Trojan.generic.375865

Hello, can anyone help me get rid of this? BD says no action possible. Thank you.

Comments

  • I had the same problem.... said that no action can be taken... please fix! :(

  • I was given the same notice today. Trojan.Generic.375865 was detected and no action possible. What are we supposed to do and what kind of trojan is this?

  • mspringer
    mspringer ✭✭
    edited July 2008
    I was given the same notice today. Trojan.Generic.375865 was detected and no action possible. What are we supposed to do and what kind of trojan is this?


    My scan last nite also flagged 4 occurrences of the same Trojan. Mine was in a registry key associated with QuickTime, in the QuickTime installer (Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\QuickTime) and in several of the restore points. To get rid of it I uninstalled QuickTime (and Itunes), trashed the installer and deleted the restore points. Re-running BitDefender showed removal of the 'infection'. However, I'm not sure this was a real problem rather than a false positive. If you Google for the Trojan you find that it seems to be only detected by BitDefender and only in the last 24hrs when it suddenly became the most prevalent infection. Hopefully one of the experts can clarify.


    Marty

  • rootkit
    rootkit ✭✭✭

    To all of you:


    Paste here where is the location of the trojan !

  • I had the same problem.... said that no action can be taken... please fix! :(


    I'll have to agree with mspringer that this possible was a false positive cuz I re-run BD twice to check the location of the trojan and it said that there was no problem, and I didn't do anything.

  • To all of you:


    Paste here where is the location of the trojan !


    Here were the locations:


    [system]=]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\QuickTime Task=]C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE


    C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.6.2.9\QuickTime.msi=](Embedded CAB)=]QTTask.exe


    C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\QuickTime 7.50.61.0\QuickTime.msi=](Embedded CAB)=]QTTask.exe


    C:\System Volume Information\_restore{690019E0-5BAF-408F-87F8-3400F3EA2022}\RP115\A0023436.msi=](Embedded CAB)=]QTTask.exe


    C:\System Volume Information\_restore{690019E0-5BAF-408F-87F8-3400F3EA2022}\RP51\A0009200.rbf=](Embedded CAB)=]QTTask.exe


    Marty

  • Here were the locations:


    [system]=]HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\QuickTime Task=]C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE


    C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 7.6.2.9\QuickTime.msi=](Embedded CAB)=]QTTask.exe


    C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\QuickTime 7.50.61.0\QuickTime.msi=](Embedded CAB)=]QTTask.exe


    C:\System Volume Information\_restore{690019E0-5BAF-408F-87F8-3400F3EA2022}\RP115\A0023436.msi=](Embedded CAB)=]QTTask.exe


    C:\System Volume Information\_restore{690019E0-5BAF-408F-87F8-3400F3EA2022}\RP51\A0009200.rbf=](Embedded CAB)=]QTTask.exe


    Marty


    (I have the same problem as you guys. Plus my Bit Defender is behind on updates (it's set to atuo) and I tried to fix it but it won't fix. I have emailed their support tech.)


    HERE IS WHERE MINE ARE:


    C:\Documentsand Settings\AllUsers\ApplicationData\AppleComputer\InstallerCache\QuickTime7.4.5.67\QuickTime.msi=>(EmbeddedCAB)=>QTTask.exe


    C:\DocumentsandSettings\AllUsers\ApplicationData\AppleComputer\InstallerCache\QuickTime7.50.61.0\QuickTime.msi=>(EmbeddedCAB)=>QTTask.exe


    C:\Documentsand Settings\NetworkService\LocalSettings\ApplicationData\Apple\AppleSoftwareUpdate/QuickTime.msi=>(EmbeddedCAB)=>QTTask.exe


    C:\SystemVolumeInformation\_restore{C3A256EC-F74E-4D1B-B627-49321DAD0241}\RP1598\A0265115.msi=>(EmbeddedCAB)=>QTTask.exe


    Sue

  • The given detection was a false positive which has been removed. Please update the signature files.


    Best regards.