Good days everyone,
For the last 3 days I’ve been trying to get rid of this strange “Win32:Trojan-gen. {Delphi}” thing.
The infected files are located under "C:\Documents and Settings\user\Local Settings\Temp"
The infected files don’t have a constant name, except the beginning. The file names’ format is like “~DPxx.dll” The ‘xx’ part is the variable part. Some examples of infected filenames; “~DP24.dll, ~DP24.dll, ~DPF.dll, ~DPD.dll, ~DPB.dll, ~DPC.dll, ~DP10.dll, ~DP11.dll” And the size of the infected file is 55KB.
Also from time to time I find under the same directory some .tmp files. They carry the same filename as the .dll files but just have .tmp extension. And the filesize of these files are always 0KB. I guess that these files are created as I try to delete(and/or repair) the infected .dll file with Avast.
When I try to delete(and/or repair) the file with Avast I just get no results(all files are inaccessible). Avast can’t even access the infected file. So I schedule a boot scan with deepest scan options. Avast deletes the infected file during the boot scan and Windows launches normally. Now at this point there are two possibilities.
- I check the directory and I see that there are no files everything is cool and ok. But after some time(during the same day and actually the next couple of hours) I start getting the same warning from Avast.
- I check the directory and unfortunately see the exact same files in place.
Additionally, I’ve alredy disabled System Restore and as well I’ve tried running a complete scan in Safe Mode… Still I can’t get rid of the virus.
Till now I’ve tried every logical method to get rid of this but unfortunately I still haven’t been successful. Above I’ve explained the situation exactly and described everything I have tried. I hope there is some point I have forgotten about or missed that you people can help me with and the problem will be easily solved.
From my side of view the only way left is to install another antivirus and see what happens. I hope you people will be able solve my problem without the aid of another antivirus.
System information;
OS : Windows XP Professional Edition with SP2 and all critical security updates done.
Antivirus : Latest Avast Home Edition version with all updates done.
Firewall : Sometimes Windows Firewall sometimes NONE
Anti-Spy : SpyBot S&D 1.4 with all updates done
Thanks to all in advance,