update and everything is fine now.

Still though if anyone has any input on any of this garbage that is going on please feel free to reply. I would love to hear about any experiences similar to this.
daddy_ray is offline   Reply With Quote
Old 04-07-2004, 07:39 PM   #3 (permalink)
Admin
 
Dave's Avatar
 
Join Date: Mar 2002
Location: "Almost Heaven" USA
Posts: 4,858
Send a message via AIM to Dave Send a message via Yahoo to Dave
Default

Some trojans or spyware will actively change AV settings. Depending upon where you find the files, you may not want to delete them since this can stop programs from working. I think you found that out.

Dave
__________________


Tech Forums
Moderating Policies | Forum Rules | ***PROFANITY***

Note that I do not accept support requests via IM, email, or PMs. Please ask it on the forums.


Trying this out: My Dollar Store :: Naturally Good


Dave is offline   Reply With Quote
Old 04-09-2004, 12:16 AM   #4 (permalink)
Junior Techie
 
Join Date: Apr 2004
Posts: 69
Default

Then what would have been the proper method for getting rid of something like this ? Also, Why would Norton not have found this Trojan when it is supposed to be the industry leader in av protection, but I ended up finding it with some lower level program ??? I assume its because it was designed to be found by Norton...Is this correct ?? This trojan was in My Downloads folder. What if it had been in my C: or my Windows folder. What are the types of things that could have possibly happened if anything ? What was the purpose of this virus then ? I would appreciate any input.

Thanks, Ray
daddy_ray is offline   Reply With Quote
Old 04-09-2004, 10:48 PM   #5 (permalink)
True Techie
 
Join Date: May 2003
Posts: 221
Default

Lets have a little look at a log from the infected system:

Download 'Hijack This!'. http://www.tomcoyote.org/hjt/ and save it to a folder on your desktop.
Unzip, doubleclick HijackThis.exe, and hit "Scan".

When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, load it in Notepad, and copy its contents here. Most of what it lists will be harmless or even essential, don't fix anything yet.
__________________
Security Tools | Spyware Scan | Prevention 101
mobo is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 11:11 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0