Author Topic: win32:trojan-gen. {delphi}  (Read 11215 times)

0 Members and 1 Guest are viewing this topic.

Offline Flee

  • Newbie
  • *
  • Posts: 5
win32:trojan-gen. {delphi}
« on: March 07, 2004, 02:02:33 AM »
i have a serious problem with this worm, avast says it cant delete it.. I hope you guys can help me out.. I would really apreciate that

Offline Summoner Yuna

  • Full Member
  • ***
  • Posts: 181
  • High Summoner Yuna
Re:win32:trojan-gen. {delphi}
« Reply #1 on: March 07, 2004, 04:04:38 AM »
this is a generic detection. in order to help with removal I need a specific name. run housecall http://housecall.trendmicro.com and tell me the name of the trojan it finds.
Intel Pentium III 700 mhz desktop
384 MB of RAM
Windows XP
And a apple iBook G3 633 Mhz / upgraded to Mac OS 10.3.9 / 384 MB of RAM

Offline Flee

  • Newbie
  • *
  • Posts: 5
Re:win32:trojan-gen. {delphi}
« Reply #2 on: March 07, 2004, 03:59:16 PM »
i runned the housecall and it found: win3d:Dialui[trj]  (filename  C:\DOCUME~1\Even\LOCALS~1\Temp\V4OG3Ca02340)...last day avast said that a file under the name "kernel.exe" was infected.. im not so sure with this + I am n00b ::)
« Last Edit: March 07, 2004, 04:01:16 PM by Flee »

Offline Summoner Yuna

  • Full Member
  • ***
  • Posts: 181
  • High Summoner Yuna
Re:win32:trojan-gen. {delphi}
« Reply #3 on: March 07, 2004, 10:25:00 PM »
tell house call to delete this file or tell avast to delete it either way


let avast delete kernel.exe.
« Last Edit: March 07, 2004, 10:25:52 PM by Summoner Yuna »
Intel Pentium III 700 mhz desktop
384 MB of RAM
Windows XP
And a apple iBook G3 633 Mhz / upgraded to Mac OS 10.3.9 / 384 MB of RAM

Offline Flee

  • Newbie
  • *
  • Posts: 5
Re:win32:trojan-gen. {delphi}
« Reply #4 on: March 08, 2004, 12:18:59 AM »
its not that easy, i've tried over and over to delete the trojan(delphi), avast just gets errors when I try to delete it..but,the other trojan(win32:dialui[trj]) was no problem to remove.. what can i do to get rid of that other ignoring trojan? ::)  
« Last Edit: March 08, 2004, 12:45:46 AM by Flee »

Offline Summoner Yuna

  • Full Member
  • ***
  • Posts: 181
  • High Summoner Yuna
Re:win32:trojan-gen. {delphi}
« Reply #5 on: March 08, 2004, 01:58:43 AM »
have you tried to scan with avast in safe mode?
Intel Pentium III 700 mhz desktop
384 MB of RAM
Windows XP
And a apple iBook G3 633 Mhz / upgraded to Mac OS 10.3.9 / 384 MB of RAM

Offline Flee

  • Newbie
  • *
  • Posts: 5
Re:win32:trojan-gen. {delphi}
« Reply #6 on: March 08, 2004, 03:12:47 AM »
I scanned in safe mode, found the trojans and got stuck with error when trying to delete..

Offline whocares

  • Super Poster
  • ***
  • Posts: 1698
  • I'm not a llama! :-)
Re:win32:trojan-gen. {delphi}
« Reply #7 on: March 08, 2004, 09:59:41 AM »
Hi,

reboot the PC in safeMode, login as Admin, make sure that avast resident shield is not running (pause it if necessary).
THen navigate with file explorer to the TEMP-folder in your first posting, and delete ALL files in it

do a thorough scan (including archives) of the whole system while still in safemode
if the trojan is gone, reboot normally
if not: please post the full/complete/exact path to the file that avast finds the trojan in

- apply all Windows updates
-  check/close/secure your network shares
- Install, update, scan and fix with:
spybot, ad-aware, cwshredder (DL-Links here via the board search)
- secure IE-Browser: /disable/restrict ActiveX & scripting
-exercise caution when surfing in the future

 ;)

Offline Flee

  • Newbie
  • *
  • Posts: 5
Re:win32:trojan-gen. {delphi}
« Reply #8 on: March 08, 2004, 10:30:19 PM »
yeah :)
it worked! ;D

thanks so much for helping me

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9271
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re:win32:trojan-gen. {delphi}
« Reply #9 on: March 08, 2004, 10:32:10 PM »
Hehe you'd just have to terminate trojan process running in the background ;)
Visit my webpage RejZoR's Flock of Sheep