Computing.Net > Forums > Windows 95/98 > Trojan Horse - how to remove?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Trojan Horse - how to remove?

Reply to Message Icon

Name: ken
Date: October 27, 2003 at 16:53:35 Pacific
OS: win98se
CPU/Ram: amdk6/256
Comment:

I have a trojan horse virus. NAV has detected it, but can't repair or remove it, so it is quarantined. I have deleted it from the NAV quarantined files, but it keeps surfacing and getting "re-detected", so I quarantine it again. I emailed NAV support and got this response: "filename: C:\WINDOWS\system32\svc.exe
machine: G7V0X3
result: This file is infected with Trojan Horse

Developer notes:
C:\WINDOWS\system32\svc.exe is non-repairable threat. NAV with the latest beta definition detects this. Please delete this file and replace it if neccessary. Please follow the instruction at the end of this email message to install the latest beta definitions.


The current monthly definitions are capable of detecting and repairing
this virus. Please update your definitions by clicking the "LiveUpdate"
button in your NAV program.
" I followed their directions, but no luck. When I do a search on my hard drive for the file,it can't be found. I downloaded Tauscan and ran it, and it says I don't have a trojan horse virus. how do I get this out of my system? Thanks for helping!



Sponsored Link
Ads by Google

Response Number 1
Name: WhitPhil
Date: October 27, 2003 at 17:27:36 Pacific
Reply:

Here is more info on your trojan.

http://www.esecurityplanet.com/alerts/article.php/3095901

Restart to safe mode and run msconfig > startup tab
UNselect SVC
Also, browse to \System32 and delete SVC.exe

Reboot

Also, start running NAV in autoprotect mode. Then any virus/trojan will be detected on the way in, not after the fact.


0

Response Number 2
Name: loral
Date: October 28, 2003 at 09:05:09 Pacific
Reply:

Hi Ken,

Unfortunately, running MSCofig and unchecking this does nothing to CURE the problem, it will remove it until you get hit again by it. MSCofig is for troubleshooting, not fixing problems. To check & uncheck an item is only for finding the culprit and then taking proper actions. I tell my customers that they should always be running in normal mode.

I have not personally worked on this problem but have checked with some other techs.

I am told by two different techs that running AD-Aware from www.lavasoftusa.com will detect this and remove it. Both techs said their customers got the exact same email from NAV and are both still waiting for a follow up response.

If you are inexperienced with SpyWare removal tools, be VERY careful as these also edit and/or delete keys in your registry that can render your computer unbootable. If you choose to run Ad-Aware, just work with this particular problem (SVC.EXE)until you can research other items found.

Good luck


0

Response Number 3
Name: ken
Date: October 28, 2003 at 17:23:26 Pacific
Reply:

Thanks for the info, I'll let you know how things go!
Ken


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


cpu too slow crash probs with win98se ...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows 95/98 Forum Home


Sponsored links

Ads by Google


Results for: Trojan Horse - how to remove?

trojan horse, how to find to get rid of www.computing.net/answers/windows-95/trojan-horse-how-to-find-to-get-rid-of/11742.html

how to remove username/password? www.computing.net/answers/windows-95/how-to-remove-usernamepassword/150042.html

How to remove a start menu toolbar?? www.computing.net/answers/windows-95/how-to-remove-a-start-menu-toolbar/108109.html