WINNTsystem32uwryljwu5.exe any ideas?

G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Trojan Horse
File: C:\WINNT\system32\uwryljwu5.exe
Location: C:\WINNT\system32
Computer: PENTIUMII266
User: Sylvia
Action taken: Quarantine failed : Clean failed : Access denied
Date found: Wed Feb 23 17:10:23 2005
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

Whats the time stamp on the file? Any other files created around the same
time. Although this can be altered other files present might provide clues
about what this file is.

Try downloading Process Explorer v9.01 from www.sysinternals.com to see if
this file is running on your machine and is calling other processes. These
might help identify it further.


"LadyHills" wrote:

> Scan type: Realtime Protection Scan
> Event: Virus Found!
> Virus name: Trojan Horse
> File: C:\WINNT\system32\uwryljwu5.exe
> Location: C:\WINNT\system32
> Computer: PENTIUMII266
> User: Sylvia
> Action taken: Quarantine failed : Clean failed : Access denied
> Date found: Wed Feb 23 17:10:23 2005
 
G

Guest

Guest
Archived from groups: microsoft.public.win2000.security (More info?)

Did your antivirus scan give a name for the virus? If it did you may need a
removal tool or manual removal instructions. Usually you can find one if you
search Google for the name of the virus or go to a couple of the major
websites such as Trend Micro, McAfee, Symantec, etc and do a search for that
name. Another thing to try to is do a virus scan in safe mode being sure
your virus definitions are current as of today and trying a stand alone
malware detection and removal tool such as the free Sysclean from Trend
Micro as shown in the links below. If all else fails contact your antivirus
program vendor to ask what to do. --- Steve

http://www.trendmicro.com/download/dcs.asp --- Sysclean
http://www.trendmicro.com/download/pattern.asp --- pattern file in .zip
file

"LadyHills" <LadyHills@discussions.microsoft.com> wrote in message
news:FDB909B9-1BA5-4E87-BA09-93350E5AEEF7@microsoft.com...
> Scan type: Realtime Protection Scan
> Event: Virus Found!
> Virus name: Trojan Horse
> File: C:\WINNT\system32\uwryljwu5.exe
> Location: C:\WINNT\system32
> Computer: PENTIUMII266
> User: Sylvia
> Action taken: Quarantine failed : Clean failed : Access denied
> Date found: Wed Feb 23 17:10:23 2005