Computing.Net > Forums > Security and Virus > avg finds stealth trojans

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

avg finds stealth trojans

Reply to Message Icon

Name: frank breen
Date: November 27, 2004 at 07:33:21 Pacific
OS: wxp
CPU/Ram: 1.8g/512k
Comment:

Hello Everyone,
I have the avg virus program, it keeps popping up and reporting I have a trojan horse in c:\temp\installer2.exe and in c:\temp\instal~1.exe. The trojan is dripper.delf.3.l. It also reports I have the trojan downloader.vd.4.b in c:\windows\cupdate.exe. It asks what it should do, with installer2.exe, I can use the delete option, it reports it delete the file. With instal~1.exe it can't delete, heal or isolate the file, I then use the continue option. These keeping popping up as I surf the web. Another mystery trojan is the one in c:\windows\cupdate.exe, this keeps popping up not as often as the ones in the temp sector. I have erased all files in the temp sector with the exception of the folders that seem to belong in this area. I just ran an online scan at trend, it could find nothing. This has me scratching my head.
I was wondering if anyone has some advice as to the next steps I should take with reference to these virus alerts. I don't want to ignore them as they could be there or at some time in the future could infect my computer.
I thank you in advance for any help you can give me,
frank



Sponsored Link
Ads by Google

Response Number 1
Name: RoadRunner
Date: November 27, 2004 at 08:23:13 Pacific
Reply:

Hi ...If you have an Anti-Virus Program which is fairly new ( mostly under a year )and you are sure that you are still recieving update definitions ? Then update yours now ....
Then afterward download a few programs , Like these here below

first one is Ad aware ( free Version )

http://www.lavasoft.de/support/download/

Start up this program , What you need to get is the most latest update for it ,run JUST the "updated" option and afterward close the program for later use ...

Next program >> Spybot Search and Destroy ( Free )

http://www.safer-networking.net/en/download/index.html

Next Program >> SpywareBlaster ( Free )

http://www.javacoolsoftware.com/sbdownload.html

Okay now perform this operation from this website below

http://support.microsoft.com/?kbid=310405

Okay this is next to perform below :

Click Start. >>Open My Computer. Select the Tools menu and click Folder Options. Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders. Uncheck the Hide protected
operating system files (recommended) option. Click Yes to confirm. Click OK.
DON'T WORRY ABOUT THE WARNING POP UP WINDOW THIS IS NORMAL , just click yes

Now its time to start your computer in Safe Mode
How to start up in safe mode , there is 2 ways in doing so , just choice one method only ... Look at this website below

http://www.bleepingcomputer.com/forums/index.php?showtutorial=61#winxo

Okay once in safe mode do the following : Clear out the Temporary internet files and other temp files.
Go to Start > Settings > Control Panel >Internet Options.
Under the General tab click the Delete temporary internet files,
delete all Offline content as well. Clear out Cookies ... Now close eveything and be back at your desktop

Now click the start buttom > then the Search/Find option > click Files or folders > in the named box, type: *.tmp , click search and choose Edit > select all -> File > delete.

Empty/delete the entire contents of the C:\Windows\temp folder and C:\temp folder, (Contents only but not the folder itself.)

This one too if it is there C:\Documents and Settings\username\Local Settings\Temp\
Delete the recycling bin ...

Now start up Ad Aware and just basically perform the options its set at for now ... And remove whatever it finds ...
Start spybor search and destory and do the same with this program
Also with the spyware blaster , just clean what it finds ....

Now use your Anti - Virus Program and run it and see what it finds ...If your anti-virus finds anything try the repair option first, if that can't be done then delete the file...
Now restart your computer back to normal mode and reset the setting back too...Once your computer is up and running do the following :
http://support.microsoft.com/?kbid=310405
and this next >>> : http://www.microsoft.com/technet/prodtechnol/winxppro/maintain/xpsysrst.mspx
Okay after all that was done and you want to be sure its clean go to these anti virus scan sites and do the scan from each site if you like

http://www.trendmicro.com/download/dcs.asp

http://windowsxp.mvps.org/Scanners.htm

http://housecall.trendmicro.com/

http://www.bitdefender.com/scan/licence.php

http://security.symantec.com/sscv6/home.asp

http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

Afterward you can download hijackthis and have someone look at your log for programs that shouldn't be there ...

http://www.spychecker.com/download/download_hijackthis.html


0

Response Number 2
Name: frank breen
Date: November 27, 2004 at 10:20:04 Pacific
Reply:

Hello Road Runner,
You are dazzling me with a storehouse of data, I thank you for this. I have adaware, spybot and spyware blaster. I will follow your roadmap and see if I come up with something, again, thank you for a procedure to follow,
frank


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Downloader Agent 3.BO Spyware Toolbar



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: avg finds stealth trojans

AVG Finding virus T.exe, comes back www.computing.net/answers/security/avg-finding-virus-texe-comes-back/14217.html

AVG found a Trojan in a TurboTax fi www.computing.net/answers/security/avg-found-a-trojan-in-a-turbotax-fi/23453.html

backdoor.agent.ba removal www.computing.net/answers/security/backdooragentba-removal/12526.html