Solved

Trojan horse Downloader effect in win\system32...

Posted on 2004-10-16
5
481 Views
Last Modified: 2008-02-01
hi ,
     i have scanned my system through AVG anti-virus and find out that 3 virusus can't  be deleted by antivirus.so i getting warning everytime when i start the system that AVG found the virusus as follows:

Testing C:\WINDOWS\system32 serial F0DE-8D32
C:\WINDOWS\SYSTEM32\SNCNTR.EXE Trojan horse Downloader.Dluca.AR
C:\WINDOWS\SYSTEM32\SP2CTR.EXE Trojan horse Downloader.Dluca.AM
C:\WINDOWS\SYSTEM32\YSLUX.EXE Trojan horse Downloader.Purityscan.M
 anyone can help me how to rid out these files from m system......is  any other software i hav to use?
0
Comment
Question by:lesmydad
  • 3
  • 2
5 Comments
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 250 total points
Comment Utility
Hello lesmydad =)

run the scan in Safemode and also try to manually delete those three files if u can find them lying in C:\Windows\System32 folder !!
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
Comment Utility
How to get into safemode >> http://www.computerhope.com/issues/chsafe.htm

You can also run Run Stinger in Safemode ==> http://vil.nai.com/vil/stinger
and dont forget to run the Disk Cleanup on ur hard drive in order to delete all those extra junk temp files and also the temp internet files of IE !!

Good Luck :)
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
Comment Utility
and if u are good at manual editing the registry, then here are some Good instructions on the Removal of this trojan >> http://securityresponse.symantec.com/avcenter/venc/data/downloader.dluca.html

Post back if u still face problems :)
0
 
LVL 17

Expert Comment

by:Lobo042399
Comment Utility
Hi lesmydad,

As you can see from the linked Symantec page that Shehar posted, removal of Dluca involves installation of Norton AV. You can download a 30-day trial version of Norton from:

http://nct.symantecstore.com/0142/NAV_2005_trialware.html

Remember to disable System Restore when doing the removal.

To get rid of PurityScan all you need to do is download Spybot Search & Destroy. PurityScan is adware and it's been included in Spybot's reference file since September '03. To maximize protection, run the Update on Spybot before scanning your machine.

That should take care of your problem. Good Vibes!

Lobo
0
 
LVL 17

Expert Comment

by:Lobo042399
Comment Utility
OOps!   I forgot. You can download Spybot S&D from:

http://www.gatesofdelirium.com/ee/tools/

Don't forget to run the Update after installation.

Good Vibes!

Lobo
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Change your password...do it now!. Probably the easiest point of access to your account is through guessing your password. If your password is guessable, do change it now. If not for your sake but for everyone else in your friends list. Remember …
PREFACE The purpose of this guide is to provide information to successfully add specific IIS 7.0 role services for the Symantec Endpoint Protection Manager (SEPM) to function properly when installed on Windows 2008. AUDIENCE Information Technol…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

5 Experts available now in Live!

Get 1:1 Help Now