Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
computer has one instance of downloader.alchemic.A and 2 instances of downloader.agent.as on it. AVG finds the 3 virus instances but cannot delete/heal/remove to virus vault. Tried the Turn off system restore and restart fix. AVG still finds the viruses. Norton doesn't find them at all. I've looked for the manual removal steps on the net, but have found many varying answers. Is there a set fix for these exact viruses? Thanks for the Help
Drew Michael
dmichael112@hotmail.com

Visit this site to learn about removal of your Trojan:
http://fr.trendmicro-europe.com/enterprise/security_info/ve_detail.php?VName=TROJ_ALCHEMIC.Agood luck

I to have this problem except that mines says it's in need C:\_Restore\Temp\A0017764.CPY
AVG found it; I've tried to have the software deal with it but it can't. Could I deleted it, but isn't likely to be an important file since it's in the restore folder... Is there anyother way?

If you are Win Me or Xp you must do this:
http://download.nai.com/products/mcafee-avert/SystemHelpDocs/DisableSysRestore.htm
It covers both Me and Xp (scroll down), then run your updated AV from safe mode. If it's a trojan, note the file name and delete it in "Find" or "search files and folders", and, still in safe mode (in order):Trojan Hunter trial version:
http://www.misec.net/
Trojan Scan:
http://www.windowsecurity.com/trojanscan/SWATIT:
http://swatit.org/download.html
Then, still in safe mode:
General clean-up:
Expose Hidden Files (Me):
http://www.xtra.co.nz/help/0,,4155-1916458,00.html
Expose hidden files, 2 ways in XP:
#1.:Make sure your settings allow you to view "Hidden files". Open up any explorer windows and click on "Tools" => "Folder Options" => "View" and be sure to check off "Show Hidden Files and Folders".
Some people claim that is not enough in all cases, so #2.:
http://www.davehigham.zen.co.uk/downloads/xphidden.zip
Download xphidden.zip. Extract xphidden.reg and save it to ‘desktop.’ Double-click the xphidden.reg and when prompted to ‘merge’ > yes.
I use Me, so I have never used the XP process for exposing hidden files...Caveat Emptor, folks...thats the best I can do...
Still in safe mode, continue cleaning:
dump TIF:
Tools > Intenet Options> General Tab > Delte files > check the box to delete off line content > click ok > delete cookies > click ok.
Dump %TEMP% files:
Dble click My Computer icon on desk top > type %TEMP in the address bar > click enter > delete all you can delete.
Empty recycle bin.
Go to start > Programs > Accessories > System Tools > Run disk clean up, then scan disk, if scan disk tells you there are programs running in the background--ctrl+alt+delete and end-task on everything except sytray and explorer, the run scan disk > then defragmenter.
If you are Win Me, read this:
Me set up page, Trev:
http://www.burzurq.com/forum/trevtweak.htmlIf you need a free good firewall (I use it) go here:
Free Sygate firewall:
http://smb.sygate.com/products/spf_standard.htm
Use these free diagnostics:
Jason’s Browser Security Test:http://www.jasonstoolbox.com/BrowserSecurity/
Gibson tests:
http://www.grc.com/default.htm
I use LeakTest, DCOMbobulator, ShieldsUp, and UnplugNprayThresher

Thanks a ton for all the fix helps. I now have ANOTHER problem. The computer is clean from viruses. AVG with latest defs now shows no viruses, spybot has cleaned all it found, trojanhunter comes up finding nothing. Problem now though is that the computer will not go to any antivirus website. Symantec comes up "Sorry page could not be displayed" ...so does trendmicros housecall site. Any AV site comes up with that error message while other sites not related to AV come up just fine. ANY IDEAS? I've rerun all the tools and found nothing.
Thanks again!
Props to Thresher for all the detailed explanations.
Drew
Drew Michael
dmichael112@hotmail.com

![]() |
fragment flood attack
|
New update for hijack thi...
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |