BAT/Delsys.trojan removal tool?

Discussion in 'Software' started by NICK ADSL UK, Feb 6, 2004.

  1. NICK ADSL UK

    NICK ADSL UK MajorGeeks Forum Administrator Staff Member

    elle
    Private E-2 Join Date: Feb 2004
    Posts: 1

    BAT/Delsys.trojan removal tool?

    --------------------------------------------------------------------------------



    Hi,

    Does anyone know of a removal tool for a BAT/Delsys.trojan? I have tried several different things - e.g. F-Secure antivirus, Simply Super software trojan remover, Spyware remover but nothing has worked so far. I think this is a very old trojan, I read somewhere it was around in 2001. Perhaps the antivirus software is too up to date.

    I would really appreciate it if anyone could help. The operating system being used on the computer that has it is Windows 2000.

    Elle
     
  2. alanc

    alanc MajorGeek

  3. elle

    elle Private E-2

    The trojan scan you suggested did not manage to remove it and I cannot manually delete it because it is in a folder called System Volume Information on C drive which can't be traced for some reason.

    The F-Secure virus scan which is currently being used on the computer just keeps finding the virus but is unable to do anything with it.

    The worrying thing is the computer totally crashed the other day. It was impossible to boot up, even in safe mode. Eventually we had to reinstall the o/s - pretty drastic. The virus scan is still picking up the trojan (not sure whether this is because the old o/s is still there). I'm not sure whether the computer dying was due to the virus, but there are about 3 others on our network with the same thing and I don't want it to happen to them as well!
     
  4. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    System Vol Info is I know part of System Restore on XP but I didnt know W2K had System Restore ( well you learn something new every day ) the reason you cannot get access to it is its a protected system file BUT if you are Admin you can add yourself to the users that can access that file.



    To access the System Vol Info folder...........

    Goto tools > Folder Options > View and click show hidden files & folders also unclick Hide protected operating system files > Apply

    then goto the C: drive and the System Vol Info folder should have appeared right click it and pick properties then click the security tab ( if its not showing then you will need to go back to Tools > Folder Options > View and un-tick Use simple file sharing ) next click add > Advanced > Find now > Pick your user name off the list and click OK > OK > Apply and you will have access to that folder.


    As to what to delete... well I'm not at work so have no access to a W2K machine only a XP one... where Disabling System Restore dumps the contects of that folder.




    Being on a network I suspect that all the PCs are infestated with this trojan so all will need treatment together to remove the trojan.


    Trends online scanner will detect and remove this...

    Info
    http://www.trendmicro.com/vinfo/vir...m=q&virus=Bat.Delsys.Trojan&alt=Delsys.Trojan

    Online Scan
    http://housecall.trendmicro.com/
     
  5. elle

    elle Private E-2

    Well I have found the file that was flagged by F-Secure which is called

    C:\System Volume Information\restore{7E5A22D2-C464-4478-B81A-7D6C14BB79E3}\RP1\A0001100.CMD

    but I don't know whether this is the infection or whether this is just the infected file. ie Is this file important or can I just delete the whole thing?
     
  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Shouldnt be a problem deleting the RP1 ( Restore Point ) it just means that if you have a problem you cannot go back in time to a point when things where ok... but in your case you have a virus/trojan at that point.

    unless you remove it it will keep comming back.. this is the only negative side of System Restore points they hold the nastys as well as the good backup info.

    As you are on network this will need to be done to all machines as the infection will keep on getting passed around if not.. good Idea is to do further AV scans just to make sure.


    I just been looking at the size of my Sys Vol Info folder 750mb OMG! needs clearing I guess.
     
  7. alanc

    alanc MajorGeek

    Actually Win2k normally doesn't have System Restore, can it be installed from the Resource Kit, perhaps? Are you sure this is 2k, not XP? :confused:
     
  8. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member


    Yeah me too Alan but elle seems to be in the right area for System Restore, we just have to wait for the reply to see if the trojan is no more *finger crossed*
     
  9. elle

    elle Private E-2

    I managed to get rid of the trojan on all the computers!!!!! Thanks for all your advice. :cool:

    PS It is W2k being run on the computers.

    Thanks again!
     
  10. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Great NEWS elle :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds