Re: Trojan in Win.32 driver folder

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 02/01/05


Date: Mon, 31 Jan 2005 22:34:03 -0500

There are anti virus News Groups specifically for this type of discussion.

microsoft.public.scripting.virus.discussion
microsoft.public.security.virus
alt.comp.virus
alt.comp.anti-virus

1) Download the following three items...

         Trend Sysclean Package
         http://www.trendmicro.com/download/dcs.asp

         Latest Trend Pattern File.
         http://www.trendmicro.com/download/pattern.asp

         Adaware SE (free personal version v1.05)
         http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download Sysclean.com and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt385.zip

Extract the contents of the ZIP file and place the contents in the same directory as
sysclean.com.

2) Update Adaware with the latest definitions.
3) Disable System Restore
        http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode and shutdown as many applications as possible
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
        platform and clean/delete any infectors/parasites found.
        (a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
        Trend Sysclean utility and Adaware
7) Re-enable System Restore and re-apply any System Restore preferences,
        (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) Create a new Restore point

* * * Please report your results ! * * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
"Crystal" <Crystal@discussions.microsoft.com> wrote in message
news:CE67F2B0-5FD3-4468-96B6-C61AA3D8EA6E@microsoft.com...
| This trojan is called
| Win32.Benuti.K!downloader
|
| This is where the virus is loacated
| C:\WINDOWS\system32\drivers\
|
|
| This is the file name That is located on my C drive.
| bqjguhld.sys
|
| My anti virus does not find this when it dose a scan.  It only finds it in
| real time when I click on Internet explorer to go on line.  My anti virus
| pops up a window giving me all the information and says it has deleted it.
| It freezes up my IE and I have one heck of a time accessing my browser.  When
| I go into windows explorer to delete the file it's not there but each time I
| go to access my IE it is back again.
|
| Someone please help me.  I am a full time student and I have 2 on line
| classes that I can't access right now.
|
| Thank you so much,
| Crystal
|


Relevant Pages

  • Re: Do I have TOO MANY antivirus, antispyware, etc
    ... My NAV updates auto & runs a complete scan once a day. ... The only firewall I have is whatever my Linksys router provides for my ... > There are anti virus News Groups specifically for this type of discussion. ... > FireWall to allow it to download the needed AV vendor related files. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Do I have TOO MANY antivirus, antispyware, etc
    ... There are anti virus News Groups specifically for this type of discussion. ... FireWall to allow it to download the needed AV vendor related files. ... This will bring up the initial menu of choices and should be executed in Normal Mode. ... It is suggested to run the scanners in both Safe Mode and Normal Mode. ...
    (microsoft.public.windowsxp.security_admin)
  • >>>> AVG DOWNLOAD <<<<
    ... 100 free avg antivirus software downloads, 7.0 avg free downloads, 7.5 ... avg free download, all versions avg free download, anti avg cnet ... virus brontok avg download, anti virus download avg, anti virus ...
    (sci.geo.meteorology)
  • Re: Virus Scans Freezing
    ... | In Spybot, I've followed the path, and gone into the "hosts" file, but it asks what I want ... The following "is" anti virus software. ... You can choose to go to each menu item and just download the needed files or you can ... It is suggested to run the scanners in both Safe Mode and Normal Mode. ...
    (alt.comp.anti-virus)
  • Re: Virus Scans Freezing
    ... > | In Spybot, I've followed the path, and gone into the "hosts" file, but it asks what I want ... > The following "is" anti virus software. ... > download the files and perform a scan in Normal Mode. ... It is suggested to run the scanners in both Safe Mode and Normal Mode. ...
    (alt.comp.anti-virus)