Page 3 of 15

Posted: Sat Dec 27, 2003 11:27 pm
by El_Choni
I ran my AV with the exe, no virus. Ran it in the whole hd, the same. Anyway, I had a look at that virus, and it seems that the request for plugin install you talk about must come from a web page. Can't come from the exe, which you hadn't even downloaded yet.

You're sure you were not visiting some hot sites just before trying the link I put? XD

Posted: Sun Dec 28, 2003 12:03 am
by Polo
i can't download it : file not found ...

Posted: Sun Dec 28, 2003 12:08 am
by Manne
I don't talk about your file El_Choni, sorry for misunderstanding.
Before the download starts the site request to install a browserplugin.
This plugin maybe contains malicious code.
I am using Kaspersky Antivirus and had no bad alert in the past for almost two years of using it.
I don't know what the plugin is for, maybe it is a kind of ad or spyware.
You're sure you were not visiting some hot sites just before trying the link I put? XD
For sure. My system is protected with an excellent firewall (look'n'stop), one of the best av (kav) and last but not least adwatch by ad-aware.

Manne

Posted: Sun Dec 28, 2003 12:14 am
by Proteus
Maybe you want to do a AV scan, Manne. Trojandownloader tries to download trojans. It may already be on your system.

BTW, Trojandownloader travels by e-mail, as an attachment to a mail that is made to look like it's from kaspersky.com

Posted: Sun Dec 28, 2003 12:30 am
by Manne
@Proteus

Thanks, but the last complete scan is about 1 hour ago.
My System seems to be clean.
I've received no mail containing an attachment for about 3 days and i don't use outlook as client.
I've checked the site again right now and got the same result.
The (maybe) infected file is a dll called "MaConnect.dll" and is a part of this browserplugin.
If you select no to abort the installation of this plugin you get an downloadrequest for a dialer named "od-stnd269.exe".
Don't use NAV or F-Prot for testing. This software is obvious and didn't detect many known viruses.

Manne

Posted: Sun Dec 28, 2003 9:53 am
by Berikco
I downloaded it yesterday, no request for installing a plugin.
Sophos AV did not found a virus in the installer.

Posted: Sun Dec 28, 2003 12:03 pm
by Polo
Can someone post it in another place, as I say, I can't download the file...

Posted: Sun Dec 28, 2003 12:28 pm
by Proteus
The file is there. Right-click on the link and click "Save target as".

Posted: Sun Dec 28, 2003 12:55 pm
by Polo
it's not here for me ...

Posted: Sun Dec 28, 2003 1:43 pm
by Proteus
Odd... Are you using some sort of site blocker?

Posted: Sun Dec 28, 2003 2:48 pm
by freak
Might be because there is a space in the filename, some browsers
have a problem with that.

Timo

Posted: Sun Dec 28, 2003 3:08 pm
by El_Choni
Hi,

I still don't understand what can be happening. The URL I gave is not a web site, it's only a folder with the executable and an update file, no html. I don't understand why or how you get a plugin install request. The domain is terra (Telefonica), it's unlikely that they make you download a virus. Maybe I'll put an underscore instead of a space to see if that fixes something:

EDIT: my mistake, mistyped the URL, sorry.

http://www.terra.es/personal5/temporald ... taller.exe

But I strongly recommend you to wait for the final version anyway.

Posted: Sun Dec 28, 2003 4:06 pm
by einander
El_Choni:
http://www.terra.es/personal5/temoprald ... taller.exe

No luck.
That is the message that Terra shows:
ERROR
Ha sido imposible encontrar la página solicitada. Inténtalo más tarde.

Posted: Sun Dec 28, 2003 4:35 pm
by Polo
still don't work ...

Elchroni => Can you send it by email to me, and I will post it on my website ?

My email is webmaster@gtnsoft.com

Thanks

Posted: Sun Dec 28, 2003 6:23 pm
by El_Choni
@Polo: thank you, but I think it's better to make it available when it's finished. It is a beta now, there's no help file included yet and several bugs must be fixed. But I'll send it to you as soon as it is finished. Anyway, the link above should work now (I had mistyped the URL, sorry).