Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I am working on a heavily infected Dell. 2.4GHz with XP Home, no service packs. I managed to remove 16 of the 17 viruses on the PC leaving one that Norton identifies as a Trojan Horse. That's it, nothing more. I've tried the conventional removals recommended by Symantec.
The Trojan manifests itself as an exe file in the System 32 folder. I cannot delete the file as it says it's in use. Even in safe mode. I even tried hooking the hard drive up to a second PC and it says the file is write protected and will not let me delete it.
The file also changes it's name quite frequently.
Help me Obi-wan Kenobi, you're my only hope!
~TR
Alter Ipse Amicus

Time Rider, here are some options for you:
1. Find the root of where the trojan is starting up from, stop it from starting up, remove the trojan.
2. Boot your computer using ERD Commander, remove the trojan.
3. Boot from a Knoppix disc, remove the trojan.Check to make sure you aren't running any rootkit malware. Go to www.sysinternals.com and get the Rootkit Revealer tool. Many times viruses and trojans hide themselves using rootkits.
There are 10 types of people in the world, those who know binary, and those who don't.

Do the following:
Run regedit
Go to Hkey-Current user
Then go to software
Microsoft
Current version
RunFind the path that the trojan uses to start up, then edit it to point away from the trojan (preferably to a blank).
Then open notepad and overwrite the trojan, for example if the trojan is gmbh.exe save the notepad file as gmbh.exe(It should work, been a while since I used Windows to be honest, but I have done that a number of times with success).

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |