http://computercops.biz/postt7729.html
My antivirus software detected a virus (Download.Trojan) in a file called Belt.exe & Belt.cab. They were in my local settings/temp folder. I was not able to quarantine the items nor delete them. My virus software replies with "quarantine failed" and "repair failed". So, I just found the file myself and deleted it. So far, I'm not experiencing any problems....but can somebody tell me what this was?
Belt.exe is indeed an Adware downloader trojan, and you may have more issues deserving attention.
We'd like to have a closer look at your configuration. Please do the following:
Go to <http://tomcoyote.org/hjt/> , and download 'Hijack This!'.
Unzip, doubleclick HijackThis.exe, and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log somewhere, and please show us its contents.
Most of what it lists will be harmless or even required, so do NOT fix anything yet.
In Hijack This, check all of the following items, then close all browser windows, and press "Fix Checked":
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download2.abetterinternet.com/do.../flash.cab <http://download2.abetterinternet.com/download/cabs/FON19106/flash.cab>
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/18cde0ae43a5047a0e...xIE601.cab <http://207.188.7.150/18cde0ae43a5047a0e01/netzip/RdxIE601.cab>
Now restart your computer, and delete that Belt.exe file, if still there.
Page url:
http://www.tje.net/PCSupport/index.html?belt_exe.htm
Page content was last updated: 10/6/2008
|
|