1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojan help please

Discussion in 'Malware and Virus Removal Archive' started by mdk3, 2005/01/19.

Thread Status:
Not open for further replies.
  1. 2005/01/19
    mdk3

    mdk3 Inactive Thread Starter

    Joined:
    2005/01/19
    Messages:
    1
    Likes Received:
    0
    here is what is going on.

    I ran my virus scan (AVG 7 pro) and it returns a virus located in my temp folder called psw.agent.3.an. my program deletes it but then it reappears. I have manually deleted from my computer in Normal mode, safe mode, and dos. But it reappears everytime. I am running winxp pro sp2. i even have tried to rename the file but then it creates another file that is the original. The file is called yekbil.dat
    also
    I have run hijackthis and have noticed an entry that is *libkey
    that is not usually in the list, but when i try to delete it, it too comes back even in the registry. I have run ad-aware on the computer and it is clean. I even tried The Cleaner program but no luck. I have also turned off System restore, and deleted the _restore directorary

    Any suggestion


    Thank you
     
    mdk3,
    #1
  2. 2005/01/20
    moboking

    moboking Inactive

    Joined:
    2004/12/26
    Messages:
    82
    Likes Received:
    0
    Have you removed any suspicious entries in the Run key in the registry for both HKLM and HKCU? How about in win.ini file? Startup folders?
     
    Last edited: 2005/01/20

  3. to hide this advert.

  4. 2005/01/23
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    In safe mode, delete the contents of all temp folders.
    C:\Temp
    C:\Windows\Temp
    C:\Windows\Prefetch
    C:\Documents and Settings\username\Local Settings\Temp........do this for all usernames.....local settings is a hidden folder, so you will need to show hidden files and folders
    control panel>internet options......delete temporary internet files, including offline content
    control panel>Java Plug-in>cache tab, click clear........if you have Sun Java installed
    Empty the recycle bin

    Reboot to Windows and run Panda ActiveScan. If still infected, post a HijackThis log.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.