Help ! Virus or Trojan Problem

Status
Not open for further replies.

Hulo

Broken In
There is a file being created in my computer named ec5d8aef.exe . This is created under Documents and Settings - My user folder - temp . Registry entries are being created to load the file at the start and the file is being shown as a process after I press ctrl+alt+del. I removed the process, deleted the file from the temp folder and removed entries from registry. I ran Ad aware and Spybot S&D. The file keeps coming back after some time. The file also tries to connect thru the net and only because I have installed Zonealarm, it cannot do so. The Zonealarm log shows its repeatedly trying to connect.

How do I remove this for good? It appears that this file is being created by some other trojan or virus but I can't find that out.
 

klinux

Ambassador of Buzz
- flush all the temp directories for all users
- run updated antivirus for all files , might be another file with different name creating this one
- update the scan engine for the antivirus program too .
- check all programs > startup
- check msconfig > startup
- try safe mode to delete the file next time it appears
 

it_waaznt_me

Coming back to life ..
Scan your system with updated virus definitions:
Panda ActiveScan
Stinger
Symantec System Check
Kaspersky
 

sidewinder

Ambassador of Buzz
If u use spybot then with it's advance option startup organizer remove all unrecognised startup prog.Then under services.msc search for a process that is linked to that infected file.Now run the computer is safe mode and run a av that is capable of running in safe mode such as avg ao antivir with updated definitions.I m not sure nav can run in safe mode.....
 
Status
Not open for further replies.
Top Bottom