Page 1 of 2 12 LastLast
Results 1 to 15 of 19

Thread: Trojan Horse Agent ZCJ

  1. #1

    Zeropaid Noob

    Join Date
    Jul 2008
    Posts
    4

    Trojan Horse Agent ZCJ

    Just downloaded WinRAR 3.80 beta 3 from filehippo.com, and AVG has just done a scan to say that it's infected with the above trojan. No mention of said trojan anywhere else on the net. Is AVG right, should I be worried, or is this just bullshit?

    Cheers

    Tom

  2. #2
    HelenaP's Avatar

    go luath.. céanna go luat

    Join Date
    Jun 2007
    Location
    An bealach fada chun an bhaile
    Posts
    6,090
    Perhaps download and run this-
    http://www.majorgeeks.com/Malwarebyt...are_d5756.html

    I'm still looking for something else thaT MIGHT be useful.

    Sorry bout the caps. Haven't had my coffee yet.

    Edit: Not sure where you were looking in the Internet, but I am seeing all sorts of results.

    The most Beautiful thing we can experience is the mysterious.
    It is the source of all true art and science.
    ~ Albert E.


  3. #3

    Zeropaid Noob

    Join Date
    Jul 2008
    Posts
    4
    Thanks, will give that a go.

    By the way, isn't it like before 6am where you are? What the hell are you doing up at this time? It's past 2pm for me!

  4. #4
    HelenaP's Avatar

    go luath.. céanna go luat

    Join Date
    Jun 2007
    Location
    An bealach fada chun an bhaile
    Posts
    6,090
    No, it's 8:00 right now.

    I am going to keep looking (because this stuff is interesting), but have an appointment (maybe one of the awesome, knowledgeable dudes will show up), so am about to leave.

    Are you positive it's ZCJ and not CCJ or BCJ?

    The most Beautiful thing we can experience is the mysterious.
    It is the source of all true art and science.
    ~ Albert E.


  5. #5

    Zeropaid Noob

    Join Date
    Jul 2008
    Posts
    4
    definitely ZCJ. it's in my AVG virus vault at the moment.

  6. #6
    HelenaP's Avatar

    go luath.. céanna go luat

    Join Date
    Jun 2007
    Location
    An bealach fada chun an bhaile
    Posts
    6,090
    You might also dl HJT-
    http://www.trendsecure.com/portal/en...kthis/download

    and post your results here.

    You could also go through the steps laid out by Castle Cops-

    http://wiki.castlecops.com/Malware_R...tion:_Overview

    Quote Originally Posted by tom_manchester View Post
    definitely ZCJ. it's in my AVG virus vault at the moment.

    Gotcha.

    The most Beautiful thing we can experience is the mysterious.
    It is the source of all true art and science.
    ~ Albert E.


  7. #7
    uselesscrap's Avatar

    shud up shuttin up

    Join Date
    Oct 2004
    Location
    where you're not
    Posts
    478
    That is strange, cause I downloaded the latest spyware blaster from filehippo a while back and it too was infected with a trojan. I am wondering if AVG finds part of their software(s) as a false positive. It seems strange that filehippo would host an infected file, doesn't it? Very odd. I tried this same download on my main computer and EST Security did not detect anything.
    Protest long enough that you are right, and you will be wrong

  8. #8
    mountain_rage's Avatar

    Zeropaids nipple

    Join Date
    Mar 2004
    Location
    purgatory
    Posts
    7,069
    Well if symantecs information of a different variant of the virus is accurate for this version than you will probably want to run your anti-virus in safe mode. To get into safe mode hold F8 when windows starts. Then just select run in safe mode. This works to remove viruses most of the time. That is if the virus is still causing you problems, you did mention its in your avg vault.

    Also, just a heads up. If you want an alternative to winrar try 7zip, its always worked great for me.
    Anyone upset or offended by my post please follow the link and let your opinions be known.
    http://www.zeropaid.com/bbs/showthread.php?t=55492

  9. #9
    RACKnRAIL's Avatar

    今は知っているでしょ

    Join Date
    Apr 2003
    Location
    an island in the pacific
    Posts
    6,540
    Quote Originally Posted by mountain_rage View Post
    Well if symantecs information of a different variant of the virus is accurate for this version than you will probably want to run your anti-virus in safe mode. To get into safe mode hold F8 when windows starts. Then just select run in safe mode. This works to remove viruses most of the time. That is if the virus is still causing you problems, you did mention its in your avg vault.

