Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Upon running AVG, I have been alerted to a trojanhorse downloader. The name of the virus is Turown.H Can anyone explain how to get rid of this?
The file it is in, is, C:\Windows\Temp\ABCE246Exe:\Files\IEDriver.exe
I have had some trouble with IE recently, and did go into settings, Control Panel, add/remove and did a repair of the IE. What more can I do?
Thank you for any help,
Trish

Hi Trish59,
That's Cydoor (Urlblaze) spyware.. Install and run Ad-Aware to remove it:Download the latest version of Ad-Aware at http://www.lavasoftusa.com/support/download/
After installing AAW, and before running the program, FIRST update the reference file following these instructions.
http://www.lavahelp.com/howto/updref/index.html
Now do the following:
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."
Press "Scan Now"
- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:
Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"
Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.
Finally, close Ad-Aware, and reboot.

Hi Tom41,
I should have mentioned and sorry I didn't, I run ad-aware everyday as I do a lot of research online. Ad-aware didn't find it, neither did Spybot or Avast!. But last night, I again was trying to figure this out on my own, and I did finally resolve the problem.
I ran repair options again on IE. Then ran a program called CrapCleaner. What a mess it found!!!!! After rebooting, I no longer had the downloader and when I checked AVG again this morning.... it was gone!
Tom41 thank you so much for the information as I am sure it will help others.
Trish59

Trish:
Before you ran CrapCleaner did you disable your system restore? This my clean-up Me schpiel:
I also run Script Sentry, MRU Blaster, Spyware Blaster and A Squared (once a week or so just to double check).
Dump system restore:http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?Open&src=sec_doc_nam&docid=2001111912274039&nsf=tsgeninfo.nsf&view=docid&dtype=&prod=&ver=&osv=&osv_lvl
General clean-up:Expose Hidden Files:
http://www.xtra.co.nz/help/0,,4155-1916458,00.html
Have you lately dumped your TIF?
(you can set your TIF folders to dump when you close your browser in tools, internet options, advanced tab, check the box for it.)Tools > Intenet Options> General Tab > Delte files > check the box to delete off line content > click ok > delete cookies > click ok.
%TEMP% files:
Dble click My Computer icon on desk top > type %TEMP in the address bar > click enter > delete all you can delete.
Empty recycle bin.
Go to start > Programs > Accessories > System Tools > Run disk clean up, then scan disk, if scan disk tells you there are programs running in the background--ctrl+alt+delete and end-task on everything except sytray and explorer, the run scan disk > then defragmenter.
Read this yet?:
Me set up page, Trev:
http://www.burzurq.com/forum/trevtweak.html
use these in order:Trojan Hunter trial version:
http://www.misec.net/
Trojan Scan:
http://www.windowsecurity.com/trojanscan/SWATIT:
http://swatit.org/download.html
If you are getting trojans wither do not have a firewall or your settings need to be adjusted--if you want a great free service, I use:
Free Sygate firewall:
http://smb.sygate.com/products/spf_standard.htm
Diagnostics:
Jason’s Browser Security Test:
http://www.jasons-toolbox.com/BrowserSecurity/
Gibson tests:
http://www.grc.com/default.htm
I use LeakTest, DCOMbobulator, ShieldsUp, and UnplugNpray
Thresher

![]() |
Sharing printer wirelessl...
|
Help with MSN Messenger
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |