hi
for last one week i am trying to remove trojan horse backdoor.agent.LTR ..it has infected this file … c:windowssystem32driversfdwmayz.sys … i use AVG 7.5.516 version ..it has quarantined this file for me..but i cant repair it or heal it….if i delete the file then the flle comes back again and avg quarantines it again… my firewall is Zonealarm 7.0.462 ..so i am stuck ..can anyone give some suggestions how to get rid of that trojan horse..i searched in google for it found 4 results 1 was in chinese and other 3 did not help much .
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
trojan horse backdoor
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » trojan horse backdoor
- This topic has 10 replies, 8 voices, and was last updated 17 years, 3 months ago.
AuthorTopicWSsameer_katoch
AskWoody LoungerFebruary 24, 2008 at 4:45 pm #448880Viewing 6 reply threadsAuthorReplies-
WSjaystarter1
AskWoody LoungerFebruary 24, 2008 at 5:39 pm #1098974I would wait for more informed loungers than me to answer but….I seem to remember having trouble getting rid of a nastie and the solution was to clear all the restore points in windows restore and then run your anti virus again. What about the AVG forums? might be worth asking for advice there.
-
WSPrestonK
AskWoody Lounger -
WSArgus
AskWoody LoungerFebruary 25, 2008 at 5:43 am #1099056Since I sometimes comment on issues related to SR (here in the Lounge) I could maybe be seen as its advocate, but I have not used it so many times and see it as one of several layers of protection (in broad sense) in Windows XP. However one should know its do’s and don’ts.
As Jefferson says (and puts it very well); if a file (or anything) keeps re-appearing something, yet not detected and removed, is responsible for putting it there. In this case it isn’t SR.
It has been mentioned so many times on the webb that you should disable SR in the process of cleaning out viruses and other malware, that it is almost on the standard list of tasks to do, but very few think about the consequences or why it should or shouldn’t be done during the cleaning process.
The reason SR is mentioned, obviously (for those who knows what SR is), is that if you don’t remove old restore points (RP) you could maybe get re-infected in the future when using SR to go back in time to an earlier RP. But until the time you chose to use SR, there is no risk to get re-infected (via SR).
In a, sometimes, complicated cleaning process it is possible that something goes wrong and the situation is worse than when you started to clean the PC. Given this possibility, it is obvious why one should wait with purging old RP’s. You could then use SR in the cleaning process and go back to where you started. But when the PC is clean (confirmed by different types of programs) it is a good time to start fresh, by removing old RP’s (turn off and turn on SR, and maybe adjust settings; size & what drive to monitor).
Then of course one has to have a little knowledge about what the AV reports as a virus etc. If at last in the process it only reports a virus in the RP area, purging the RP’s can be seen as the last step, since some AV programs have problems with working in that area.
The recommendation to leave SR and its RP’s in place until the PC is clean has been mentioned by some, most known maybe MS-MVP Bert Kinney, who probably knows most about SR of any outside MSFT.
He has a site about SR, which also mention a little about virus and spyware removal programs: http://bertk.mvps.org/html/spyware.html%5B/url%5D The page also links to an IE community article by MS-MVP Sandi Hardmeier about getting rid of spyware.
He also participates In the AUMHA FORUMS, which mention the above about SR in a thread: Purging old System Restore pointsJefferosn an Bob have mentioned some good programs, since it could be needed to broaden the approach beyond AV programs.
-
WSsameer_katoch
AskWoody LoungerWSjscher2000
AskWoody LoungerFebruary 24, 2008 at 8:19 pm #1098987If a file keeps re-appearing, you should suspect that an undetected program keeps “dropping” the trojan after it is removed. Or, depending on how it spreads, a web site you visit regularly (or chat or P2P file sharing software) may be dropping the trojan. Try some other clean-up tools to detect and remove any malware. And shut down all nonessential programs that start up with Windows and Internet Explorer to try to arrive at a stable configuration where the trojan does not reappear.
WSviking33
AskWoody LoungerFebruary 24, 2008 at 8:44 pm #1098990Another well thought of and recommended program is SPYBOT S&D
WSCah
AskWoody LoungerFebruary 25, 2008 at 2:29 am #1099038Hi, unfortunately I can’t offer help with the problem of removing the trojan but I strongly recommend getting some kind of disc imaging system. Eg Acronis True Image 8 may now be available free. Personally, I just don’t think it is worth the time and anxiety trying to remove a Trojan. Rootkits are so horrendous these days one can never be completely sure of having got rid of one. A better approach, in my opinion, is to install the operating system with programs from scratch and then make an image as a fail safe. I make a back-up image of my system every month. At the first sign of a problem I just go back to a known clean image. This approach does mean having a partition and putting your data on another drive. The images can be stored on the data partition – or for added security on a removable hard disc that is usually not connected to the system.
Best wishes,
Chris (Hunt)
WSsameer_katoch
AskWoody LoungerFebruary 25, 2008 at 4:13 pm #1099132ok ..i use spybot search and destroy also….i did a scan with it and found nothing…then i went to the free avg forums ….searched there for the trojan horse ..did not find it there..then i did a free online scan of my full system from —http://housecall.trendmicro.com/ …it detected some windows updates i needed to do rest it did not find anything…as i mentioned earlier i dont use windows system restore ..and i had disabled the serive from services.msc 6 months back and its off in my computer also from the beginning. Right now the trojan is quarantined by avg …i have a software called hijackthis …but i dont know how to use it .i use Process xp ..to see the process which are running all the time ..all of them looked the regular ones although i am not a expert in that . i have a 157 GB hdd …3 partitions… c ,d ,e …i have never made a image of the system ..but to make the image the system should be clean ..so if i could somehow get rid of the trojan ..then i could probably make the image also .
-
WSDocWatson
AskWoody LoungerFebruary 25, 2008 at 5:42 pm #1099150Get your HijackThis Tutorial do a scan & post your log in their forum. I’m afraid you will be needing their help with this thing.
-
WSjscher2000
AskWoody Lounger
Viewing 6 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Windows 11 ad from Campaign Manager in Windows 10
by
Jim McKenna
13 hours, 4 minutes ago -
Small desktops
by
Susan Bradley
31 minutes ago -
Totally disable Bitlocker
by
CWBillow
7 hours, 55 minutes ago -
Phishers extract Millions from HMRC accounts..
by
Microfix
21 hours, 43 minutes ago -
Windows 10 22H2 Update today (5 June) says up-to-date but last was 2025-04
by
Alan_uk
23 hours, 35 minutes ago -
Thoughts on Malwarebytes Scam Guard for Mobile?
by
opti1
1 day, 2 hours ago -
Mystical Desktop
by
CWBillow
1 day, 2 hours ago -
Meta and Yandex secretly tracked billions of Android users
by
Alex5723
8 hours, 15 minutes ago -
MS-DEFCON 2: Do you need that update?
by
Susan Bradley
1 hour, 9 minutes ago -
CD/DVD drive is no longer recognized
by
WSCape Sand
1 day, 18 hours ago -
Windows 11 24H2 Default Apps stuck on Edge and Adobe Photoshop
by
MikeBravo
1 day, 20 hours ago -
North Face and Cartier customer data stolen in cyber attacks
by
Alex5723
1 day, 19 hours ago -
What is wrong with simple approach?
by
WSSpoke36
1 day, 11 hours ago -
Microsoft-Backed Builder.ai Set for Bankruptcy After Cash Seized
by
Alex5723
2 days, 6 hours ago -
Location, location, location
by
Susan Bradley
20 hours, 56 minutes ago -
Cannot get a task to run a restore point
by
CWBillow
2 days, 7 hours ago -
Frustrating search behavior with Outlook
by
MrJimPhelps
1 day, 22 hours ago -
June 2025 Office non-Security Updates
by
PKCano
2 days, 18 hours ago -
Secure Boot Update Fails after KB5058405 Installed
by
SteveIT
21 hours, 16 minutes ago -
Firefox Red Panda Fun Stuff
by
Lars220
2 days, 18 hours ago -
How start headers and page numbers on page 3?
by
Davidhs
3 days, 5 hours ago -
Attack on LexisNexis Risk Solutions exposes data on 300k +
by
Nibbled To Death By Ducks
2 days, 7 hours ago -
Windows 11 Insider Preview build 26200.5622 released to DEV
by
joep517
3 days, 13 hours ago -
Windows 11 Insider Preview build 26120.4230 (24H2) released to BETA
by
joep517
3 days, 13 hours ago -
MS Excel 2019 Now Prompts to Back Up With OneDrive
by
lmacri
3 days, 3 hours ago -
Firefox 139
by
Charlie
2 days, 20 hours ago -
Who knows what?
by
Will Fastie
1 day, 22 hours ago -
My top ten underappreciated features in Office
by
Peter Deegan
57 minutes ago -
WAU Manager — It’s your computer, you are in charge!
by
Deanna McElveen
1 day, 8 hours ago -
Misbehaving devices
by
Susan Bradley
2 days, 10 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.