    Also, just a heads up. If you want an alternative to winrar try 7zip, its always worked great for me.
    From my own experience I can tell you this method can be effective, but certainly no guarantee. I recently had a virus hiding in sys restore, that could not be removed, even in safe mode. However, after disabling sys restore I was able to remove it by running the same scan. It was only after running Housecall that I discovered where it was hiding though.

    Often I will use my garage computer and plug the infected HD as a slave and run everything under the sun on it, including booting to MiniPE XT, which has several AV's and anti-spyware apps.
    -----------®N®----------


    あなたをファック

  10. #10
    HelenaP's Avatar

    go luath.. céanna go luat

    Join Date
    Jun 2007
    Location
    An bealach fada chun an bhaile
    Posts
    6,090
    I just want to amend what MR and ®N® have suggested.

    Before you go into safe mode to run the AV or AM, I think you are supoosed to turn system restore off.

    The most Beautiful thing we can experience is the mysterious.
    It is the source of all true art and science.
    ~ Albert E.


  11. #11
    mountain_rage's Avatar

    Zeropaids nipple

    Join Date
    Mar 2004
    Location
    purgatory
    Posts
    7,069
    forgot about sys restore, mines always off. Good catch RnR.
    Anyone upset or offended by my post please follow the link and let your opinions be known.
    http://www.zeropaid.com/bbs/showthread.php?t=55492

  12. #12
    thepuzzler's Avatar

    parp

    Join Date
    Aug 2005
    Location
    UK
    Posts
    1,118
    Hate to state the obvious, but why not download it from the offical winrar site rather than a third party?

    www.rarlabs.com

    A little common sense is the best virus protection anyone could ask for...
    A couple of sites I've been working on if you're interested http://www.howtogetfaster.co.uk, [url]http://www.documentaries.me.uk[url] and a new startup http://thelocalseo.co

  13. #13

    Zeropaid Noob

    Join Date
    Jul 2008
    Posts
    1

    Regarding Trojan Horse Agent.ZCJ

    Greetings from Sweden :)

    Yesterday, we downloaded a monopoly-game(about 2 year old torrent) from thepiratebay.org, opened up the folder where the file landed and directly got a popup from AVG telling that it had found the trojan: Trojan Horse Agent.ZCJ.

    We ran AVG scan, successfully removed the trojan (that's what we thought atleast).
    I have two partitions of my harddrive, we removed the file we downloaded, and ran AVG scan again - threat still found, in WinRAR.exe.

    Then we did a complete OS reinstall of Windows XP Pro SP2.
    Installed all drivers and the applications we wanted to use.
    When it came to WinRAR though... When we installed WinRAR (downloaded from www.rarlabs.com) we got the same friggin trojan.

    Ran Ad-Aware which found alot of threats, we did not check the logfiles though so we did not accually see what it found, but it removed the threat. Ran AVG - No threat. Ran Ad-Aware again, no threat.

    So we believe that we have successfully removed the trojan by now, but we are not going to download WinRAR again, thus it seems that AVG reacts very strong on in.

    We are also currently using 7zip instead of WinRAR.

  14. #14
    HelenaP's Avatar

    go luath.. céanna go luat

    Join Date
    Jun 2007
    Location
    An bealach fada chun an bhaile
    Posts
    6,090
    I guess I'm just lucky.

    I dl'ed mine in 2005 when I started uni and have never had a problem with it.

    The most Beautiful thing we can experience is the mysterious.
    It is the source of all true art and science.
    ~ Albert E.


  15. #15

    Zeropaid Noob

    Join Date
    Jul 2008
    Posts
    4
    Should i post the main.txt and extra.txt files from DSS? Would that help?

Page 1 of 2 12 LastLast

Similar Threads

  1. garage old skool
    By maccanappa in forum Music
    Replies: 17
    Last Post: October 9th, 2007, 04:18 PM
  2. Trojan horse leads to porn convictions
    By Jared Moya in forum The Lounge
    Replies: 1
    Last Post: August 27th, 2006, 03:11 AM
  3. trojan horse -suicide-TB
    By northwest stew in forum General Discussion
    Replies: 4
    Last Post: March 11th, 2005, 07:22 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •