Name: zalwa Date: December 31, 2007 at 11:28:48 Pacific Subject: Trojan in cscu.dll - delete file OS: XP CPU/Ram: Core2Duo
Comment:
I've got a Trojan in my Computer I cannot get rid of: Trojan PSW.Generic5.UWD in cscu.dll file. I've been trying to remove it with several software witout any result included Spybot and ad-aware. Since I know which file that contains the trojan it should be enough deleting the file. However I cannot delete the file (Error: file cannot be deleted, running or pretected) so the question is: Is there is a way I can delete the file. Thank you.
There are some good progs to delete the file: Move on boot Dr Delete Unlocker You'll have to google for those. Probably Dr Delete will be the best to work for you and they are all free progs. Good Luck
Please download and install the latest version of HijackThis v2.0.2:
Download the "HijackThis" Installer from this link: Hijack This
1. Save " HJTInstall.exe" to your desktop. 2. Double click on HJTInstall.exe to run the program. 3. By default it will install to C:\Program Files\Trend Micro\HijackThis. 4. Accept the license agreement by clicking the "I Accept" button. 5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log. 6. Click "Save log" to save the log file and then the log will open in Notepad. 7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. 8. Paste the log in your next reply. 9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
Thanks so far, my Hijakt This log looks like this: -------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:33:50, on 2008-01-01 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal
Then extract the contents to your desktop. !!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!
Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd" Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
The information on Computing.Net is the opinions of its users. Such
opinions may not be accurate and they are to be used at your own risk.
Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE