Trojan horse dialer.17.E removal help

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by s_croxford, Aug 2, 2005.

  1. s_croxford

    s_croxford Private E-2

    Hi there
    I recentley discovered this lovely dialer on a customers comp and promtley ran a virus scan to remove it, but the virus scanner could not remove it (avg6) so i tryed to install avg7 wich failed along with mcaffe norton and all the otheres i have here at work.
    i have tryed all the suggestions on the other posts but all of them come back with the same answer (this file is in use and cannot be removed) i have removed all links to it in startup and registery and even made a dos boot disk and tryed removing it from there to be told "cannot delete access is denied"

    Anyone got any ideas before i throw this laptop out of the window

    cheers :eek:
     
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    Lots and lots of possibilities. Did you run our tutorial? Theres a good chance its locked in system restore, have you disabled it for example? Are you scanning from there in safe mode. These are the 2 big things. Make sure you covered those 2 bases. If successful deleting it, I would scan with Hijack This from safe mode and remove any related entries before rebooting.

    Ewido may be of help:
    http://majorgeeks.com/Ewido_security_suite_d4677.html

    Once removed you may lose internet, if so:
    http://www.majorgeeks.com/download4372.html
     
  3. s_croxford

    s_croxford Private E-2

    yea i have disabled system restore, and i did try running multiple programs in safe mode to remove it all with the same result.
    thanks for the ideas
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    [​IMG] Download HijackThis 1.99.1

    [​IMG] Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    [​IMG] Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    [​IMG]Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    [​IMG]Run HijackThis and save your log file.

    [​IMG] Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    [​IMG]Need help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  5. s_croxford

    s_croxford Private E-2

    Finally got it fixed cheers for the help guys, had to download a few other programs that hijackthis sugested wich worked after a few attempts.
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Feel free to attach a HJT log to confirm your clean. In the meantime I recommend your following this thread on How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds