Trojan horse Downloader.Generic.ML

Jun 15, 2005 174 Replies

Jason Edwards wrote: [snip]

fallibility is not the same as uselessness... no security is perfect, does that render all security useless? no...

virus scanners are not useless, they just don't offer perfect protection...

[snip]

they probably got rid of it to pave the way for their new anti-virus offering...

Cert & Microsoft. Google it.

? His text didn't even hint at them being frauds. Can't work reliably when compromised yes.

It has been done, host based IDS. Its still unreliable in the case of being owned or root-kitted.

Its entirely upto whether you reinstall. (It doesn't take long so i don't understand why you wouldn't.)

Your flawed logic maybe. The real logic would dicate that you would reinstall windows, recover executable data from a known good backup, and restore the data from a recent backup. At this point the data is still untrust worthy so you would have to test it, check it etc etc.

Sure. Some time ago I was curious about strange messages with links appearing in newsgroups, so I set up an isolated PC with its own broadband connection running Windows 98 with ALL updates and clicked one of the links. This took me to a website offering adult material. I can't remember the details but it had some clever way of getting me to scroll down and click. A quick run of hijackthis then discovered that a trojan had been planted in the startup folder and was waiting to run on the next startup. The computer was then wiped and restored from a clean image. I got rid of the trojan file about a week later, it was kept only to verify that two popular virus scanners were still pronouncing it clean after a week.

I thought I'd already explained that no matter how hard they look they can't be expected to include all malware the same day it's written. Some may only be included months later, or perhaps never.

Nope.

Sure it's the usual model for a home Windows user but it is not effective for the reasons you have discovered for yourself. Personal software firewalls are useless because there are many ways for malware to bypass them. Malware might ride on another application such as Internet Explorer, it might answer the firewall's popup questions itself, it might shut the firewall down completely, it might prevent the firewall from getting updates, etc. Virus scanners are useless for exactly the reason that you are understandably upset about discovering for yourself. You thought you were doing everything possible but you still got a trojan.

Barely possible would be more than enough for me. I'd rather make it impossible. To do that you arrange to prevent any executable code getting where you don't want it. This is likely to be impossible with a Windows 98 PC connected directly to a broadband connection where everything has complete access to everything else. Consider an external firewall box which stops it getting to the PC in the first place.

How about the experiment I did with the isolated windows 98 PC described above. It may be that this hole has since been patched but it makes no difference to me, I will continue to trust no executable code unless I'm very sure about where it came from and what it's going to do to my system. You may say that it's difficult or impossible to keep addware off a Windows PC. But this is not the same as asking whether or not it can be done.

There was a Microsoft technet article giving just this advice but I can't find it, maybe someone else can unless it's gone.

No. What I have established is that you are understandably upset about the fact that you did everything you thought you had to do (virus scanner, personal firewall, spyware remover) but you STILL got a trojan. It's not my fault if you would rather attack the person giving you this information instead of asking yourself why the methods you've applied so far are not working.

Jason

There was a Microsoft technet article giving just this advice but I've not been able to find it.

Ok so why don't virus scanners use this method?

It doesn't take very long with drive imaging software and an external USB

2.0 hard drive. There are other methods.

Jason

I've yet to see a virus scanner advertised as being fallible. How are users going to know that virus scanners are fallible?

Yes

Where did "all security" come from? Not from me. I sometimes advise installation of a virus scanner because it will be better than nothing and anyway the user wants one because everyone else has one so it must be the only way to prevent viruses.

protection...

So they are fallible as you say. How many home Windows users know that their virus scanner is no guarantee that an undetected trojan isn't sending their personal information to almost anywhere?

Jason

That's what I was looking for. Thanks.

Jason

The Microsoft page is

formatting link

Read yourself...

Gabriele Neukam

snipped-for-privacy@t-online.de

And the user would get more "this file has changed" messages than they'd know what to do with.

If you're running 2000 or XP, start, run, cmd, type sfc Before using it, be aware that it's your own problem if you get into a mess.

Jason

Hi Ron - I think it might be useful to run A2 (that was my original recommendation, you may remember). Here's its current detection profile for the free version:

Number of Signatures: Trojans 80524 Dialer 27877 Worms 5064 Spyware 4166 Traces 26997

As you can see it's differently oriented than is a virus scanner. You can download the free version here:

formatting link
It shouldn't take nearly as long as SysClean, although it will take a bit. :) Run it from Safe mode w/Internet Access (in order to update) (or update and then boot to Safe mode) or, even better, from a Clean Boot taking into account the following. If it finds anything, clean, reboot and then run it again. After everything is clean in Safe mode or Clean Boot, re-run it after a normal boot still showing hidden files:

From my Blog:

Show hidden files and run all of the following removal tools from Safe mode or a "Clean Boot" when possible, logged on as an Administrator. BEFORE running these tools, be sure to clear all Temp files and your Temporary Internet Files (TIF)(including offline content.) Reboot and test if the malware is fixed after using each tool.

