Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

trojan infection - possibly from IZArc_Setup

Oct 3, 2008 11:04AM PDT

My computer is a Dell Dimension 4600 with Win XP Home 5.1.2600 Service Pack 2 Build 2600. It has been running normally. I have Panda Internet Security 2008 12.00.01 installed and running.

This morning I downloaded IZArc_Setup.exe from http://www.download.com/3001-2250_4-10826781.html?idl=n (at least, that is the link that I get now when I start the download process.)

I then installed and ran the program. After about a minute in the program my desktop background changed to white with a warning "window" in the center warning of infection. Nothing in the "window" was clickable.

Panda gave a message that it was restoring something (I do not rememeber the name) that it had mistakenly quarantined. There were no other warnings or messages from Panda. Neither Panda's full scan nor Total Scan Pro found any problems.

I installed Malwarebytes' Anti-Malware and it removed all the problems. Below is the relevent portions of the log. I also have a jpg of my infected desktop.

At this time, I believe that the infection was from IZArc_Setup.exe but Panda sees no problem with it.

***************
Malwarebytes' Anti-Malware 1.28
Database version: 1225
Windows 5.1.2600 Service Pack 2

10/03/2008 5:37:07 PM
mbam-log-2008-10-03 (17-37-07).txt
Memory Processes Infected:
C:\WINDOWS\SYSTEM32\lphcjtfj0eea7.exe (Trojan.FakeAlert) -> Unloaded process successfully.

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcjtfj0eea7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\Downloaded Program Files\atmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\COUNTER.BAT (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\lphcjtfj0eea7.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\phcjtfj0eea7.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Documents and Settings\RAB\Local Settings\Temp\.ttD.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
***********

I am ok now but perhaps someone can check IZArc_Setup.exe.

thanks,
rab106

Discussion is locked

- Collapse -
Thanks for letting us know.......
Oct 3, 2008 11:22AM PDT

I have informed our Administrator, Lee Koo.

- Collapse -
Thanks for reporting this rab106
Oct 8, 2008 9:24AM PDT

I have notified the CNET Download.com team of this title to have them check for any malware.

I will report back what they find.

Thanks again!
-Lee

- Collapse -
UPDATE. CNET Download.com did a thorough check and ...
Oct 10, 2008 2:17AM PDT

the results came back negative on this particular title. No malware was found.

It may very well be a false positive reported with Panda Internet security. I would update your security software with the latest definitions and try to download the software title again to see if it happens again. Or if you don't feel comfortable with that, then I would just suggest not download the title again.

The CNET Download.com team takes these reports from you folks seriously and they do a thorough check to ensure that what was reported is safe. And if it's not they will immediately remove the title from the site.

Best regards,
-Lee

CNET Community