Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jul 20th, 2008, 1:16am
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Trojan.win32.dnschanger.mc
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Trojan.win32.dnschanger.mc  (Read 900 times)
arachnid
Newbie
*





   


Posts: 3
Trojan.win32.dnschanger.mc
« on: Sep 12th, 2007, 10:37am »
Quote Quote  Modify Modify

I am running XP pro with sp2 update on a AMD Athhlon(tm) XP 3000 2.18 GHZ with 1 GB of ram. I have "Trojan Hunter 4.6 build 930" and Zonealarm as my firewall. Today I ran a scan from my Zonealarm firewall. After the scan it came up that 2 instances of a trojan "win32.dnschanger.mc" were found one in the Windows\system32 folder with a file name kdemp.exe and also in the system volume information\restore folder. Zonealarm's main function is for viruses and spyware but it has found a number of trojans recently whilst doing a virus scan, but Trojan Hunter a dedicated Trojan finder has not picked these up. I can find little information on this (trojan-virus) and non at all from Trojan Hunter. Firstly is this a true trojan or a virus. Why is Trojan Hunter not picking these up and although in the wrong section why isn't Trojan Hunter Guard stopping them in the first place.
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5516
Re: Trojan.win32.dnschanger.mc
« Reply #1 on: Sep 12th, 2007, 2:39pm »
Quote Quote  Modify Modify

Welcome to the forum arachnid  Wink
 
First, you really need to update to the latest version of TrojanHunter which is Version 5.0.  V4.6 is two significant revisions behind.  The link below explains V5.0.
 
http://www.misec.net/forum/board/TrojanHunter/1189327431
 
I cannot find any info on the validity of kdemp.exe via a Google search.  Therefore it is not possible for me to "guesstimate"  whether it is truly malicious or not.  
 
Please do the following:
 
1.  Submit the file kdemp.exe for analysis by Mischel Internet Security.  The link below defines how to do this:
 
http://www.misec.net/forum/board/FAQ/1139308293
 
2.  Run the file kdemp.exe through Virustotal and see what other scanners report.  The link below is for Virustotal.
 
http://www.virustotal.com/
 
If Virustotal is busy, use Jotti
 
http://virusscan.jotti.org/
 
Please post back what these scanners report on the file.  
 
And lastly, the probable cause of THGuard is not alerting first on the previous trojans is a matter of "who detects it the fastest and firstest" locks the infected file so others cannot see it.  So ZoneAlarm is probably seeing the infection before THGuard.  THGuard polls memory every 10 seconds looking for infections.  So there is a fairly large window in there for ZoneAlarm to get there first.  
 
Also the blog on 3-Aug-07 by Gavin Coe "TrojanHunter Detection Rates" might explain further what you are seeing.
 
http://blog.misec.net/tag/trojans/
« Last Edit: Sep 12th, 2007, 3:09pm by siliconman01 » IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
arachnid
Newbie
*





   


Posts: 3
Re: Trojan.win32.dnschanger.mc
« Reply #2 on: Sep 12th, 2007, 9:31pm »
Quote Quote  Modify Modify

SmileyThankyou for the welcome Siliconman 01 and for the quick response. Have done all that was requested and an email with the file kdemp.exe, zipped and password protected and as an attachement has been sent. I think you might want to have a look at this one asap as it's a real nasty Shocked. I submitted the file to Virustotal.com but have only listed 5 results as there were quite a few.
 
Symantec :- Trojan.zlob
Avast :- Win32 chancrypt
Bit Defender :- Trojan.DNSchanger.bf
Panda Rootkit/xxxAccess
Rising :- Rootkit.win32.Access
 
 CoolI was pleased to note that version 5 has a revision update included so I won't get caught out running an older version again  Cheesy
 
 Lips Sealed Accept explination as to why Zonealarm would have got to this first as infact I had to disable the online scanner as each time I tried to restore the file from quarantine to submit it the online scanner kept putting it back in. However thankfully Trojan Hunter Guard doesn't take the vast amount of memory that Zonealarm's online scanner does. I am also not convinced that a simple delete of the .exe file that Zonealarm proposes will cure this one. I have no idea where I picked this up, and if it's of any help to you  and for referance Hijackthis appears to miss it as well.
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5516
Re: Trojan.win32.dnschanger.mc
« Reply #3 on: Sep 12th, 2007, 10:56pm »
Quote Quote  Modify Modify

Definitely looks like you found a malicious critter on your system.  Here is a link that explains how to get rid of it in your System Volume Information folder.
 
http://www.misec.net/forum/board/FAQ/1139255588
 
I emailed Gavin also concerning your email submittal.  You should hear from him shortly.
 
It might be a good idea to also run a remote scan with Kaspersky via the link below.
 
http://www.misec.net/forum/board/FAQ/1141894786
 
« Last Edit: Sep 12th, 2007, 11:04pm by siliconman01 » IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
arachnid
Newbie
*





   


Posts: 3
Re: Trojan.win32.dnschanger.mc
« Reply #4 on: Sep 16th, 2007, 5:12pm »
Quote Quote  Modify Modify

Smiley SmileyThankyou siliconman01. Have removed this nasty critter from my system volume information file as directed by the link and all went without a hitch. I hope i followed the instructions correctly for sending the email and that Gavin received the file. I await his reply. Grin Grin
« Last Edit: Sep 16th, 2007, 5:14pm by arachnid » IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5516
Re: Trojan.win32.dnschanger.mc
« Reply #5 on: Sep 16th, 2007, 11:59pm »
Quote Quote  Modify Modify

I received an email yesterday from Gavin stating that he did not receive an email on this.  
 
Would you please resend the file.  Be sure the email address is submit@misec.net and that the file is zipped and password protected so that it will pass through the email various servers along the way.
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register