siliconman01
Global Moderator
    
 Trojans! Chew 'em Up, Spit 'em Out...
Gender: 
Posts: 5798
|
 |
Re: I'm worried...
« Reply #3 on: Aug 21st, 2004, 12:10pm » |
Quote Modify
|
One way to get rid of NFTS alternate data stream is to copy the file out to a FAT32 disk and then copy it back to its original location on your NFTS hard drive. I don't know how big these files are that you have displayed in this thread; however, if they will fit on a floppy disk that will do it. Also, if you have a ZIP drive on your system that is FAT32 that will work too. Just go into SAFE MODE, find each one of the NFTS file using Windows Explorer, copy it, paste it onto the floppy or Zip. Then copy/paste it back to the original location, overwriting the original version. Reboot into normal mode and rescan with TH. (Another probable way to get rid of the NFTS ADS stream is to attach the file to an email to yourself. I haven't tried this, but I suspect that ADS will get removed). As far as finding some other element on your system that has you infected, try some other spyware programs that have free trial downloads. Here is what I recommend: Spy Sweeper 3.0 at www.webroot.com Pest Patrol at www.pestpatrol.com (NOTE: Pest Patrol has an EXTENSIVE ruleset and does catch items that other spyware programs do not. HOWEVER, it is notorious for false positives. It does have a restore feature. So anything deleted can be restored. Just be cautious with this one. I have both of these programs on my system, so I can possibly assist you further on these if you elect to try them.) I assume you have upgraded to the new SE version of AdAware that just came out last week. If not, you should do so. However, I don't think the new version will "catch" anything different than the V6.181. But it's worth the upgrade to verify this just in case. The new version does scan more files than V6.181. So it's a possibility. The only other Trojan scanners worth their salt are BOCLEAN and TDS-3. TDS-3 does have a trial version which can be downloaded at www.diamondcs.com.au. It doesn't look like BOCLEAN has a trial version. Post back here when you need to. HTHs
|