From: <(E-Mail Removed)>
| I am working on Win2K Pro. When I open 'Component Services' (by
| navigating to Control Panel-->Administrative Tools), the name of the
| very first service listed is '01325' (without the quotes). When I
| double-click to open its 'Properties' dialog, the 'Path to executable'
| is set to the following (note that the IP address is hypothetical):
|
| \\41.22.13.117\Admin$\eraseme_34124.exe
|
| The anti-virus installed in my PC reports that the file
| 'eraseme_34124.exe' (which resides in C:\WINNT) is actually a trojan.
|
| Now I connect to the Internet using LAN & the IP address used to
| connect to the Net is exactly the same as above i.e. 41.22.13.117. Does
| this mean that the trojan is making its way through the LAN network
| connection?
|
| Also I don't connect to the Net using the ISP's server directly. The
| ISP's server connects to another server (which is in the neighbourhood)
| & this neighbourhood server, in turn, connects to different computers
| in my area using LAN cables. Does this necessarily mean that the
| neighbourhood server (which connects to my PC using LAN cables) is also
| infected with the above mentioned trojan?
|
| Moreover, how do I delete this service named '01325' from Component
| Services?
You have a badly infected computer. Assistance was attempted and you abandoned that thread
and here you are with a new thread.
Please wipe the computer and re-install the OS from scratch !
--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm