Link to home
Start Free TrialLog in
Avatar of asparak
asparak

asked on

DUN Settings keep changing after a virus attack

I have just cleaned up virus Trojan.ByteVerify from a client after a great deal of digging and rebooted. Subsequent scans using Norton show no virus. However, his DUN Settings keep replicating and replacing the proper number/login with a premium rate one. The Original one then appears as _OLD

How do I find and kill the payload the virus has left behind? I am planning to run a spyware killer as well as soon as I get back to his desk.

I'm no expert on Windows 2000 SP4 so any help would be good.
ASKER CERTIFIED SOLUTION
Avatar of makana
makana
Flag of Bangladesh image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of asparak
asparak

ASKER

Ran Ad-Aware and it picked it up. The payload of the variant G Trojan seems to be coulomb Dialer
Thank you very much ! I hope my suggestions helped you.

makana
A+ MCP Cisco Acad Sem-1