How To Delete This Trojans?

BD find that my computer is infected with these trojans but not delete this virusses


Can you help me?


Trojan.Retapu D


Trojan downloader Agent ZEx


Trojan downloader Harnig ZC

Comments

  • use the utility found at this link http://technet.microsoft.com/en-us/sysinte...s/bb897556.aspx


    you can find the instructions there.


    of course you need to know which files are infected


    if this doesn't work please post a autoruns log

  • Thank you BDISGEO!


    I did not try yet with this tool, I send Log file made yesterday .


    Trojab retapu is not present but others are.


    BitDefender Log File !!!!!


    Product : BitDefender Internet Security 2008


    Version : BitDefender UIScanner v.11


    Log date : 21:53:22 08/04/2008


    Log path : C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\deep_scan\1207684402_1_02.xml


    Scan Paths:


    Path0000: C:\


    Path0001: E:\


    Scan Options:


    Scan for viruses : Yes


    Scan for adware : Yes


    Scan for spyware : Yes


    Scan for applications : Yes


    Scan for dialers : Yes


    Scan for rootkits : Yes


    Target selection options:


    Scan registry keys : Yes


    Scan cookies : Yes


    Scan boot sectors : Yes


    Scan memory processes : Yes


    Scan archives : Yes


    Scan runtime packers : Yes


    Scan emails : Yes


    Scan all files : Yes


    Heuristic Scan : Yes


    Scanned extensions :


    Excluded extensions :


    Target Processing


    Default action for infected objects : Disinfect


    Default action for suspicious objects : None


    Default action for hidden objects : None


    Scan engines summary


    Number of virus signatures : 1130379


    Archive plugins : 41


    Email plugins : 6


    Scan plugins : 12


    Archive plugins : 41


    System plugins : 4


    Unpack plugins : 7


    Overall scan summary


    Scanned items : 88936


    Infected items : 4


    Suspicious items : 0


    Resolved items : 0


    Individual viruses found : 2


    Scanned directories : 3554


    Scanned boot sectors : 3


    Scanned archives : 860


    Input-output errors : 29


    Scan time : 00:00:18:25


    Files per second : 80


    Scanned processes summary


    Scanned : 50


    Infected : 0


    Scanned registry keys summary


    Scanned : 306


    Infected : 0


    Scanned cookies summary


    Scanned : 0


    Infected : 0


    Remaining issues:


    Object Name Threat Name Final Status


    C:\System Volume Information\_restore{E479253E-B6A6-4560-BDB7-7D9D79997AA0}\RP44\A0009187.exe Trojan.Downloader.Agent.ZEX Disinfect FailedC:\System Volume Information\_restore{E479253E-B6A6-4560-BDB7-7D9D79997AA0}\RP47\A0009262.exe Trojan.Downloader.Agent.ZEX Disinfect Failed


    C:\WINDOWS\mrofinu1535.exe.tmp Trojan.Downloader.Agent.ZEX Disinfect FailedC:\Documents and Settings\Drago i Marjana\My Documents\marijana\stik\Games_Games_1[1].1.rar=]Games_Games_1.1\PopCap Games Universal Crack\PCDPRemover.exe Trojan.Small.UD Delete Failed (file was in an archive)


    Resolved issues:


    Object Name Threat Name Final Status


    Objects that were not scanned:


    Object Name Reason Final Status


    In Log fale stay:


    Target Processing


    Default action for infected objects : Disinfect


    Default action for suspicious objects : None


    Default action for hidden objects : None


    Where can I change this settings, Default action for others objects - Disinfect?


    Is it I safe to remove manually these files with viruses?

  • Foxter
    edited April 2008

    Deactivate System restore to remove this:


    C:\System Volume Information\_restore{E479253E-B6A6-4560-BDB7-7D9D79997AA0}\RP44\A0009187.exe Trojan.Downloader.Agent.ZEX


    C:\System Volume Information\_restore{E479253E-B6A6-4560-BDB7-7D9D79997AA0}\RP47\A0009262.exe Trojan.Downloader.Agent.ZEX


    You can remove manually the rest. However you may have to enter Start/Run/msconfig/Startup and deactivate the startup of the virus if it's a memory resident virus.


    I think that this file "C:\WINDOWS\mrofinu1535.exe.tmp Trojan.Downloader.Agent.ZEX" is active in memory when windows starts. In this case you will have to deactivate it by using msconfig.


    Also if you want to erase those file manualy you better do it from windows Safe Mode (F8 right before windows starts loading to enter Safe Mode).