Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Today I discovered I have 2 viruses: belt.exe and Ruledor.B, some kind of backdoor nasty. McAfee firewall caught belt.exe trying to access the internet. I had not seen this program, so Googled it and found this forum. McAfee Antivirus didn't catch either of these cooties. I scanned at: ravantivirus.com and got this report:
Scan started at 3/2/2004 10:21:10 AM
Scanning memory...
Scanning boot sectors...
Scanning files...
C:\WINDOWS\Belt.exe - TrojanDownloader:Win32/Stubby.A -> Infected
C:\Documents and Settings\CHARLEE\Local Settings\Temp\Belt.cab->Belt.exe - TrojanDownloader:Win32/Stubby.A -> Infected
C:\Documents and Settings\CHARLEE\Local Settings\Temp\Belt.exe - TrojanDownloader:Win32/Stubby.A -> Infected
C:\System Volume Information\_restore{AB147568-89BC-431B-91BE-5A426DCE2681}\RP417\A0037232.exe - Backdoor:Win32/Ruledor.B -> InfectedScanned
============================
Objects: 86009
Directories: 6217
Archives: 1868
Size(Kb): 824348
Infected files: 4Found
============================
Viruses found: 2
Suspicious files: 0
Disinfected files: 0
Mail files: 149I scanned using AdAware & Spybot and they found a trainload of undesirables. I also ran Hijack This and have saved all the logs. I'm hesitant to post them - they're huge. Would truly appreciate some assistance & guidance in getting these creepy-crawlies off my machine. Thanks very much!
Charlee

Empty your temp internet files and off line content and turn off "system restore"(My Computer>Properties>System Restore) and then restart your computer and enter the "safe mode". Run McAfee's scan while you are in the "safe mode". If the system is clean restart the computer and then turn "system restore" back on. Of your harddrive is 30G or larger I would suggest you set the slider to 4-5% instead of the default 12% to save drive space. Take care and all the best!

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |