Author Topic: Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe  (Read 27894 times)

0 Members and 1 Guest are viewing this topic.

Amadeumc

  • Guest
Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« on: December 16, 2004, 07:31:51 PM »
Hi fellas
How can i remove this trojan forever
im using avast 4.5 home and all updates installed

Plz help me
thanks

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #1 on: December 17, 2004, 08:53:16 AM »
Click on the link in my signature and visit the malware removal section.

Amadeumc

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #2 on: December 18, 2004, 12:41:56 AM »
Thanks bro !
I installed spybot and some shit was founded
I think my download acellerator was infected, than i remove him

Now i think im clean
thanks

Amadeumc

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #3 on: December 18, 2004, 08:49:56 PM »
Man the trojan is back !
I cant remove or do nothing with the avast
and the spybot dont detect this one
i installed the Spyware Blaster

But this shit is returning
what more can i do ?
thanks
« Last Edit: December 18, 2004, 08:51:07 PM by Amadeumc »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #4 on: December 18, 2004, 08:55:35 PM »
Do as I suggested that will remove it. And be carefull with what websites you visit, what you download/install etc.

kiwikid

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #5 on: December 20, 2004, 05:13:00 AM »
Excuse me for jumping into your post, but I got the same trojan today when trying to download lyrics to a song. A Macromedia window appeared and stated I could not see the site unless I clicked yes. Although something stuck in my mind that it wasn't right about the box, I clicked yes, it started to download, I got panicky and tried to stop it.  Avast 4.5 made a warning noise and immediately put a box up on my screen telling me of this virus and recommended moving it to Virus chest. [ Brilliant catch by Avast - really impressed   8) ]

Closed browser, disabled system restore, ran Avast in boot time scan, chose 1. delete [my isp said that the C:\temp\.. files were not vital so could use delete in this instance.]
Ran Adaware = found 4X BlazeFind malware in RegKey[2], RegValue[1], + file in C:\Windows\System32\ide21201.vxd. Got Adaware to delete the regkey and regvalue ones and chose to run spybot to fix the ide21201.vxd file which it did. Re-ran Adaware, Spybot, Avast again and all came up clean.

Now can I go into the Virus Chest and delete the trojan that appears to still be in the chest even though Avast deleted it in boot time, and came up clean when I ran it again?
It says this will delete it irreversibly, ie. not removed to recycle bin.

PS:Adaware also found 3x WindUpdates malware [data miners, TAC8].
Do go on a bit don't I? sorry.
« Last Edit: December 20, 2004, 05:17:33 AM by kiwikid »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #6 on: December 20, 2004, 03:47:14 PM »
Now can I go into the Virus Chest and delete the trojan that appears to still be in the chest even though Avast deleted it in boot time, and came up clean when I ran it again?
It says this will delete it irreversibly, ie. not removed to recycle bin.

Yes, you can delete from Chest.
But, if you're not sure that it was a malware, wait few days to do it.
It won't harm in anyway if it's on the Chest  ;)
The best things in life are free.

kiwikid

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #7 on: December 20, 2004, 06:37:52 PM »
Thanks for the prompt reply Technical  :)
My computer is functioning ok. Will leave it in the chest for the moment as I don't feel threatened by it.

I'm living proof that it is the User's actions, more than the OS, which gives you more grief. My first virus!  :-[

REDACTED

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #8 on: December 21, 2004, 05:54:40 AM »
I keep getting the above virus. At 10:37 every night, avast goes off saying that it is infected with the file. I've tried deleting it, says its not  valid, try moving to the chest, says its not valid. Tried running all those programs listed on your site Eddy last night, and it came up proptly at 10:37 again tonight. Tried running in safemode tonight and running avast from there, so i guess i'll find out at 10:37 tomorrow if it really got rid of it.. I'm just about to just wipe the whole system and start over. this is the first virus I have ever received, and of course its on my 2 week old brand new computer :(  Any other suggestions? I've ran every possible program, avast, antivirus, all those on Eddy's site, ad-aware, lavasoft's program. Nothing will get rid of the Ncasepackage.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89164
  • No support PMs thanks
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #9 on: December 21, 2004, 01:41:56 PM »
Have you run HiJackThis and used the log file analyser from Eddy's site? I strongly doubt it, HiJackThis is the best tool for removing items in the registry and this sounds like something is kicking this off (running at 10:37) and that is likely to be a registry entry.

Have you tried scheduling a boot-time scan?

Did you try finding ncase removal tools/advice using google? This is just one of many I found http://www.pchell.com/support/ncase.shtml, google is your friend learn to use the tools. Would you care to guess what they are doing to remove this, yes, editing the registry. This is what HiJackThis does without you having to do it manually!
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #10 on: December 21, 2004, 01:47:51 PM »
Have you disabled system restore before running the applications?
If you follow the instructions on my website, it will be gone. And it won't come back unless you make a mistake. eg by visiting a bad website, install a with malware infected application or such.
« Last Edit: December 21, 2004, 01:48:03 PM by Eddy »

REDACTED

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #11 on: December 22, 2004, 02:33:01 AM »
Yes, I did run Hijack, but i couldn't understand anything it was displaying. After I got the virus again last night i turned off the system restore, so it probably won't fix that until tonight when it goes off again and i try to get rid of it.  Thing i dont understand is I can't delete/repair/move to chest via avast.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #12 on: December 22, 2004, 02:50:23 AM »
Quote
Thing i dont understand is I can't delete/repair/move to chest via avast.
Yes you can, but you must disable the harmfull process first.

watchthisspace

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #13 on: December 22, 2004, 02:57:38 AM »
Have you tried an online virus scan?
Go here for a Trend micro online scan: http://housecall.trendmicro.com/housecall/start_corp.asp
Also, have you tried deleting youe temp files? that might help

inthewildteam

  • Guest
Re:Win32:Trojano-803 [Trj] C:\temp\NCasePackage.exe
« Reply #14 on: December 22, 2004, 04:23:01 AM »
Try reboot into safe mode command prompt/  or dos.......... depending on your os.

From command prompt type "del c:\temp\*.*"  no quotes.  press enter!

Reboot into Windows and delete your I.E cache then try a full scan, (or alternative browser's cache)

If you are using M.E. XP, disable system restore first, as posted above.
« Last Edit: December 22, 2004, 04:34:17 AM by inthewildteam »