CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Plse help - can't delete TR/Dldr.jh

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
pcdunce

Cadet
Cadet


Joined: Nov 18, 2004
Posts: 2
Location: UK

PostPosted: Thu Nov 18, 2004 3:04 pm    Post subject: Plse help - can't delete TR/Dldr.jh
Reply with quote

Hi - AntiVir detected trojan TR/Dldr.jh but then gave a message saying it couldn't delete or repair it as it was in an archive file. Plse can you give any advice on how I can delete this? Many thanks!

The report was as follows:

Start of scan: 18 November 2004 14:37

Memory test OK
Master boot record of hard disk HD0 OK
Boot record of drive C: OK


C:\
pagefile.sys
Access denied! Error during file opening!
This is a Windows swap file. This file is locked by Windows.
Error code: 0x000D
WARNING! Access error/file locked!
C:\Documents and Settings\Small Boy\Local Settings\Temporary Internet Files\Content.IE5\S5IZ0XU7
cax_gb[1].cab
ArchiveType: CAB (Microsoft)
--> Ole32ws.dll
[DETECTION] The Trojan horse TR/Dldr.JH
cax_gb[2].cab
ArchiveType: CAB (Microsoft)
--> Ole32ws.dll
[DETECTION] The Trojan horse TR/Dldr.JH
cax_gb[3].cab
ArchiveType: CAB (Microsoft)
--> Ole32ws.inf
NOTE! Bad header
--> Ole32ws.dll
NOTE! Bad header
GB175_100[1].exe
The file contains the signature of a cost-incurring dialer DIAL/301116 (Dialer) and was suppressed by the user.
swflash[1].cab
ArchiveType: CAB (Microsoft)
--> swflash.inf
NOTE! Bad header
--> Flash.ocx
NOTE! Bad header
--> GetFlash.exe
NOTE! Bad header
Error! Could not change directory: Sneleanor Snark
C:\Program Files\PestPatrol
Spyware.dat
ArchiveType: ZIP
NOTE! The whole archive is password protected
C:\Program Files\PestPatrol\Quarantine
20040709114652156.zip
ArchiveType: ZIP
--> WINDOWS\htpatch.exe
The file contains the signature of a cost-incurring dialer DIAL/301122 (Dialer) and was suppressed by the user.
20040710090633531.zip
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
20040808195027546.zip
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
20040808214358500.zip
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
Error! Could not change directory: System Volume Information
C:\WINDOWS\SoftwareDistribution\EventCache
{4A7F58D8-24DB-4079-9C74-421EBC456DAF}.bin
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
C:\WINDOWS\system32\config
default
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SAM
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
SECURITY
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
software
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
system
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!
C:\WINDOWS\system32\spool\drivers\w32x86
E_DWM0XE.EXE
ArchiveType: LZH (+.LHA) SFX (self extracting)
NOTE! No files to extract.
C:\WINDOWS\Temp
ZLT06596.TMP
Access denied! Error during file opening!
Error code: 0x000D
WARNING! Access error/file locked!

End of scan: 18 November 2004 14:55
Time taken: 17:33 min


2313 directories were scanned
62062 files were scanned
11 warning messages were issued
0 files were deleted
0 files were repaired
2 detections

Back to top
View users profile Send private message
Rocketmech

Trooper
Trooper


Joined: May 20, 2004
Posts: 13
Location: USA

PostPosted: Fri Nov 19, 2004 6:42 am    Post subject:
Reply with quote

1.Delete this folder:
C:\Documents and Settings\Small Boy\Local Settings\Temporary Internet Files\Content.IE5\S5IZ0XU7

2.You can delete the quarantined files in Pest Patrol .

3.Rescan with AVPE .

Back to top
View users profile Send private message
pcdunce

Cadet
Cadet


Joined: Nov 18, 2004
Posts: 2
Location: UK

PostPosted: Fri Nov 19, 2004 7:34 pm    Post subject: Success
Reply with quote

That worked ok - thanks very much for your help!! Very Happy

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer