Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hi all, I am so confused, and I need help!
I came home from vacation to find my email full of mostly the same email (600 or so) from lots of people, some of whom I know -- they all has subjects such as "Your application" "Wicked screensaver" "Details" etc. I wasn't sure if I had accidentally opened a bad one before I left or if these were all just the result of other people's viruses. Though I did get a couple of bounceback emails telling me that mail I tried to send looked suspicious, or like the Sobig F, I guess.
I scanned my pc for the Sobig F virus, which it said I did not have. Then I scanned my pc with housecall. But housecall only found an "uncleanable" TROJ KATIEN.A.
I followed its instructions to delete it manually through my registry, but didn't find the _restore file it said was corrupted. (the restore file, actually, said it was created at the end of July, which seemed weird to me, less recent than I would have thought) And then, however I did find a file in the registry that was BAD that I had dl'd a while back that threw my pc into a fritz...and deleted that.
I scanned with housecall again and it still says I have the trojan....
So I'm wondering a couple things.....1--is it safe to just delete C:\_restore file (I guess to do that I would have to start in DOS/safe mode) and 2--is this trojan related at all to the email virus I think I have? And if not, why can't house call detect it?
Thanks so much....any help is very very very much appreciated....otherwise I'm thinking I should just burn lots of data cd's and say bye bye to my pc :(

If the Trojan or other bug is in the RESTORE FOLDER.... Disable the RESTORE FOLDER, shut down the PC for 2 mins, re-start and re-enable SYSTEM RESTORE. You will lose all the RESTORE points but you will be Trojan free.....
http://www.computing.net/security/wwwboard/forum/5045.html
Response Number 1

The Trojan was probably calling out to the Internet to give out your personal details.... E-mail address, Passwords, Internet banking details... the list goes on.
If you had a firewall (a prog that allows you to control what is sent from your PC), you may have been warned that a bug on your PC wants Internet connection. I get this EVERYTIME I use Adobe Acrobat Reader !
A good free firewall is Zonealarm from....
www.zonelabs.com
TROJ KATIEN.A details from Symantec...http://securityresponse.symantec.com/avcenter/venc/data/troj.polyglot.html

Ok, well I had seen that post about disabling the Restore altogether, and the file that was supposedly infected did disappear....so I'm running yet another scan :-P
I'd checked out the details on the Trojan from Symantec too, not that I understand much of it really, but thanks :)
I guess the only thing that worries me now is the possibility of this email virus....and where is it, what is it, and why aren't any of these scans detecting it? In the meantime, I don't think any of my other actual emails are getting through :( Help?

hello,
I know a good trojan clean tool:
Website: http://www.isecsoft.com/eng
download url: http://www.isecsoft.com/eng/dl.asp
All the best :-)

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |