Hi fellas
How can i remove this trojan forever
im using avast 4.5 home and all updates installed
Plz help me
thanks
Hi fellas
How can i remove this trojan forever
im using avast 4.5 home and all updates installed
Plz help me
thanks
Click on the link in my signature and visit the malware removal section.
Thanks bro !
I installed spybot and some shit was founded
I think my download acellerator was infected, than i remove him
Now i think im clean
thanks
Man the trojan is back !
I cant remove or do nothing with the avast
and the spybot dont detect this one
i installed the Spyware Blaster
But this shit is returning
what more can i do ?
thanks
Do as I suggested that will remove it. And be carefull with what websites you visit, what you download/install etc.
Excuse me for jumping into your post, but I got the same trojan today when trying to download lyrics to a song. A Macromedia window appeared and stated I could not see the site unless I clicked yes. Although something stuck in my mind that it wasn’t right about the box, I clicked yes, it started to download, I got panicky and tried to stop it. Avast 4.5 made a warning noise and immediately put a box up on my screen telling me of this virus and recommended moving it to Virus chest. [ Brilliant catch by Avast - really impressed 8) ]
Closed browser, disabled system restore, ran Avast in boot time scan, chose 1. delete [my isp said that the C:\temp.. files were not vital so could use delete in this instance.]
Ran Adaware = found 4X BlazeFind malware in RegKey[2], RegValue[1], + file in C:\Windows\System32\ide21201.vxd. Got Adaware to delete the regkey and regvalue ones and chose to run spybot to fix the ide21201.vxd file which it did. Re-ran Adaware, Spybot, Avast again and all came up clean.
Now can I go into the Virus Chest and delete the trojan that appears to still be in the chest even though Avast deleted it in boot time, and came up clean when I ran it again?
It says this will delete it irreversibly, ie. not removed to recycle bin.
PS:Adaware also found 3x WindUpdates malware [data miners, TAC8].
Do go on a bit don’t I? sorry.
Yes, you can delete from Chest.
But, if you’re not sure that it was a malware, wait few days to do it.
It won’t harm in anyway if it’s on the Chest
Thanks for the prompt reply Technical
My computer is functioning ok. Will leave it in the chest for the moment as I don’t feel threatened by it.
I’m living proof that it is the User’s actions, more than the OS, which gives you more grief. My first virus! :-[
I keep getting the above virus. At 10:37 every night, avast goes off saying that it is infected with the file. I’ve tried deleting it, says its not valid, try moving to the chest, says its not valid. Tried running all those programs listed on your site Eddy last night, and it came up proptly at 10:37 again tonight. Tried running in safemode tonight and running avast from there, so i guess i’ll find out at 10:37 tomorrow if it really got rid of it… I’m just about to just wipe the whole system and start over. this is the first virus I have ever received, and of course its on my 2 week old brand new computer Any other suggestions? I’ve ran every possible program, avast, antivirus, all those on Eddy’s site, ad-aware, lavasoft’s program. Nothing will get rid of the Ncasepackage.
Have you run HiJackThis and used the log file analyser from Eddy’s site? I strongly doubt it, HiJackThis is the best tool for removing items in the registry and this sounds like something is kicking this off (running at 10:37) and that is likely to be a registry entry.
Have you tried scheduling a boot-time scan?
Did you try finding ncase removal tools/advice using google? This is just one of many I found http://www.pchell.com/support/ncase.shtml, google is your friend learn to use the tools. Would you care to guess what they are doing to remove this, yes, editing the registry. This is what HiJackThis does without you having to do it manually!
Have you disabled system restore before running the applications?
If you follow the instructions on my website, it will be gone. And it won’t come back unless you make a mistake. eg by visiting a bad website, install a with malware infected application or such.
Yes, I did run Hijack, but i couldn’t understand anything it was displaying. After I got the virus again last night i turned off the system restore, so it probably won’t fix that until tonight when it goes off again and i try to get rid of it. Thing i dont understand is I can’t delete/repair/move to chest via avast.
Thing i dont understand is I can't delete/repair/move to chest via avast.Yes you can, but you must disable the harmfull process first.
Have you tried an online virus scan?
Go here for a Trend micro online scan: http://housecall.trendmicro.com/housecall/start_corp.asp
Also, have you tried deleting youe temp files? that might help
Try reboot into safe mode command prompt/ or dos… depending on your os.
From command prompt type “del c:\temp*.*” no quotes. press enter!
Reboot into Windows and delete your I.E cache then try a full scan, (or alternative browser’s cache)
If you are using M.E. XP, disable system restore first, as posted above.
I have deleted the temp folder, many times. The Trend micro found where it was hiding, i deleted that folder. I’m going to re-run in safe mode again and delete the temp folder from there. I disabled system restore as well. So once this Trend Micro is done scanning, i’ll restart in safemode, delete the temp folder in CP, reboot and delete the cache and scan again. crosses fingers Whenever i have run avast after the virus went off, it scanned clean even though it was not repaired/deleted/moved to the chest. We shall see tomorrow at 10:37pm
Bleh ya know, as much problems as this is causing me, i am sure it will be much easier to wipe it. I have had this system for 2 weeks, and i have all of two programs installed on it that I use, Everquest 2 and Teamspeak. Heh. It just figures, i have never got a virus in my entire span of using computers, and i get my brand spanking new one and there we go I really appreciate your guys’ help, but i figure it will be much easier and less stressful to just wipe it since i have nothing much on the computer in the first place.
Ok, if you want that, but be sure to install, since from beginning and before browsing or downloading emails the necessary protection: windows updates, antivirus, antispy, script blocker and firewall
WindowsUpdates and/or Firewall MUST be Applied OFFLINE/before EVER connecting to the inet
otherwise, you’d very likely be infected via an Network/inet-Worm within the first half hour after going online (even if you DON’T browse or read Email)
I assume you have XP ?
so get the full Installer for Servicepack2 (280MB)
I cant access your link…
I have this same problem! I dont know how to get rid of it.