Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 08-08-2003, 06:22 AM   #1
Member (12 bit)
 
Markoman01027's Avatar
 
Join Date: Jul 2002
Location: Easthampton, Massachusetts
Posts: 2,633
Friend with Trojan

Hello everybody,

A friend of mine has a trojan installed on his PC. Ran a Trend Micro Virus Scan and it detected that his PC has a Trojan installed on it. I hit "delete" but it said that the file is in use by Windows. So I CTRL+ALT+DEL and once I see the processs list come up, the whole box disappears.
I ran a spybot search and destroy scan and removed all instances of spyware on his PC and removed all of the spyware software installed via add/remove in the control panal.

So after the reboot, the spyware is gone, but the trojan is still inside the system. I cannot end task the process, because once I do the 3 finger salute, the box disappears.

Maybe this will work in safe mode? He has a Dell, P4 1.8Ghz, with 512MB of RAM, and running Windows XP home edition.

I tried to run MSCONFIG from RUN, but I would just click "OK" and nothing else would happen.

I don't see any control over his computer, but he is getting a lot of pop ups, messages, etc.

Any help would be appreciated.
Markoman01027 is offline   Reply With Quote
Old 08-08-2003, 06:58 AM   #2
Member (12 bit)
 
Redo40's Avatar
 
Join Date: Jan 2002
Location: Central Arkansas
Posts: 2,170
What's the name of the Trojan?

Definitely try safe mode to see if you can stop it from running.
__________________
Roger

"Our greatest glory is not in never falling, but in rising every time we fall."
-Confucius
Redo40 is offline   Reply With Quote
Old 08-08-2003, 09:57 AM   #3
Shiro Usagi
Premium Member
 
Cricket's Avatar
 
Join Date: Sep 1999
Location: Kaneohe, Hawaii
Posts: 34,002
Have you tried a trojan scanner like The Cleaner by Moosoft?

Cricket
Cricket is offline   Reply With Quote
Old 08-08-2003, 09:15 PM   #4
Member (12 bit)
 
Markoman01027's Avatar
 
Join Date: Jul 2002
Location: Easthampton, Massachusetts
Posts: 2,633
Next time I am over his house, I will download The Cleaner. NAV didn't detect it, as it was the 2002 version.

Not sure what the Trojan is. But Trendmicro couldn't remove it because the file was in use, and if I tried to end process the offending file, it wouldn't let me.

Will post back next time I am over his house.
Thanks for the input guys!
Markoman01027 is offline   Reply With Quote
Old 08-08-2003, 10:06 PM   #5
Member (4 bit)
 
Join Date: Aug 2003
Posts: 9
Trojan nightmares

I'm assuming you are using Windows XP on this system... I haven't done any troubleshooting of a trojan that wasn't on Windows 98, but I'll state what I know and maybe you'll be able to take this information and use it.

The trojans I dealt with would usually make several copies of themselves. The registry, autoexec.bat or config.sys, and in the system.ini

The trick would be to look in the system.ini under the RUN= line, and look to see what executable was listed there
(Some of these had many spaces after the RUN= to make it look like there was nothing there, but if you scrolled over to the right, you'd find a file name)

Once you get the name of this file, Start -> run -> REGEDIT
Go to SEARCH
and enter the name of the executable you found there
Delete any occurrences of this file name in the registry

Next, go to Start -> run -> sysedit
Look in the win.ini system.ini, config.sys, and autoexec.bat search for that same executable and delete any references in these files.

Now, here's the real kicker -
Before you delete the actual file that is being run from the hard drive, look at the file's creation date.
Go to Start -> Find -> Files and Folders

Search your entire C: drive for any files that were created on the same date, and if any are the same exact file size, you want to delete those as well. They are known to make several copies of themselves with several different names.

It always took me several tries to use this method, but it guarantees that you'll get it deleted. If you miss just one reference or one copy of the trojan and restart, it will put itself back in all the places that you deleted it from.

Hope the above wasn't all jibberish to ya... Take it for what it is ;-)
Railbird is offline   Reply With Quote
Old 08-09-2003, 02:42 AM   #6
Member (12 bit)
 
Markoman01027's Avatar
 
Join Date: Jul 2002
Location: Easthampton, Massachusetts
Posts: 2,633
Thank you for your reply Railbird. I used that method before on removing Sub7 manually. I will try running in safe mode, ending the offending file and then running the cleaner. If that safely removes it. Then I will check the registry, win.ini, system.ini for any instances of that file(s).

Thanks!
Markoman01027 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 01:40 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2