Computing.Net > Forums > Security and Virus > backdoor.trojan virus

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

backdoor.trojan virus

Reply to Message Icon

Original Message
Name: Derenda
Date: July 12, 2003 at 12:41:53 Pacific
Subject: backdoor.trojan virus
OS: Windows XP
CPU/Ram: 512 MB Ram Pentium Intel
Comment:

Hi,

I need help with a Backdoor.Trojan virus. My Norton AntiVirus will not quarantine or delete the files. It is in this form c:/documents and settings. I have Windows XP and it says the Compressed File Installer_george_test.exe within c:\download and settings. I have ran McAfree, Norton, Trojan and none of them can remove the infected files. Can anyone help me? Thanks for looking.


Report Offensive Message For Removal


Response Number 1
Name: capt
Date: July 12, 2003 at 13:46:11 Pacific
Reply: (edit)

Have you done a search for that file to manually delete it? Have you emptied your temp internet files and disabled "system restore" by using MY Computer>right click>Properties>System Restore>Turn Off System Restore? After your system is clean go back and turn System Restore back on, but set the soder to 2% instead og the default 10% if your hard drive is 30G or larger.


Report Offensive Follow Up For Removal

Response Number 2
Name: Derenda
Date: July 12, 2003 at 14:23:16 Pacific
Reply: (edit)

I tried to find it manually and I can not. I don't know where to search besides at start. I turned off system restore and re-ran Trojan Hunter, and Trojan Remover. Trojan Hunter gave me the following report:
unable to unpack upx-packed file C:\Documents and Settings\Cassie\local Settings\Temporary Internet Files\Content\IE5\184VTTS1\dialer\[1].exe then I also got unable to unpack upx-packed file C:\Program Files\Trojan Remover\unp.exe
I am really confused here. Thank you.


Report Offensive Follow Up For Removal

Response Number 3
Name: capt
Date: July 12, 2003 at 14:50:35 Pacific
Reply: (edit)

Have you deleted your temporary internet files by using Tools>Internet Options>Delete Files?


Report Offensive Follow Up For Removal

Response Number 4
Name: Derenda
Date: July 12, 2003 at 15:23:46 Pacific
Reply: (edit)

Did that too! I even ran it in safe mode and ran the Trojan programs again, now is says their are no viruses but the Backdoor.Trojan file is still there


Report Offensive Follow Up For Removal

Response Number 5
Name: capt
Date: July 12, 2003 at 15:39:41 Pacific
Reply: (edit)

Perhaps it is a spyware dialer that was detected. Do you use Adaware and SpyBot? If not go to http://www.wilders.org/ and get them. Then see if they will take care of this problem. Also get Spywareblaster, it protects against Active X.


Report Offensive Follow Up For Removal


Response Number 6
Name: Jim Beau
Date: July 12, 2003 at 19:10:55 Pacific
Reply: (edit)

Hi.

If this is a dialer Spybot should fix it.
If not a dialer and really a backdoor trojan,send an email to Trojan Hunter's developer.
There should be a link in the TH program under "About" tab in the TH console.
I submitted a suspicious file when I trialled Trojan Hunter.
Or you could go to the Trojan Hunter support forum.

For faster file searches there is a free program that is excellent.
Google search for "AgentRansack".

Hope this helps,
JB.


Report Offensive Follow Up For Removal

Response Number 7
Name: Mark
Date: July 14, 2003 at 06:33:04 Pacific
Reply: (edit)

I have this virus, too and am having the same problems. I will be monitoring this thread for a fix. Or, should I find one, I will let you know!

Mark


Report Offensive Follow Up For Removal

Response Number 8
Name: jim
Date: July 19, 2003 at 15:16:37 Pacific
Reply: (edit)

I had the virus too. I am running Nort Corprate Edition 8.0. It quarentined and then I was able to tell norton to delete.

If you are not able to then here are a

couple of things you can try.

First find the file go into properties and make sure you have full access under the security tab. Then try and delete.


Second try cutting and pasting the file to your desktop and then try and delete it.

Third start into safe mode and delete.

And lastly if none of that works startup your pc in repair mode and delete it from the command prompt the old fashion way.

Hope this helps


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software