Author Topic: Archive Trojan  (Read 5337 times)

0 Members and 1 Guest are viewing this topic.

scroll

  • Guest
Archive Trojan
« on: August 18, 2006, 03:25:43 PM »
Avast says there is a Trojan  win32:delf-bcg  in windows  update  KB908531.log.

Any information available? As search reveals little or no info on this Trojan.

Scroll

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: Archive Trojan
« Reply #1 on: August 18, 2006, 03:42:28 PM »
Hi scroll,

Here is the removal instruction:
http://www.spywaredb.com/remove-win32-delf-kjoiner/

polonus
« Last Edit: August 18, 2006, 04:23:35 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Spiritsongs

  • Guest
Re: Archive Trojan
« Reply #2 on: August 18, 2006, 04:00:58 PM »
 :)  Hi scroll :

     Info from Microsoft indicates this Update was released in
     Apr 06 & "updated" 2 months later ( see :
     http://www.microsoft.com/technet/security/Bulletin/MS06-015.mspx ) ; did you get the "revised" "edition" !?

scroll

  • Guest
Re: Archive Trojan
« Reply #3 on: August 18, 2006, 04:14:43 PM »
Hi Polonus

Can't find anything, but thanks for the link.See there's another poster with the same problem? False positive?

Hi Spiritsongs.

Last update 10th June 2006, so seems I have the latest version, but thanks anyway.

Scroll

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: Archive Trojan
« Reply #4 on: August 18, 2006, 04:25:32 PM »
Howdy Scroll,

It is always a good policy to clean crap of your machine. A lot of things that stay onto the machine, can be taken off not doing any harm,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

scroll

  • Guest
Re: Archive Trojan
« Reply #5 on: August 18, 2006, 04:31:15 PM »
Hi Polonus

Will run  CCleaner again over the weekend. Seems a good  safe tool to use.Thanks for the intro!

Scroll

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: Archive Trojan
« Reply #6 on: August 18, 2006, 04:35:51 PM »
Hi Scroll,

Splendid thought of yours, I cannot live without CCleaner anymore.
Have a malware free time!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

k86

  • Guest
Re: Archive Trojan
« Reply #7 on: August 18, 2006, 04:38:15 PM »
Hey

Quote
Info from Microsoft indicates this Update was released in
     Apr 06 & "updated" 2 months later ( see :
     http://www.microsoft.com/technet/security/Bulletin/MS06-015.mspx ) ; did you get the "revised" "edition" !?


I've just looked at my update history and I don't have the revised version of the update (I have no idea why though) so I need to download it but should I restore the original file from the chest before I install the update? or would it just be safe enough to delete the file and then install the update

Thank you very much for your time
K86

scroll

  • Guest
Re: Archive Trojan
« Reply #8 on: August 18, 2006, 05:11:11 PM »
Hi K86

Just downloaded latest iAVS, and  scanned offending file.

Gives an OK scan now so a false positive.

Just delete the file and download the latest fix.

Scroll

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Archive Trojan
« Reply #9 on: August 18, 2006, 07:30:20 PM »
Same here, caught by the screen saver module... False positive for sure, but, this time, I'm surprised that a log (txt) file was detected as infected  :o ???
The best things in life are free.

k86

  • Guest
Re: Archive Trojan
« Reply #10 on: August 26, 2006, 12:51:48 PM »
Hey

Thank you all very much for your help :-)

I restored the file from the chest, did a scan and then installed the revised version of the KB908531 windows update and now everything seems fine :-)

Thank you all once again for your help :-)
K86