Trojan Downloader.Small.6.B

Discussion in 'adware, spyware & hijack cleaning' started by mikesmith, May 24, 2004.

Thread Status:
Not open for further replies.
  1. mikesmith

    mikesmith Registered Member

    Joined:
    May 24, 2004
    Posts:
    1
    I have this virus and AVG seems unable to remove it. It tells me the infected file is in C:\Documents and Settings\Mike\Application Data\UPDATE.EXE but when I click "move to virus vault" I get the message saying it cannot be deleted. I have run Spybot S&D and Hijackthis, can you help me fix it? The log is attached.
     

    Attached Files:

    Last edited: May 24, 2004
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,330
    Location:
    Netherlands
    Hi mikesmith,

    This looks like a combo of files keeping each other alive:
    O4 - HKCU\..\Run: [System Update] c:\winnt\system\update.exe
    O4 - HKCU\..\Run: [System Update2] c:\docume~1\mike\applic~1\update.exe
    O4 - HKCU\..\Run: [System Update4] c:\docume~1\mike\applic~1\system.exe

    Check the items listed above in HijackThis, close all windows except HijackThis and click Fix checked.

    Then reboot into safe mode and delete:
    c:\winnt\system\update.exe
    c:\documents and settings\mike\application data\update.exe
    c:\documents and settings\mike\application data\system.exe

    Get your Windows and IE updated as soon as possible.

    Regards,

    Pieter
     
Thread Status:
Not open for further replies.