LJ Computers PC Support Forums  

Go Back   LJ Computers PC Support Forums > General > Security Issues/Announcements/News
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 15-03-06, 03:26 PM
yddraigoch yddraigoch is offline
Junior Member
 
Join Date: Nov 2004
Posts: 9
Exclamation Trojan-'wuredir.cab.bak'

During startup of Windows XP, Norton regulary checks the above. According to various sites on the internet it is a Trojan.
Can anyone recommend a way of removing it. My AVG (free edition) has not highlighted it.
Reply With Quote
  #2  
Old 15-03-06, 09:42 PM
ljcomp's Avatar
ljcomp ljcomp is offline
Admin
 
Join Date: Sep 2002
Location: Cardiff
Posts: 668
Hi Mate

Quote:
According to various sites on the internet it is a Trojan.
What website/s say it's a trojan

I would say its a backup, hence the .BAK extension.
Of a required Windows update file

You should find the original .CAB file in C:\Windows\SoftwareDistribution\WuRedir\load of letters and numbers

load of letters and numbers above will be different to mine, but looks something like this 9482F4B4-E343-43B6-B170-9A65BC822C77

You can do a search for wuredir.cab to verify you have it.

Then search for wuredir.cab.bak and then DELETE it.

Don't forget to empty that file from your recycle bin.

This in my opinion and error on nortons part, and AVG may well be correct

However if you have read somewhere it's a trojan, I would like to read what they have to say, before commenting further.

LJ
__________________
I hope my reply has helped, if not please come back and tell us. We will do all we can to help..
Reply With Quote
  #3  
Old 09-07-06, 07:46 PM
rontomuk rontomuk is offline
Member
 
Join Date: Jan 2004
Posts: 45
Quote:
Originally Posted by ljcomp
Hi Mate


What website/s say it's a trojan

I would say its a backup, hence the .BAK extension.
Of a required Windows update file

You should find the original .CAB file in C:\Windows\SoftwareDistribution\WuRedir\load of letters and numbers

load of letters and numbers above will be different to mine, but looks something like this 9482F4B4-E343-43B6-B170-9A65BC822C77

You can do a search for wuredir.cab to verify you have it.

Then search for wuredir.cab.bak and then DELETE it.

Don't forget to empty that file from your recycle bin.

This in my opinion and error on nortons part, and AVG may well be correct

However if you have read somewhere it's a trojan, I would like to read what they have to say, before commenting further.

LJ

Hi Lyndon

What you state above is what I read on another site here is a copy of their reply

Re the "wuredir.cab.bak" problem.
wuredir.cab is a legitimate Microsoft file created from MS Update site....but the wuredir.cab.bak file is not needed.
If you can find the wuredir.cab.bak file... delete it. ( MAKE SURE YOU CAN SEE HIDDEN FILES and FOLDERS),
It may be in the C:\WINDOWS\SoftwareDistribution\WuRedir folder, under a sub-folder with a long alphanumeric name.
If you find it there, and it wont delete, let us know.

Cheers
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT +1. The time now is 07:16 AM.


Powered by vBulletin Version 3.6.0
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.
Site Content LJ Computers