Computing.Net > Forums > Security and Virus > Can't find Trojan to remove it

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Can't find Trojan to remove it

Reply to Message Icon

Name: Carol B.
Date: February 10, 2004 at 17:05:55 Pacific
OS: Win XP Pro ver. 2002 SP1
CPU/Ram: AMD Athlon 2500+ / 512 Ra
Comment:

I run AVG anti virus and it has found a "Trojan".
Location is on my second hardrive that I JUST had to replace because it froze up and I could get Windows to work. Now I had already scan it for virus and had found none.
I set it up as a "slave".
Here is the location< believe it is in a restore file, could explain why I could get the thing to restore just before it crashed.

D:\System Volume Information\_restore{1136EA44-66DE-4969-BAE0-CA5B208F853C}-\RP12\A001497.exe

I can't get to this file to delete it, nor can AVG seem to be able to either.

PLEASE HELP!! I would like to get to reinstall the drive as the main drive again. But I'm afraid to as long as I can't get this "Trojan" gone.

Thanks!!



Sponsored Link
Ads by Google

Response Number 1
Name: Carol B.
Date: February 10, 2004 at 17:32:46 Pacific
Reply:

Edit to the above message...

I could NOT get my computer to restore from Windows Restore.

Thanks.


0

Response Number 2
Name: wawadave
Date: February 10, 2004 at 20:48:20 Pacific
Reply:

hello
try rebooting to safe mode. and goto mycomputer right click it and disable system restore (if thats where the trojin is)
and reboot.
you might try on line scan at panda or housecall anti virus.

••• Resistance is invigorating! •••


0

Response Number 3
Name: Carol B.
Date: February 10, 2004 at 21:17:47 Pacific
Reply:

The problem is that it is on the HDD that is a slave because of windows crashing.
I'm not even sure if I can get it to come back up with Windows.
I have no way of disabling Restore on it, I can't even find it with search.
Of course it's probably listed with a different name.
I'm trying my best NOT to lose the info on that HDD.
So I want to get rid of the trojan before I reconnect it as Master.

Does my problem sound like it comes from a trojan or virus attack? I really would like to solve that little mystery too.

Thanks!


0

Response Number 4
Name: Carol B.
Date: February 11, 2004 at 07:18:01 Pacific
Reply:

Does anyone know how the get to the restore folder on a HDD?

Should I attempt to change over to "kill" this trojan?

Thanks!

Remove under score to email.


0

Response Number 5
Name: blender
Date: February 11, 2004 at 07:52:21 Pacific
Reply:

If the trojan is where you say it is...

D:\System Volume Information\_restore{1136EA44-66DE-4969-BAE0-CA5B208F853C}-\RP12\A001497.exe

If that is the only location of the trojan....you are safe. The only way the trojan would harm you in that folder is if you used that restore point.
To kill it...you need to disable system restore as said above.
To disable system restore:

Right click "my computer"
Click properties
Click the system restore tab
Checkmark "turn off system restore on all drives"
Click apply
Click ok
Reboot the machine

All restore points will be deleted along with your trojan on ALL drives.
Just to be sure...rescan and if all clean then turn system restore back on.

The reason you or your AVG cannot access or remove the trojan from System restore is because windows locks that file from anything changing it including antivirus.

I never give up!


0

Related Posts

See More



Response Number 6
Name: Carol B.
Date: February 12, 2004 at 17:26:53 Pacific
Reply:

I did the "uncheck" restore.
The Trojan if on the "slave" HDD, which is D:\.

That did remove it.

I removed the "restore log" with Norton's wipe info and the thing still shows up with AVG.

I tried to switch the hards drives, Slave back to original and new to slave. The system said it could find the slave but not the master.

Something new..NOW I'm having a box come up saying I need to put n my Win XP disk as some of the files on system are not correct.

IF I turn off computer and back on, It doesn't come back up.

What the heck could cause that?

I'm not giving up, but this is driving me crazy.

Thanks!

Remove under score to email.


0

Response Number 7
Name: Carol B.
Date: February 12, 2004 at 17:34:33 Pacific
Reply:

OK it's been a LONG day.

edit to the above....

The Trojan is ON the D:\ which is the slave HDD.

The unchecking restore did NOT remove the Trojan.

The thing about putting in the XP disk doesn't show up immediately, but after a while, say 30+ minutes.

Hope your having a better day than me, LOL.

Remove under score to email.


0

Response Number 8
Name: ch21je
Date: February 18, 2004 at 05:06:31 Pacific
Reply:

Hi

I've got almost the identical problem. The AVG Resident shield flags up this system restore folder as harbouring a Trojan Horse, but the full system test doesn't find or remove it.

C:\System Volume Information can be found by:

In a windows explorer window goinging to tools>folder options...

Go to the 'view' tab;
check the 'show hidden files and folders'
uncheck the 'hide protected system operating folders' > say 'ok' to the warning message it flashes up.

I got this far, but access is still denied to this folder. Apparently right-click and go to properties, then if you have a 'security' tab, you can put your username in as one of the users who can access that file.

Whether deleting any files in that folder is a good idea though....


0

Response Number 9
Name: blender
Date: March 7, 2004 at 21:04:04 Pacific
Reply:

John

I would not think it is a good idea to delete files in there once you do gain access...you would be left with a partial restore point and if ever had to use it...computer is rooked.

Easiest to disable system restore, reboot, rescan, if all clean then enable restore again.
The reboot after enabling restore would create a brand new restore point you know is complete and clean.

You likely didnt see ant results in your avg scan because avg is configured to skip scanning those files because it can't fix them anyway.
Windows locks that folder from any modification including from anti virus.
Windows will sometimes back up viruses/trojans etc.

I dont know what operating system you have so I will post for both me and xp.


(winXP)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

How to Turn On and Turn Off System Restore in Windows XP
http://support.microsoft.com/default.aspx?...kb;en-us;310405
.............................
Win ME
To disable System Restore:

1. Right-click My Computer, and then click Properties.
2. On the Performance tab, click File System, or press ALT+F.
3. On the Troubleshooting tab, click to select the Disable System Restore check box.
4. Click OK twice, and then click Yes when you are prompted to restart the computer.
5. To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.
6. Ok your way out.

How to Enable and Disable System Restore
http://support.microsoft.com/default.aspx?...kb;en-us;264887
_____________________________

I never give up!

Windows Update


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Can't find Trojan to remove it

need Mailwiper removal www.computing.net/answers/security/need-mailwiper-removal-/16557.html

I can't find it or fix it! www.computing.net/answers/security/i-cant-find-it-or-fix-it/12536.html

Can't Find the file www.computing.net/answers/security/cant-find-the-file-/930.html