[x]
Posted via EE Mobile

Search, ask, and monitor your questions on the go with EE Mobile. Visit Experts Exchange from your mobile device and never be out of touch again.

Question
[x]
Attachment Details

Trojan-Downloader.JS.Psyme.hz

Asked by mrmoderate in Kaspersky, Internet Security, Symantec Anti-Virus Software

Tags: trojan, kaspersky, norton internet security, norton internet security 2009, sophos

I ran a scan using Kapersky's online scan tool.  I did this twice.  (BTW, I'm running Windows XP Media Center Edition SP3 and IE 8.0.6....)

The first time, I came up with 4 trojan downloaders: Trojan-Downloader.JS.LuckySpoit.e, Trojan-Downloader.JS.Psyme.hz, another instance of Trojan-Downloader.JS.Psyme.hz, and Trojan-Downloader.JS.Iframe.vz.  Apparently, I got rid of the first 3 by uninstalling the application in whose folder the trojan resided.  Also, I got rid of the 4th (the subject of this thread) by just deleting the file and emptying the Recycle Bin.  Then, if I recall, I restarted the PC.

Then, I re-ran the Kaspersky scan.  It, again, came up with the Trojan-Downloader.JS.Psyme.hz; this time it was in a different file.  Both files were contained in the path F:\BackupOnlyESS\My Documents--EMERGENCY BACKUP OF NEW D DRIVE ONLY--Eric\Downloads\members.tsmtravel.com\[2 different yada, yada, yada subfolders].  (Last period closes the sentence.  Not part of path.)  I'm going to, again delete the file Trojan-Downloader.JS.Iframe.vz, the allegedly infected file.  (BTW the "I" in "IFrame" is an "I," as in indigo, not an "L" as in Lotus.)  I'm going to empty the Recycle Bin, restart the PC, download the latest version of Java (I have multiple Java icons in the SysTray), restart the PC, and re-run the Kaspersky online scanner.  We'll see what happens.

TWO QUESTIONS:

(1)  What's the deal?  Kaspersky online scanner (or whatever it's called) found Trojan-Downloader.JS.Iframe.vz the first time around.  It only found the second instance of it the second time I ran the scan.  Did Kaspersky miss it, or did the malware re-create itself, only to be detected the second time around?

(2)  What are the trustworthy sites (e.g., Kaspersky and Symantec) that have an online scanner function?  (I don't know if Symantec even has this.)  It's been suggested on other sites, notably in a CNET forum, that http://www.sophos.com/security/analyses/trojmaranar.html will take care of my problem.  I've never heard of Sophos.  Are they trustworthy?  Is this tool a freebee, or at least one that won't make me uninstall NIS09 (see next paragraph)?

Finally, I should note that I've been running Norton Internet Security 2009 (NIS09).  It missed this trojan, both when running a full system scan and when I told it to scan the file detected on the second running of Kaspersky's online scanner.  So, there's actually a third question:

(3) Do I have a problem with NIS09?  Or, does it suck, despite all of the wonderful reviews?  Or, do I have it incorrectly configured?  Or, is the Kaspersky online scanner paranoid or otherwise malfunctioning?  I don't think the Kaspersky online scanner is just a sales tool, designed to scare potential customers, as I ran it previously on another PC, and it came up clean.

Thanks much.
 
Related Solutions
 
Loading Advertisement...
 
[+][-]09/08/09 03:05 PM, ID: 25286562Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09/25/09 08:32 PM, ID: 25428690Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09/25/09 08:40 PM, ID: 25428705Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09/25/09 08:54 PM, ID: 25428743Expert Comment

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 30-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20091111-EE-VQP-92 - Hierarchy / EE_QW_3_20080625