Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I can't seem to get rid of a trojan virus. I have tried many different Virus scanners and adware removers. I have also tried the program TrojanHunter, and that seems to remove it, but it comes back each time I reboot. I have also tried TrojanRemover, and that finds it in Safe Mode, but it can't remove it. If I run that program in Normal Mode, it blue screens my computer. Any advice or assistance would be greatly appreciated.

have you turned off system restore to scan?
What is the EXACT virus?
You said:
**I have tried many different Virus scanners and adware removers.**Also, let us know which programs you have used to try removing it.
Some HELP in posting on Cnet plus free progs and instructions Glad to Help!

I have tried some free Virus Scan programs, the most recent is AVG. Unfortunately, I do not recall the rest of them. Do you have one that you recomend. Everytime after bootup, and I run the Trojan Remover program it detects an Agent.100 registry key.

Click on my red link, all software is listed on one page.
Download Avast, install it and make sure it does a bootscan on reboot. Move EVERYTHING it finds to the chest.
Disable AVG for now.There are some other freebies on that page, I would suggest running all of them. Good Luck
Some HELP in posting on Cnet plus free progs and instructions Glad to Help!

After doing some more scans with some programs, here is the latest:
Avast pops up warnings continuously about Trojan Horses being found. It is a Malware Trojan Horse - Win32.Small - EPJ[Trj]
Trojan Remove 6.6.2 finds the below. It can't seem to remove it even after a reboot:This Windows Service appears to be hidden using Rootkit techniques:
C:\WINDOWS\system32\drivers\runtime2.sys
The Program is loaded by the following (hidden) Registry key:
HKLM\SYSTEM\CurrentControlSet\Services\runtime2\
----------------
The Windows Registry loads this file (entry is stealthed):
C:\WINDOWS\Temp\startdrv.exe
The file is loaded by the follwing Registry key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
----------------
This file is called by a Services Registy key:
C:\WINDOWS\System32\drivers\runtime.sys
The file is loaded by the follwing Registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\runtime\"ImagePath"
----------------
AVG finds the following:
Trojan Horse BackDoor.Generic7.XXD

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |