A Windows XP help forum. PCbanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » PCbanter forum » Microsoft Windows XP » Security and Administration with Windows XP
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

downloader trojan



 
 
Thread Tools Display Modes
  #1  
Old June 28th 06, 09:28 AM posted to microsoft.public.windowsxp.security_admin
external usenet poster
 
Posts: n/a
Default downloader trojan

hi Everybody,

I got my computer infected with a trojan horse, it makes symantec AV pops-up
every second to block a file copied to the windows\system32 floder, named
adl.exe.tmp.

I issued Netstat in the cmd, it shows a session to
("numbers".btnaccess.net), it actually uses explorer.exe to get connected.

I need to know which files are involved in using the explorer. how can I do
that????

anybody got a clue..

Zuhair


--
Zuhair Attya
IT Administrator
Bahrain
Ads
  #2  
Old June 28th 06, 02:42 PM posted to microsoft.public.windowsxp.security_admin
external usenet poster
 
Posts: n/a
Default downloader trojan

Zuhair Attya wrote:

hi Everybody,

I got my computer infected with a trojan horse, it makes symantec AV
pops-up every second to block a file copied to the windows\system32
floder, named adl.exe.tmp.

I issued Netstat in the cmd, it shows a session to
("numbers".btnaccess.net), it actually uses explorer.exe to get
connected.

I need to know which files are involved in using the explorer. how can
I do that????


What you need to do is clean up your computer. Do all the preparatory
work he

http://www.elephantboycomputers.com/...moving_Malware

Then run either Sysclean or David Lipman's Multi_AV:

http://www.elephantboycomputers.com/...icros_Sysclean
http://www.ik-cs.com/multi-av.htm - how to use Dave Lipman's Multi-AV
http://www.ik-cs.com/programs/virtools/Multi_AV.exe - Multi-AV download
http://pcdid.com/Multi_AV.htm - additional Multi_AV instructions

Continue with the general malware removal steps from the first link,
including running Ewido. Make sure you do all the finishing up, too.

If the procedures look too complex - and there is no shame in admitting
this isn't your cup of tea - take the machine to a professional
computer repair shop (not your local version of BigStoreUSA).

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
explorer only works if I rename it Dave Sell General XP issues or comments 7 June 3rd 05 01:33 PM
Trojan Horse Downloader : Dyfoca.2.BA inflected - need help 123 General XP issues or comments 1 April 11th 05 03:49 PM
Trojan Horse Downloader : Dyfica.2.BA inflected - need help 123 General XP issues or comments 1 April 11th 05 03:44 PM
trojan horse downloader agent.ac Jason B Security and Administration with Windows XP 7 July 29th 04 10:14 AM
Trojan Horse Downloader Lance Cook Security and Administration with Windows XP 1 July 25th 04 05:30 AM






All times are GMT +1. The time now is 01:16 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 PCbanter.
The comments are property of their posters.