What is this trojan??How do I get rid of it??

M

MB_

Help.

AVG has identified a file called: Series008.scr as a trojan
"Backdoor.Small.3.AG".

The path goes fairly deep into:c:/documents and setting/myname/local
setting/temp/Temporary Directory 2 for Series008.zip/

What us this??

Is it the type to cause problems?

How can I remove it??

(Should I just try and remove that last directory or just the file or????)

Any advice would be appreciated.

Thanks,

MB
 
D

David H. Lipman

1) Download the following three items...

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp

Adaware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt327.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

2) Update Adaware with the latest definitions.
3) If you are using WinME or WinXP, disable System Restore
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
4) Reboot your PC into Safe Mode and shutdown as many applications as possible.
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
Trend Sysclean utility and Adaware
7) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) If you are using WinME or WinXP, create a new Restore point

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html




| Help.
|
| AVG has identified a file called: Series008.scr as a trojan
| "Backdoor.Small.3.AG".
|
| The path goes fairly deep into:c:/documents and setting/myname/local
| setting/temp/Temporary Directory 2 for Series008.zip/
|
| What us this??
|
| Is it the type to cause problems?
|
| How can I remove it??
|
| (Should I just try and remove that last directory or just the file or????)
|
| Any advice would be appreciated.
|
| Thanks,
|
| MB
|
|
 
B

Beauregard T. Shagnasty

MB_ said:
Help.

AVG has identified a file called: Series008.scr as a trojan
"Backdoor.Small.3.AG".

The path goes fairly deep into:c:/documents and
setting/myname/local setting/temp/Temporary Directory 2 for
Series008.zip/

What us this??

A trojan in a zip file. Generally, an .scr file is masquerading as a
screen saver.
Is it the type to cause problems?

Most assuredly.
How can I remove it??

Delete it.
(Should I just try and remove that last directory or just the file
or????)

I would delete the folder as well. After all, anything in this Temp
directory is .. temporary.

The real question is: where did you download it from?
 
M

MB_

David:

Thanks for the info. I've d/l the Sysclean package and the signature files.
Also, I regularly use Ad-Aware.

AVG indicated that it got rid of the trojans. I ran AVG again and it said
no viruses.

Is this somewhat hopeful that AVG took care of it??

Mel
 
M

Max M.Wachtel III

MB_ said:
David:

Thanks for the info. I've d/l the Sysclean package and the signature files.
Also, I regularly use Ad-Aware.

AVG indicated that it got rid of the trojans. I ran AVG again and it said
no viruses.

Is this somewhat hopeful that AVG took care of it??

Mel
Just a note,I have some good programs listed on my site to help you
"keep it clean"
-max

--
Virus Removal Instructions: http://www.geocities.com/maxpro4u/
Keeping Windows Clean: http://www.geocities.com/maxpro4u/madmax.html
Virus Cleaning+Fixes: http://www.geocities.com/maxpro4u/TechPros
Change nomail.afraid.org to neo.rr.com so you can reply by e-mail
(nomail.afraid.org has been set up specifically for
use in Usenet. Feel free to use it yourself.)
 
P

Peter Seiler

Max M.Wachtel III - 04.01.2005 05:46 :
Just a note,I have some good programs listed on my site to help you
"keep it clean"
-max

[over 100! unnecessary quoting lines snipped]

only to post your single line - grrr!

Same to you (and many others) what I posted Subj. "Very sorry..." to
David H. Lipman at 10:45. Please have a look there. THX in advance for
your kind understanding.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top