Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

How to remove Trojan WebDL-K

 
   Security Forums (Home) -> General Discussions RSS
Next:  helpexp.exe trojan horse  
Author Message
Ekonomski fakultet

External


Since: Dec 01, 2003
Posts: 1



(Msg. 1) Posted: Mon Dec 01, 2003 7:27 pm
Post subject: How to remove Trojan WebDL-K
Archived from groups: alt>comp>anti-virus (more info?)

on Windows Xp Professional...
file infected is c:\windows\system32\aupdate.exe

I don't have floppy disk.

 >> Stay informed about: How to remove Trojan WebDL-K 
Back to top
Login to vote
Gabriele Neukam

External


Since: Sep 14, 2004
Posts: 462



(Msg. 2) Posted: Tue Dec 02, 2003 10:10 pm
Post subject: Re: How to remove Trojan WebDL-K [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On that special day, Ekonomski fakultet, (danceunity@mail.com) said...

> on Windows Xp Professional...
> file infected is c:\windows\system32\aupdate.exe
>
> I don't have floppy disk.

Not good. One possibility is: Burn a bootable CD-Rom, add an anti-trojan
program, and use it for cleaning. If you need a (clean) boot disk, you
can try www.bootdisk.com, where you can download one.

But the name "WebDL-K" makes it look like this trojan is a downloader,
this means it will fetch one more program from internet and install it,
perhaps another trojan, and this trojan then can introduce some more
"friends".

Once it has itself installed, your PC will forever suffer from the
trojan. If you remove one, another will be there. It is like cockroaches
in the kitchen.

Better burn the house. Backup your data files (and NO programs), then
format the hard disk. Reinstall Windows on a completely pure hard disk.
Everything else is unsafe.

Think of Valve. Their computer was infected with a keylogger. The
keylogger sent passwords to "someone". The "someone" then logged into
the server of Valve, with the stolen password, and stole the complete
source code of Half Life 2. After the password had been reveiled, it was
too late to remove the keylogger, the harm had already been done.

A downloader can download and install many things, including a
keylogger. So, after the new Windows installation, you *must* change all
passwords.


Gabriele Neukam

Gabriele.Spamfighter.Neukam RemoveThis @t-online.de


--
Ah, Information. A good, too valuable theses days, to give it away, just
so, at no cost.

 >> Stay informed about: How to remove Trojan WebDL-K 
Back to top
Login to vote
Rodriguez

External


Since: Dec 03, 2003
Posts: 1



(Msg. 3) Posted: Wed Dec 03, 2003 2:35 pm
Post subject: Re: How to remove Trojan WebDL-K [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

I think I solved my problem.

I downloaded SAV32CLI from Sophos web page, and burned it on CD.

After that, I started WinXP in Safe mode, run sav32cli from cd...

and Trojan was removed. Program deleted aupdate.exe with trojan.

After that I restart windows, run Sophos antivirus with newest update, and
there is no trojan anymore on my disk.

And there is also no aupdate.exe

I don't know if I need this file or it is created with trojan...






"Gabriele Neukam" <Gabriele.Spamfighter.Neukam.DeleteThis@t-online.de> wrote in message
news:bqiv3f$ipr$03$2@news.t-online.com...
> On that special day, Ekonomski fakultet, (danceunity@mail.com) said...
>
> > on Windows Xp Professional...
> > file infected is c:\windows\system32\aupdate.exe
> >
> > I don't have floppy disk.
>
> Not good. One possibility is: Burn a bootable CD-Rom, add an anti-trojan
> program, and use it for cleaning. If you need a (clean) boot disk, you
> can try www.bootdisk.com, where you can download one.
>
> But the name "WebDL-K" makes it look like this trojan is a downloader,
> this means it will fetch one more program from internet and install it,
> perhaps another trojan, and this trojan then can introduce some more
> "friends".
>
> Once it has itself installed, your PC will forever suffer from the
> trojan. If you remove one, another will be there. It is like cockroaches
> in the kitchen.
>
> Better burn the house. Backup your data files (and NO programs), then
> format the hard disk. Reinstall Windows on a completely pure hard disk.
> Everything else is unsafe.
>
> Think of Valve. Their computer was infected with a keylogger. The
> keylogger sent passwords to "someone". The "someone" then logged into
> the server of Valve, with the stolen password, and stole the complete
> source code of Half Life 2. After the password had been reveiled, it was
> too late to remove the keylogger, the harm had already been done.
>
> A downloader can download and install many things, including a
> keylogger. So, after the new Windows installation, you *must* change all
> passwords.
>
>
> Gabriele Neukam
>
> Gabriele.Spamfighter.Neukam.DeleteThis@t-online.de
>
>
> --
> Ah, Information. A good, too valuable theses days, to give it away, just
> so, at no cost.
 >> Stay informed about: How to remove Trojan WebDL-K 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Damn trojan in my temp (probably). Advice needed. - Ok..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]