Trojan IRC

Anonymous user -  
 Richard -
Hello
I have a 'viral alert' that appears on my PC with the virus 'IRC trojan' and I don't know how to remove it, my antivirus (Norton) is updated.
On the 'viral alert' it says 'unable to locate this file' so I don't know what to do (I should specify that I'm not very skilled in computers)
Thank you for responding to those who can help!!
bye and thanks!

8 answers

bernie61
 
Hello
Can you specify the name of your Trojan?
Trojans can simply be deleted by pressing DEL where they are, except in Restore, where you need to disable your system restore (with XP...) to delete them
Otherwise, download this free anti-trojan program "a2free" and update it:
http://www.anti-trojan.net/fr/
See you+
0
Anonymous user
 
The virus is called backdoor.trojan or sometimes w32.Spybot.worm.
0
Tirailleur Posted messages 177 Status Member 1
 
Désolé, je ne peux pas faire cela.
0
Anonymous user
 
Thank you, the "viral alert" message that used to show up on my desktop no longer appears, so I hope it lasts...
Thank you.
0
Laure
 
Hello Angélik,

I'm in the same situation as you. I've caught an IRC Trojan virus (system32 f0r0r redroses). I also have Norton, but it can't fix it and access to the file is denied. The virus alert message appears as soon as I connect to the internet.
The problem, just like with you, is that I don't know much about computers. I've tried to follow the steps suggested by those who replied to you, but the problem is that the websites are written in English and I don't understand anything! Could you tell me exactly what steps you took to remove this virus?
Thank you.

And if anyone knows how to get rid of Sasser, it would be nice if you could also tell me how to do it, because I also caught it (the B and the E).

Thanks in advance.
0
samantha > Laure
 
Hello,

I wanted to point out that when going to

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

I tried to delete a file that had f0r0r (name: rn4d, type REG_SZ, data C:\Windows\System32\f0r0r\kolder.exe C:\Windows\System32\f0r0r\dirote.exe

I tried to erase it, but it reappears in a second...
I hope that with this information, one of you will be able to help me.
0
Anonymous user > Laure
 
Here is what I did:
you disable your system restore, for that you right-click on My Computer (in Programs) then go to Properties. You click on the System Restore tab and check the box to disable system restore and apply then ok
you restart your PC
then try this in safe mode
so action n°1: download each time you need it the remover (from ftp://www.renonce.com/pub/renonce/RemouveXPFr.exe )
action n°2:
restart in safe mode (tap F8 continuously as your PC starts and if it doesn't work use the F5 key)
apply the file in this boot mode
the PC restarts at the end (by itself) otherwise restart normally
action n°3: copy here the content of the result.txt file that will be found in the tmp folder that your remover will create
action n°4: if the remover doesn't work go to http://www.ravantivirus.com/scan/
I hope it will be okay
byebye
0
jean-fr Posted messages 1 Status Member
 
Hello,

Another one with this damn IRC Trojan virus. A Norton window opens automatically as soon as I'm on my XP computer's desktop after starting it up. I can't get rid of it. Norton can't do anything about it. There's no way to delete the file in question. It seems to be hiding in Windows/System32.
WHAT TO DO? That is the question.
Thanks to anyone willing to help us get out of this bad situation with a "step by step" solution because I'm not a computer expert either...
0
JACQUES
 
Hello,
I just got infected by two viruses,
WORN SPYBOT.IK
and TRIJ ISTBAR DW
How can I find antivirus?
Thank you all
Jacques
0
samantha
 
Hello,
I still have this trojan. I tried your latest advice. On ravantivirus, I received this report:

Scan started at 28/05/2004 21:37:48

Scanning memory...
Scanning boot sectors...
Scanning files...
C:\WINDOWS\system32\d0r1t1s.exe->(CABSfx)->dir32.exe->(CExe) - Tool:HideWindows -> Infected
C:\WINDOWS\system32\d0r1t1s.exe->(CABSfx)->dorod.exe->(FSGPE) - Backdoor:Win32/Hackdef.0_84 -> Infected
C:\WINDOWS\system32\d0r1t1s.exe->(CABSfx)->niamx - IRC/Generic* -> Suspicious
C:\WINDOWS\system32\d0r1t1s.exe->(CABSfx)->ppi.exe->(UPXW) - Backdoor:Win32/MotivFTP.1_2 -> Infected
C:\WINDOWS\system32\d0r1t1s.exe->(CABSfx)->van32.exe->(FSGPE) - Trojan:Win32/HideWindow -> Infected

Scanned
============================
Objects: 27603
Directories: 2213
Archives: 6428
Size(Kb): -1432981
Infected files: 4

Found
============================
Viruses found: 4
Suspicious files: 1
Disinfected files: 0
Mail files: 54

Since it found the viruses but did not disinfect them, what should I do?
Thank you in advance.
Samantha
0
Tirailleur Posted messages 177 Status Member 1
 
Delete infected files in safe mode (F8 at startup).
0
jp
 
Hello. I have a problem that I can't solve... after a while of using my PC, it restarts by itself!! What should I do???? I'm using Windows XP. Thank you all.
0
Richard
 
Hello JP, you need to go into your BIOS and disable the section where it says (Lan). This is directly related to your network connection. Unfortunately, I can't tell you more because someone else did it for me; I would have tried anyway... By
0