Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old April 28th, 2005, 09:33 PM
weam weam is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 73 weam User rank is Private First Class (20 - 50 Reputation Level)weam User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 23 h 52 m 46 sec
Reputation Power: 5
a Trojan while protected by Norton

I got a Trojan while protected by Latest update Norton AntiVirus - Norton Internet Security 2004
Just the thing I don't understand how did this file (load.exe) upload it self from the internet, executed on the hard-drive and Norton later, maybe after 20 minutes from me noticing it, Norton finally alarmed it's a trojan and blocked it
but why waiting for 20 minutes, isn't such time critical, how effective are anti-viruses really?

Reply With Quote
  #2  
Old April 28th, 2005, 10:35 PM
Dngrsone's Avatar
Dngrsone Dngrsone is offline
Infernal Technomancer
Dev Shed Novice (500 - 999 posts)
 
Join Date: Apr 2005
Location: Centrally located far from everywhere
Posts: 950 Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)Dngrsone User rank is Second Lieutenant (5000 - 10000 Reputation Level)  Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1Folding Points: 340434 Folding Title: Super Ultimate Folder - Level 1
Time spent in forums: 1 Week 16 h 34 m 19 sec
Reputation Power: 92
Send a message via ICQ to Dngrsone Send a message via Yahoo to Dngrsone
The current paradigm for AV is look for defined patterns. That's why most AV programs update on a regular basis.

The better method involves holistic detection of viral and malware activity, such as is used by Zondex Guard (formerly Leprechaun).

Norton's does have a holistic engine, which is why it detected your trojan... but it's not as good as the ones that Norton uses on their own networks... you have to pay some bucks for that.

I mention Zondex specifically because I know the Leprechaun was one of few AV engines that managed to catch the viruses that ran rampant a few years back without having to download a single update (ref).

Some steps you can take to avoid malware:

  • Stay away from the seedy underside of the 'net (ie, no p-p downloading, warez, and pr0n)
  • Switch away from IE-- try Firefox or Opera
  • Switch away from Windows-- Linux is free and they have quite a few tools for free that will accomplish what you do with windoze and pay for.
  • Download AdAware and Spybot and sweep the computer at regular intervals
  • Develop and implement a backup scheme so, if you do get hit by a nasty malware program you can wipe the slate clean and reinstall without fear of losing the only digital picture of Aunt Thelma in existance.
Comments on this post
Andrew80 agrees: yes, this totally works .!!

Reply With Quote
  #3  
Old April 28th, 2005, 11:57 PM
weam weam is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 73 weam User rank is Private First Class (20 - 50 Reputation Level)weam User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 23 h 52 m 46 sec
Reputation Power: 5
Thanks Dngrsone, well yeah I understand all that, I was just commenting about waiting which in such time frame can let malicious activities do harm before being caught

I will consider Zondex in next system upgrade, maybe

Thanks anyway

Reply With Quote
  #4  
Old May 2nd, 2005, 01:12 PM
Tom Myboy Tom Myboy is offline
Contributing User
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: Aug 2003
Posts: 2,491 Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level)Tom Myboy User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 3 Days 20 h 13 m 41 sec
Reputation Power: 14
Hi weam,
Quote:
I was just commenting about waiting which in such time frame can let malicious activities do harm before being caught

Malware of all types can be inactive for long periods of time before they become active and (sometimes) get caught by your antivirus program.

For example, some viruses have a preset date at wich time they will deploy and cause damage.

Feel free to post a HijackThis log as you may still be infected.

Please download HijackThis. Make sure you install HijackThis to a permanent folder such as C:\HJT as it creates backups of what we will fix.

Run the program, click the button at the top "Do a system scan and save a logfile". Save the log to a convenient place such as C:\HJT Notepad will open, copy and paste the entire log into your post. Do not fix anything yet, most of what's in the log is needed!

http://www.majorgeeks.com/download3155.html

Tom
Comments on this post
oneMSBi agrees: only two green blobs for rep ?? you deserve more !
__________________
HijackThis
Ad-aware
Spybot Search & Destroy
SpywareBlaster
SpywareGuard
Housecall Online A/V Scan

Please read the stickys at the top of the forum before posting!

Reply With Quote
  #5  
Old May 4th, 2005, 03:01 PM
oneMSBi's Avatar
oneMSBi oneMSBi is offline
CAUTION: Loderator Moose
Dev Shed Loyal (3000 - 3499 posts)
 
Join Date: Nov 2004
Location: some starry place (india)
Posts: 3,431 oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level)oneMSBi User rank is First Lieutenant (10000 - 20000 Reputation Level) 
Time spent in forums: 4 Weeks 1 Day 21 h 34 m 19 sec
Reputation Power: 156
you are probably still infected.. considering how the infection got through your firewall and the norton auto protect.. its like that the infection not completely removed. noticed any side effects of the infection like a slow net connection, slow pc, weird popups etc ?
__________________
Nigel
..Seeking code free nirvana...
Nigel Fernandes Blog
Never argue with fools. They will bring you down to their level and beat you with experience.


Manchester United Forever

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > a Trojan while protected by Norton


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 4 hosted by Hostway
Stay green...Green IT