DUN Settings keep changing after a virus attack

Posted on 2004-04-19
Last Modified: 2010-04-11
I have just cleaned up virus Trojan.ByteVerify from a client after a great deal of digging and rebooted. Subsequent scans using Norton show no virus. However, his DUN Settings keep replicating and replacing the proper number/login with a premium rate one. The Original one then appears as _OLD

How do I find and kill the payload the virus has left behind? I am planning to run a spyware killer as well as soon as I get back to his desk.

I'm no expert on Windows 2000 SP4 so any help would be good.
Question by:asparak
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2

Accepted Solution

makana earned 125 total points
ID: 10866802
This is very simple and easy. Forget Norton(!). Run any online scan:
download this CWshredder and Run it. Update it regularly.

A+ MCP Cisco Acad Sem-1

Author Comment

ID: 10867573
Ran Ad-Aware and it picked it up. The payload of the variant G Trojan seems to be coulomb Dialer

Expert Comment

ID: 10871599
Thank you very much ! I hope my suggestions helped you.

A+ MCP Cisco Acad Sem-1

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Join Greg Farro and Ethan Banks from Packet Pushers ( and Greg Ross from Paessler ( for a discussion about smart network …
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…
Suggested Courses
Course of the Month11 days, 1 hour left to enroll

631 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question