| View previous topic :: View next topic |
| Author |
Message |
Liscombe
Cadet

 Joined: Jul 11, 2004 Posts: 2 Location: Canada
|
Posted: Sun Jul 11, 2004 11:04 pm Post subject: Trojan horse Downloader.Istbar.4.G |
|
|
How do I get rid of Trojan horse Downloader.Istbar.4.G. AVG says it is located in C:\WINDOWS\Downloaded Program Files\IST activex.dll. I have searched for that file and cannot find it. I also have Trojan horse Downloader.Istbar.4.H that AVG has found in C:\System Volume Information\_restore{8268BFE6-44BD-4B25-BOF7-CE65B3815CC9}\RP64\A0003683.EXE and I cannot find that file also. I am kinda slow at this PC stuff so be easy on me please.
|
|
| Back to top |
|
 |
k027
Special Response Team Guest Forums Host

 Joined: Aug 25, 2003 Posts: 8509
|
Posted: Mon Jul 12, 2004 3:05 am Post subject: |
|
|
Try this:
Remove Trojan horse Downloader.Istbar.4.H this way:
*Close all programs.
*Turn off System Restore
*Run AVG Complete Scan
*Turn on System Restore.
If you can't find Trojan horse Downloader.Istbar.4.G, AVG may have moved it to the Virus Vault. Check the Virus Vault. 
|
|
| Back to top |
|
 |
Liscombe
Cadet

 Joined: Jul 11, 2004 Posts: 2 Location: Canada
|
Posted: Mon Jul 12, 2004 5:08 am Post subject: |
|
|
Thank You very much. It worked. This is a very useful site. Glad I had found it. Thank's again.
|
|
| Back to top |
|
 |
k027
Special Response Team Guest Forums Host

 Joined: Aug 25, 2003 Posts: 8509
|
Posted: Mon Jul 12, 2004 12:48 pm Post subject: |
|
|
Glad we could help! 
|
|
| Back to top |
|
 |
freakyfever
Cadet

 Joined: Jul 15, 2004 Posts: 1 Location: Belgium
|
Posted: Thu Jul 15, 2004 12:08 pm Post subject: |
|
|
hi, how do i turn off system restore????? 
|
|
| Back to top |
|
 |
k027
Special Response Team Guest Forums Host

 Joined: Aug 25, 2003 Posts: 8509
|
Posted: Thu Jul 15, 2004 3:54 pm Post subject: |
|
|
How to disable System Restore
Disabling Windows XP AutoRestore feature
http://www.europe.f-secure.com/v-descs/sfc_dis1.shtml
In Windows Millenium there was a new feature introduced called System Restore. The new Windows XP has this feature. It creates backup copies of the essential system files so they can be restored if they get corrupted. Sometimes this makes disinfection difficult as backup files can get infected and copied to System Restore folder by Windows. Then after disinfection Windows will copy the infected file back over the clean ones.
System Restore feature can be disabled using the following steps:
1. Select Start/My Computer.
2. Click on "View system information".
3. Select the tab "System Restore".
4. Check the "Turn off System Restore on all drives" checkbox and click "Apply" button.
5. The program asks if you want to turn off System Restore. Click "Yes" button.
6. "Drive settings" has now turned to grey. Click "OK" button.
7. Windows XP System Restore feature is now disabled.
The System Restore feature can be enabled again with the same steps. At step 4. you have to uncheck the Turn Off System Restore on All Drives checkbox.
..............................
Disabling System Restore on Windows ME
http://www.europe.f-secure.com/v-descs/sfc_dis.shtml
In Windows Millenium there was a new feature introduced called System Restore. Windows ME creates backup copies of the essential system files so they can be restored if they get corrupted. Sometimes this makes the disinfection difficult since the backup files can get infected. In those cases Windows will copy the infected file in the place of the clean one.
This feature can be disabled with the following steps
1. Right-click on the My Computer icon and select Properties
2. In the System Properties windows select the Performance tab
3. Click on File System... button
4. In the Filesystem Properties window select the Troubleshooting tab
5. Check the Disable System Restore checkbox
6. Click Apply button
7. Close the windows using the Close button
8. Click Yes when prompted for reboot
The System Restore feature can be enabled again with the same steps. At step 5. you have to uncheck the Disable System Restore checkbox.
|
|
| Back to top |
|
 |
KRRCubed
Cadet

 Joined: Jul 15, 2004 Posts: 3 Location: USA
|
Posted: Thu Jul 15, 2004 10:42 pm Post subject: |
|
|
k027, I followed your steps and it found the virus but it can't do anything about it... When I click details, it says virus not found.
I am assuming from reading other posts that this affects Windows Media Player?
Thanks for you help!
*edit* Also, is this related to a process called (named) dafogjo.exe? I keep closing it, but it reopens itself, I believe it is triggered when IE is opened.
|
|
| Back to top |
|
 |
k027
Special Response Team Guest Forums Host

 Joined: Aug 25, 2003 Posts: 8509
|
|
| Back to top |
|
 |
KRRCubed
Cadet

 Joined: Jul 15, 2004 Posts: 3 Location: USA
|
Posted: Sun Jul 18, 2004 3:12 am Post subject: |
|
|
Thanks a lot, I've done as you said, the post can be found here:
/p245261-HiJackThis_Report_from_Trojan_Issues.html#245261
Thanks again!
K3
_______________________________________
NOTE FROM FORUM HOSTS: This thread is now closed. Should you need it reopened, please PM a Host/mod. Everyone else having a similar issue, please launch a new topic for yourselves. Thank you.
|
|
| Back to top |
|
 |
|
|