Computing.Net > Forums > Security and Virus > Trojan Horse

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Trojan Horse

Reply to Message Icon

Name: tootricky
Date: October 28, 2004 at 01:20:40 Pacific
OS: Windows XP
CPU/Ram: Celeron 2.66GHz 504MB Ram
Comment:

I have a Trojan Horse Dialer.11.BU in my C:\WINDOWS\system32\saristar.dll file. I have tried AVG which will not allow me to vault the file and I have also tried TrojanHunter which does not detect the trojan at all.
It then came up and said that the trojan was in the C:\DOCUMEN~1\ANDREW~1\Temp\Z6ihr4.exe file.
Sorry if I have given the wrong system information however I am trying to rid this from a close friends PC and am not sure of their full system details.

Hope I have enough info for some help.

PLEASE



Sponsored Link
Ads by Google

Response Number 1
Name: Mechanix2Go
Date: October 28, 2004 at 01:59:11 Pacific
Reply:

Hi Tracey,

If you cannot delete the files with windows running, boot in DOS and delete them.

M2


0

Response Number 2
Name: Thresher
Date: October 29, 2004 at 20:16:06 Pacific
Reply:

Trojans hide in the system restore files. If your friend has either Win nme or Xp, there are system restore files. Disable them and leave them like that until the bug is gone.

It would help to know what OS your friend's system is, but here is something to do whatever the OS:

Use these in order, in safe mode along with running the AV in safe mode:

Trojan Hunter trial version:
http://www.misec.net/

Trojan Scan:
http://www.windowsecurity.com/trojanscan/

SWATIT:
http://swatit.org/download.html

reboot, back into safe mode:
Tools > Intenet Options> General Tab > Delte files > check the box to delete off line content > click ok > delete cookies > click ok.
%TEMP% files:
Dble click My Computer icon on desk top > type %TEMP in the address bar > click enter > delete all you can delete.

Empty recycle bin.

Go to start > Programs > Accessories > System Tools > Run disk clean up, then scan disk, if scan disk tells you there are programs running in the background--ctrl+alt+delete and end-task on everything except sytray and explorer, the run scan disk > then defragmenter.

Is your friend running either Spybot or Adaware? If not, consider downloading, updating and running them on a regular basis. They both update regularly (every weeek or less), so keep them updated or they are not effective.

Thresher


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Trojan Horse

trojan horse optix www.computing.net/answers/security/trojan-horse-optix/583.html

NetBus Trojan Horse www.computing.net/answers/security/netbus-trojan-horse/13653.html

Trojan horse BHO.BHJ removal www.computing.net/answers/security/trojan-horse-bhobhj-removal/21691.html