PDA

View Full Version : Win32:trojan-gen


Dr.MAD
03-16-2004, 04:02 AM
I have a trojan horse on my HDD. I don't know how I got it (I guess I should have uninstalled CrapZaa a long time ago), but the point is, I have one.
It's named Win32:trojan.gen and the files that seem to be infected are all located in a folder named "updater" (C:/Program Files/Common Files/updater) named

delupdat.exe
sui.exe
wupdater.exe
and also the file C:/WINNT/system32/fcs.exe

I quarantained them, but I don't know if I can remove the infected files without messing things up. Anyone knows how to help me?
Thanks

NorthViking
03-16-2004, 04:36 AM
You should be able to get rid of wupdater.exe, sui.exe, delupdat.exe (adware files) with this link http://www.kephyr.com/spywarescanner/library/keenvalue.updater/index.phtml

I'm not sure about fcs.exe, leave it for now.

If some files can't be deleted then disable System Restore http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
And restart, then run antivirus program again or delete.

Here is a trojan remover you might want to try
http://www.simplysup.com/tremover/details.html

HTH :)

Necrosaro420
03-16-2004, 08:06 AM
I have a trojan horse on my HDD.

How in the hell did you fit a horse onto your hard drive?!?!?!

NorthViking
03-16-2004, 08:12 AM
Okay that was a joke right, Necrosaro ??

Necrosaro420
03-16-2004, 08:14 AM
tryed for it to be, shrug heheeh

Dr.MAD
03-16-2004, 09:55 AM
HA HA HA. Stop! I'm dying! :rolleyes:

NorthViking
03-17-2004, 03:13 AM
Mmmhmm Spy, did you check my reply and tried any solution ???

Dr.MAD
03-17-2004, 09:41 AM
Yeh, I got rid of the updater stuff. Those are fine. But no Trojan remover could handle the other one :(
Thx for your reply, I just need to find out if that fcs.exe file can be deleted :)

poi
03-17-2004, 04:54 PM
http://www.metnet.state.mt.us/__Help/00011425-80000007/008EF459-70E903AC?Templates=Help

http://forum.avast.com/index.php?board=4

Hope these may help.

Dr.MAD
03-18-2004, 04:15 PM
Thanks to both of you :)
Aparently, the system is still fine without the fcs.exe file (your links were helpful Poi)
And NV's links pointed out that the other files were safe to kill.