Need help with unknown Trojan!
Аўтар тэмы: Rosseon
Rosseon
Rosseon
Local time: 22:58
шведская → англійская
Nov 26, 2004

I'm sorry if this is not the perfect place to post this, but I am desperaqte. I have AVG anti-virus software which detected 5 trojan horses on my laptop and successfully removed 4 of them. The remaing one is still in my WINNT/Systm32 folder and despite searching the net all day so far I'm still at square one. AVG cannot help...so if anyone knows anything about xmorkdvh.exe, which is a Trojan Dialler, I'd be mighty grateful. Please post something or email me asap.

Thanks everyone....
... See more
I'm sorry if this is not the perfect place to post this, but I am desperaqte. I have AVG anti-virus software which detected 5 trojan horses on my laptop and successfully removed 4 of them. The remaing one is still in my WINNT/Systm32 folder and despite searching the net all day so far I'm still at square one. AVG cannot help...so if anyone knows anything about xmorkdvh.exe, which is a Trojan Dialler, I'd be mighty grateful. Please post something or email me asap.

Thanks everyone....


rosseon

[Subject edited by staff or moderator 2004-11-26 14:04]
Collapse


 
Natalie
Natalie  Identity Verified
Польшча
Local time: 23:58
Член (ад 2002)
англійская → руская
+ ...

МАДЭРАТАР
УДЗЕЛЬНІК ЛАКАЛІЗАЦЫІ САЙТА
Moving the topic Nov 26, 2004

to the Safe Computing forum

 
Mathew Robinson
Mathew Robinson
Вялікабрытанія
Local time: 22:58
англійская
Spybot Search & Destroy Nov 26, 2004

Go to http://www.safer-networking.org/en/mirrors/index.html and download Spybot.

The official website for this is www.spybot.info

It's completely free. Download is about 5mb in size, installs in seconds, and finds things missed by NAV, Ad-Aware and The Cleaner.

... See more
Go to http://www.safer-networking.org/en/mirrors/index.html and download Spybot.

The official website for this is www.spybot.info

It's completely free. Download is about 5mb in size, installs in seconds, and finds things missed by NAV, Ad-Aware and The Cleaner.

FYI: If you are using broadband/cable connection, don't panic. These dialler trojans change your modem dialling to use a premium rate number when connecting to the internet (charging extortionate amounts per minute).

[Edited at 2004-11-26 14:48]
Collapse


 
Haris Nasibullin
Haris Nasibullin
Local time: 00:58
англійская → руская
Regrun Nov 26, 2004

There is such a program called Regrun or Regrun Gold. http://www.greatis.com/security/
In case you will not find a remedy you can use this one which does not allow any program to run if you do not allow to do it.

It is not an antivirus as it is. It scan a disk with all the files which try to run, and ask the user what to do.

Sorry if did not help.


 
Schwabamädle
Schwabamädle
Канада
Local time: 17:58
англійская → нямецкая
+ ...
Hi there Nov 26, 2004

hijackthis is also a good option if above should not work.
Try first the above search and destroy as this is easy to follow. With hijackthis you have to really read the instructions carefully.

I once had a huge problem too and I had to get a computer specialist and he told me to write in my webbrowser

http://xxxxxxxx/uninstall2.exe


the name of this virus
... See more
hijackthis is also a good option if above should not work.
Try first the above search and destroy as this is easy to follow. With hijackthis you have to really read the instructions carefully.

I once had a huge problem too and I had to get a computer specialist and he told me to write in my webbrowser

http://xxxxxxxx/uninstall2.exe


the name of this virus (instead of the XXXXXX above). Than a window opend and said do you want to safe or open, than you open regardless of the warning that it could have a malicious code. After another window opens which says uninstall and it you click on that and this bad thing will be history.
you have to know though the exact address of this virus.

http://www.bleepingcomputer.com/forums/index.php?showtutorial=42

Good luck
Andrea
Collapse


 
Evert DELOOF-SYS
Evert DELOOF-SYS  Identity Verified
Бельгія
Local time: 23:58
Член
англійская → галандская
+ ...
Computercops Nov 26, 2004

If any of the above fails, simply repeat your question at
http://computercops.biz/forums.html

Someone over there will certainly help you out.

Very interesting site.


 
Omar Osman
Omar Osman
Local time: 05:58
Член
Самалійская → англійская
+ ...
Try this Nov 27, 2004

Also try disabling your System Restore, run the antivirus, the Antihijack (spyboot, Lavasoft or others) once the Trojan/virus is been removed restart your pc and enable System Restore. In most cases it will solve your problem.
Omar


 


To report site rules violations or get help, contact a site moderator:

Мадэратар(ы) гэтага форума
Maya Gorgoshidze[Call to this topic]
Prachya Mruetusatorn[Call to this topic]

You can also contact site staff by submitting a support request »

Need help with unknown Trojan!






Protemos translation business management system
Create your account in minutes, and start working! 3-month trial for agencies, and free for freelancers!

The system lets you keep client/vendor database, with contacts and rates, manage projects and assign jobs to vendors, issue invoices, track payments, store and manage project files, generate business reports on turnover profit per client/manager etc.

More info »
Trados Business Manager Lite
Create customer quotes and invoices from within Trados Studio

Trados Business Manager Lite helps to simplify and speed up some of the daily tasks, such as invoicing and reporting, associated with running your freelance translation business.

More info »