HOW TO Enable Hidden Files

formatting link
Clean Boot - General Win2k/XP procedure, but see below for links for other OS's (This for Win2k w/msconfig - you can obtain msconfig for Win2k here:
formatting link
):

  1. StartRun enter msconfig.

  1. On the General tab, click Selective Startup, and then clear the 'Process System.ini File', 'Process Win.ini File', and 'Load Startup Items' check boxes. Leave the 'boot.ini' boxes however they are currently set.

  2. In the Services tab, check the "Hide All Microsoft Services" checkbox, and then click the "Disable All" button. If you use a third party firewall then re-check (enable) it. For example, if you use Zone Alarm, re-check the True Vector Internet Monitor service (and you may also want to re-check (enable) the zlclient on the Startup tab.) Equivalent services exist for other third party firewalls. An alternative to this for XP users is to enable at this time the XP native firewall (Internet Connection Firewall - ICF). Be sure to turn it back off when you re-enable your non-MS services and Startup tab programs and restore your normal msconfig configuration after cleaning your machine.

  1. Click OK and then reboot.

For additional information about how to clean boot your operating system, click the following article links to view the articles in the Microsoft Knowledge Base:

310353 How to Perform a Clean Boot in Windows XP
formatting link
How to Perform Clean-Boot Troubleshooting for Windows 2000
formatting link
How to Perform a Clean Boot in Windows Millennium Edition
formatting link
How to Perform Clean-Boot Troubleshooting for Windows 98
formatting link
How to Perform a Clean Boot in Windows 95
formatting link

I did a little research about this Trojan, Downloader.Generic.ML, but couldn't find any information under that name from _any_ of my available resources (including Grisoft, BTW), nor about your aberrant c:\\null file. I would wonder if this is any sort of possible byproduct of some legitimate software heuristically detected by a (recent?) AVG update.

Anyhow, try A2 and post back, please.

oh, i don't know... a little saying that goes "nothing's perfect", perhaps?

of course whether or not the user knows their product is fallible has no bearing on whether or not the product is useless or useful...

it is one of many layers of protection that users should be using... unfortunately it's often the only layer they're actually using...

non-sequitur... that doesn't affect whether or not the scanner is useful...

Ron - In addition to my previous post - FWIW, several MVP's are reporting on one of my private lists that numerous "false positives" are showing up with the last but one (two?) AVG update. Evidently there are two very recent "replacement" updates available now (although you will have to manually download them I'm told) to address the problem.

OK, so I did the whole SysClean thing from the very latest stuff(691) at Trend. I did however use Safe Mode GUI on the affected system to host the process rather than a totally clean OS install. It found NOTHING!.....it took about 12 hours to complete the process.

Is there any reason to believe that A2 would be worthwhile? Does trying it again using a clean OS install(move HD to another clean PC or boot from floppy) really useful? Is it just a Cartesian parnoid possbility that something could be in the SafeMode OS environment and could be "deceiving" the scan? Are such deceptions well known or just some theoretical possibility?

Google what exactly?

Define "compromised"?

HUH? With all the app installs, updates and settings to recreate one's working environment, it is often a huge and tedious job. AND a job that the immediate user might not be up to undertaking.

Define "known good"!

That's the catch 22. If one's virus checkers weren't up to detecting it before/at the fact then why be confident that "test it, check it etc etc." has any meaning.

Fixing the sytem in place is the much more reasonable route. That of course assumes that there are competent and effective tools to help one do that. The conclusion one might draw from what you and a few others have been saying is that no such tools exist?

"Some time ago" seems to be confirming what I said.

Now did your test PC have a then current virus checker and a then current firewall?

OK. so I assume you finished the experiment and can tell us when "two popular virus scanners" DID start finding it?

"never" implies incompetence/fraud or that the infection was a very special one target thing.

OK, so tell us all the secret solution save the daily clean OS install that seems so popular here

"Some time ago"....

HMM, now that sounds like something I'd say.

YES, now if someone would care to describe in more detail why that came to pass rather than hyperbole and paranoid rantings then I'd be happy. Is that protection model many are using totally bogus?

HMM, am I the OP of this thread?

Glad to see that some folks actually know how to do backups these days. I like removable SATA drives in shock mounted trays like KingWin KF-83 but USB2 works well.

Well, "blocks" or notices and queries? Does ZA deal with sharing settings or only deal with actual file access attempts?

EXACTLY! That's the condition precedent.

A url or two please.

RIGHT, and your view plus the apparent failure of the normal model in my case is why I'm the OP of this thread and am trolling for hints about an improved model.

Did I use the word fraud before in this thread?

AH, yes a horribly paranoid clean install and burn the backups article(yes read it) by someone who should by off with Descartes looking for the evil demons. I say "It boots and surfs so therefore it is." Now lets's make it do it better and catch those nasty lurking litte demons and exorcise them....after all I don't have launch codes on this system.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required