»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 04-17-2004, 10:33 AM   #1 (permalink)
Registered User
 
Join Date: Oct 2002
Posts: 92
viking12344 is on a distinguished road
Downloader.dyfica.aj and clumbs of my greying hair.

.....being pulled out.


I have a machine that has this damn trojan on it........and its usuually associated with system restore on ME and XP.....problem is, this is a 98 machine and here is what I have tried that does not remove it.

AVG virus
CW shredder
adaware
spybot

Avg will find it but wont be able to remove it.....cwshredder will remove it but on reboot its back.....same with adaware

Please....if anyone knows anything about how I can remove this damned thing, I will give you my first born.

Thank you ,

viking12344 is offline   Reply With Quote
Old 04-17-2004, 11:07 AM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Location: Indiana
Posts: 1,917
elroy is on a distinguished road
There seems to be an abundance of reported problems associated with "downloader.xxx.xxx". My guess it is a spyware type program and will require registry editing to remove it. Several posts have made reference to this same thing recently.

Run a google search on
" remove trojan downloader. "


Last edited by elroy; 04-17-2004 at 11:13 AM.
elroy is offline   Reply With Quote
Old 04-17-2004, 11:23 AM   #3 (permalink)
Registered User
 
nukes's Avatar
 
Join Date: Oct 2002
Location: Scotland, UK
Posts: 2,946
nukes is on a distinguished road
Send a message via AIM to nukes Send a message via Yahoo to nukes
Check the HKLM+CU\Software\microsoft\windows\currentversion\ run, runservices etc keys in the registry. See if there's anything suspect in there.
__________________
_____
NuKeS
nukes is offline   Reply With Quote
Old 04-17-2004, 11:32 AM   #4 (permalink)
Registered User
 
Join Date: Oct 2002
Posts: 92
viking12344 is on a distinguished road
Ok thanks fellas, will try that also......very odd thing here...on the 3rd reboot and avg scan, avg removed the trojan. I really dont understand how it did not the first two times....nothing changed.
viking12344 is offline   Reply With Quote
Old 04-17-2004, 11:57 AM   #5 (permalink)
Registered User
 
nukes's Avatar
 
Join Date: Oct 2002
Location: Scotland, UK
Posts: 2,946
nukes is on a distinguished road
Send a message via AIM to nukes Send a message via Yahoo to nukes
I suspect it was hidden somewhere, inside some dll or something, and was called at boot, causing it to reinstall itself.
__________________
_____
NuKeS
nukes is offline   Reply With Quote
Old 04-17-2004, 12:06 PM   #6 (permalink)
Registered User
 
Join Date: Oct 2003
Location: Texas
Posts: 233
dafanman is on a distinguished road
viking12344,
I just finished doing the exact same thing on a clients machine on thursday

Here is what I did:
Download the latest ad aware and update
Download HIjackthis and run it, that prog works wonders.

In additon delet temp, temp internet, mru's recent, ect....

As i reread your post I see you have resolved the issue, cool!
I would reccomend that if you work on systems you will see this again, many many times, Hijack this is a good tech tool to have.


Laterz,
dafanman
__________________
Gigabyte 7n400pro
Dual Boot XP/ME
HARDM3NU F12 FINAL Bios
*Thanks Preacher*
xp1700axoa dut3c juhhb0302xpmw
11x200=2205.
Albatron Ti4200p 128mb
WD120gb, WD40gb
LiteOn 52x burner
Pioneer 10x dvd
(2) corsair 3200 xms 256@ 11-2-2-2.5
coolermaster hhc-001 heat pipe
650watts of psu 400for sys/ 250 for fans
19" Komodo monitor
Altec Lansing 5.1 speakers
Leadtek tv2000xp tv/fm radio card
Average load temp 52c
dafanman is offline   Reply With Quote
Old 04-17-2004, 12:38 PM   #7 (permalink)
Registered User
 
Join Date: Oct 2002
Posts: 92
viking12344 is on a distinguished road
I never even heard of hijack.....going to find that and d/l it now...thanks for that nugget.
viking12344 is offline   Reply With Quote
Old 04-17-2004, 02:06 PM   #8 (permalink)
Registered User
 
nukes's Avatar
 
Join Date: Oct 2002
Location: Scotland, UK
Posts: 2,946
nukes is on a distinguished road
Send a message via AIM to nukes Send a message via Yahoo to nukes
http://www.spychecker.com/program/hijackthis.html
__________________
_____
NuKeS
nukes is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 06:50 PM.