Help ! Virus or Trojan Problem

Discussion in 'Software Q&A' started by Hulo, Oct 17, 2004.

Thread Status:
Not open for further replies.
  1. Hulo

    Hulo New Member

    Joined:
    Sep 13, 2004
    Messages:
    52
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Kolkata, India
    There is a file being created in my computer named ec5d8aef.exe . This is created under Documents and Settings - My user folder - temp . Registry entries are being created to load the file at the start and the file is being shown as a process after I press ctrl+alt+del. I removed the process, deleted the file from the temp folder and removed entries from registry. I ran Ad aware and Spybot S&D. The file keeps coming back after some time. The file also tries to connect thru the net and only because I have installed Zonealarm, it cannot do so. The Zonealarm log shows its repeatedly trying to connect.

    How do I remove this for good? It appears that this file is being created by some other trojan or virus but I can't find that out.
     
  2. klinux

    klinux New Member

    Joined:
    Sep 25, 2004
    Messages:
    625
    Likes Received:
    0
    Trophy Points:
    0
    - flush all the temp directories for all users
    - run updated antivirus for all files , might be another file with different name creating this one
    - update the scan engine for the antivirus program too .
    - check all programs > startup
    - check msconfig > startup
    - try safe mode to delete the file next time it appears
     
  3. it_waaznt_me

    it_waaznt_me Coming back to life ..

    Joined:
    Nov 30, 2003
    Messages:
    2,023
    Likes Received:
    10
    Trophy Points:
    38
    Location:
    A bit closer to heaven
  4. sidewinder

    sidewinder New Member

    Joined:
    Jul 24, 2004
    Messages:
    628
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    West Bengal
    If u use spybot then with it's advance option startup organizer remove all unrecognised startup prog.Then under services.msc search for a process that is linked to that infected file.Now run the computer is safe mode and run a av that is capable of running in safe mode such as avg ao antivir with updated definitions.I m not sure nav can run in safe mode.....
     
Thread Status:
Not open for further replies.

Share This Page