Computing.Net > Forums > Security and Virus > Can't get rid of Trojan

Can't get rid of Trojan

Reply to Message Icon

Original Message
Name: kaos2me
Date: May 31, 2004 at 07:29:28 Pacific
Subject: Can't get rid of Trojan
OS: Win ME
CPU/Ram: PIII 127 megs
Comment:

Please help me!

I use AVG and it found a Trogan horse in c:\windows\system\explorer.dll but couldn't get rid of it.

When I ran a Norton antivirus update(it really belongs on my daughter's pc but I got the update from AOL/Norton in the mail that day and decided to try it), it didn't even find the trojan. It did find some files that it said were infected. It didn't say with what though and it wanted them deleted. The files were not important so I deleted them.

I also downloaded and ran A squared as per instructions from another post here about trojans. A squared also did not find the trojan but a screen that pops up at every boot up appeared 2x while it was running. The screen is a warning from AVG and says that a virus Trojan horse psw.sclog.b. is found in file c:\windows\system\explorer.exe

I also looked on the Symantec website and found something about backdoor trojans. After the scan, it stated I didn't have a backdoor trojan.

When AVG first said I had a trojan, my pc was locking up often. That has gotten better but I am wondering if my files are in danger or if I can safely access my banking info?

Thank you for any and all help. I did check other posts about trojans but have found nothing that will work so far. I'll keep looking.


Report Offensive Message For Removal

Response Number 1
Name: kaos2me
Date: May 31, 2004 at 07:57:26 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

Sorry forgot to say that I ran A squared in both regular mode and safe mode and it didn't find the trojan either time. I also ran adaware and spybot s&d and while they both found some stuff, the trojan is still there when I run AVG.

Thanks in advance for any help!


Report Offensive Follow Up For Removal

Response Number 2
Name: Thresher
Date: May 31, 2004 at 12:01:02 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

Read this and follow the directions:

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?Open&src=sec_doc_nam&docid=2001111912274039&nsf=tsgeninfo.nsf&view=docid&dtype=&prod=&ver=&osv=&osv_lvl=

It's hiding in your system-restore files which cannot be vaulted or cleansed except by dumping them. Do not re-enable system restore until you are 100% sure you are clean. You should also dump %TEMP% files>
double click My Computer, put %TEMP% in address bar, enter, highlight and delete all. To dump TIF click tools > options > delete files, check the box for delete off line content > click ok > click delete cookies. > click ok. Dump recycle bin. Do it all from Safe Mode if you can.

Shut down for two full minutes.

This will help a lot, and if you do not have a firewall in place, get Sygate, it's free, no hassles, and keeps me clean.

This will also help, read:

Downloading hint:

One other thing I do is on downloading, after you get the download (M$ does not structure its downloads so you can do this for some reason), after download BEFORE INSTALL, #1. log off the net, #2. disable AV (right click tray icon), #3. then ctrl-alt-delete to close AV in close-program, THEN (and only then) #4. click on the install procedure. Otherwise your AV might read the install as an invader and mess with it. Then manually shut down for two full minutes.

Spybot:

Download and Read the SpyBot tutorial here:

http://s89223352.onlinehome.us/mirror/spybot/index1.php

Download it, Unzip the program, and immediately check for updates, install the updates and then do the scan.

Let it fix everything marked in red. Reboot but not with restart, shut it down for two full minutes. You’ve got two measely minutes and it’s worth it, and let Spybot run if it indicates.

To add an item to your ‘Ignore List” click on the little ‘+’ sign next to the item and left click it to highlight it, then right click it and a menu appears, select the function you want.

When you are done reboot again same way. Two full minutes shut sown is best.

Tea Time discussed by designer here:

http://forums.net-integration.net/index.php?showtopic=13433

Also, go to the update page. Notice 3 icons across the top. Between "Search For Updates" and "Download Updates" there is an icon for the download mirror location. After you click on ‘search for updates,’ the one in the middle will change. If it doesn't say "Spybot.US by Rootboxen.net USA" click on the dropbox arrows and click on Rootboxen, and use only that one. If you got a "checksum error" trying to download --that's why.


Ad-Aware:

Download AdAware from http://www.lavasoft.de/

check for updates at "webupdate".

I use these settings (green check)

From main window click "Start" then make sure " Activate in-depth scan" has a green check next to it.

Put a black dot nest to "Use custom scanning options” and click Customize" next to it, then green check these options:
"Scan within archives" ,"Scan active processes", "Scan registry",
"Deep scan registry" ,"Scan my IE Favorites for banned URL"
"Scan my host-files"

At the top of the “STATUS” page notice the Tweak (gear) icon. Click on it.

The first setting is “Scanning Engine.” Click on the little plus sign next to it, and in the drop-down green check "Unload recognized processes during scanning", and “include basic Ad-Aware settings in log file”. Next click on the ‘+’ next to "Cleaning Engine" and in the drop-down green check "Let windows remove files in use at next reboot" and Delete quarantine objects after restoring”

Click "proceed", that will save those settings.

Click "Scan"

When the scan finishes, mark everything for removal and delete it. Right-click the window and choose "select all" from the drop down menu, press ‘next’ and then ‘yes’ to the prompt: “remove all these entries”.

However, if you have certain programs running that will give a false indicator of a browser hijack attempt, such as Script Sentry, which places a monitoring function in the registry and looks like a browser hijacker but is not, then you may want to add that to the ignore list because you want to keep it there to do it’s job. To add an item to the ignore list, put the a cursor on the file it reveals and left click it to highlight it, then right click it and a menu appears. Click on ‘ignore list.’

Shut down, two minute shut down is best, and let Adaware run on reboot if it indicates.

That should keep you off the streets for a a half hour or so....

Thresher


Report Offensive Follow Up For Removal

Response Number 3
Name: kaos2me
Date: June 1, 2004 at 20:06:18 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

Thresher,

Thank you so much for all your advice. Thanks to you, I am now trojan free!

Also thanks for the advice about the free firewall from Sygate. I am in the process of downloading it now.

Thanks again!


Report Offensive Follow Up For Removal

Response Number 4
Name: svh11
Date: June 14, 2004 at 07:30:37 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

I have the trojan to! I have deleted Explorer.exe in System32! But Can't delete explorer.dll! And i have system restore disabled, but still can't delete it!


Report Offensive Follow Up For Removal

Response Number 5
Name: svh11
Date: June 14, 2004 at 07:31:55 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

How can i get rid of the trojan?


Report Offensive Follow Up For Removal


Response Number 6
Name: hohoho
Date: June 17, 2004 at 09:23:56 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

http://securityresponse.symantec.com/avcenter/venc/data/hacktool.sckeylogger.html


Report Offensive Follow Up For Removal

Response Number 7
Name: Jacky1982
Date: June 17, 2004 at 22:02:14 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

i need help on getting rid of my trojons ..its telling me they are in my temp internet file...how do i get them out .??
thanks



Report Offensive Follow Up For Removal

Response Number 8
Name: hohoho
Date: June 27, 2004 at 01:08:05 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

Google search TrojanSpy.Win32.Sckeylog


Report Offensive Follow Up For Removal

Response Number 9
Name: hohoho
Date: June 27, 2004 at 01:22:04 Pacific
Subject: Can't get rid of Trojan
Reply: (edit)

Remember to change your passwords because it logs your keystrokes including passwords and sends to the hacker.


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Can't get rid of Trojan

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software