This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Trojan\TDL3Mem-A Cleaning

Hello,

We run Sophos as our enterprise anti-virus solution. Yesterday one of our machines was found to have this trojan on it: TDL3Mem-A (http://www.sophos.com/security/analyses/viruses-and-spyware/trojtdl3mema.html). It says it needs to be manually cleaned, but the Sophos site linked does not have instructions for it.

According to the scan it has infected ntdll.dll:pid:00000ab0.

Any help offered would be greatly appreciated.

Cheers.

:2983


This thread was automatically locked due to age.
Parents
  • I suggest you read down a few posts. Unfortunately it seems we just have to reinstall.

    I was just infected by a nasty Trojan with the name Gbwb#Qf ̀lufqz. [There is a small symbol after the Qf.] It masqueraded as a free clean-up utility, running through wuauclt.exe. It stripped my PC from being able to access Restore or from using Task Manager. After a few minutes it masked all my files and even started giving me phoney RAM and HDD error messages. It's very well written and looks lethal. I did not follow any of its instructions.

    All I got from a Sophos scan was suspicious activity "HIPS/RegMod-009"

    Sophos also quarantined an item where the only action I could take was to "authorize" it to load!

    Not so happy with Sophos after this.

    BTW, it infected through a Bell Wi-Max Modem.

    My PC (running Windows XP SP3 is in the shop. Luckily I had done a complete backup July this year.

    :16993
Reply
  • I suggest you read down a few posts. Unfortunately it seems we just have to reinstall.

    I was just infected by a nasty Trojan with the name Gbwb#Qf ̀lufqz. [There is a small symbol after the Qf.] It masqueraded as a free clean-up utility, running through wuauclt.exe. It stripped my PC from being able to access Restore or from using Task Manager. After a few minutes it masked all my files and even started giving me phoney RAM and HDD error messages. It's very well written and looks lethal. I did not follow any of its instructions.

    All I got from a Sophos scan was suspicious activity "HIPS/RegMod-009"

    Sophos also quarantined an item where the only action I could take was to "authorize" it to load!

    Not so happy with Sophos after this.

    BTW, it infected through a Bell Wi-Max Modem.

    My PC (running Windows XP SP3 is in the shop. Luckily I had done a complete backup July this year.

    :16993
Children
No Data