| language
Information, tips and tutorials for ZTree file manager
Trojan Link Optimizer
{* Edits: REM, Ron Metzger, Sept. 26 2006 11:00 am ET} (This article comes from a forum's thread http://www.ztw3.com/forum/forum.cgi?read=82048Description
- It creates a file called: C:\WINDOWS\COM4.XFW
- Affects the Registry
- http://www.symantec.com/security_response/writeup.jsp?docid=2006-082416-2803-99
- Antivirus detects it but can remove it (notably NOD32)
- Booting on DOS and using NTFS for DOS doesn't work
- Spyware detectors show the entry but can't remove it (HijackThis) or freeze (Spybot-Search & Destroy
Cure
Ron Metzger proposed this solution that works: Well, if you have been hit with LinkOptimizer you must do a few things manually to remove the malware. First of all, do all the corrective actions in safe mode AND Disconnected from the Internet (yes, disconnect the wire(s)). Download any needed tools and then take the corrective actions. {*REM} Since files in the System Restore area may cause re-infection, the safe thing to do is to remove all restore points. For instructions on how to turn off System Restore, read your Windows documentation, or one of the following articles: How to turn off or turn on Windows XP System Restore> Streams -d C:\WINDOWS
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs" = "[TROJAN.DLL FILE]"
C:\Windows\System32\[RANDOM NAME]aa.dll Repeat this for: C:\Windows\[RANDOM NAME]1.dll
ntrights +r SeDebugPrivilege -u Administrators ntrights +r SeBackupPrivilege -u Administrators ntrights +r SeLoadDriverPrivilege -u Administrators
%ProgramFiles%\LinkOptimizer\
> Streams -d C:\WINDOWS
> "C:\Documents and Settings\user1\Desktop\FixLinkopt.exe" /EXCLUDE=M:\ /LOG=c:\FixLinkopt.txt
Contributors to this page: admin
.
Page last modified on Sunday 08 of November, 2009 14:49:03 EST by admin.
Category: Windows tips
