Computing.Net > Forums > Windows XP > Trojan Horse

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Trojan Horse

Reply to Message Icon

Name: Time Rider
Date: September 26, 2005 at 17:39:16 Pacific
OS: XP Pro
CPU/Ram: Intel 3.0/1GB DDR
Comment:

I am working on a heavily infected Dell. 2.4GHz with XP Home, no service packs. I managed to remove 16 of the 17 viruses on the PC leaving one that Norton identifies as a Trojan Horse. That's it, nothing more. I've tried the conventional removals recommended by Symantec.

The Trojan manifests itself as an exe file in the System 32 folder. I cannot delete the file as it says it's in use. Even in safe mode. I even tried hooking the hard drive up to a second PC and it says the file is write protected and will not let me delete it.

The file also changes it's name quite frequently.

Help me Obi-wan Kenobi, you're my only hope!

~TR

Alter Ipse Amicus



Sponsored Link
Ads by Google

Response Number 1
Name: computingMonk
Date: September 26, 2005 at 18:09:12 Pacific
Reply:

Time Rider, here are some options for you:

1. Find the root of where the trojan is starting up from, stop it from starting up, remove the trojan.
2. Boot your computer using ERD Commander, remove the trojan.
3. Boot from a Knoppix disc, remove the trojan.

Check to make sure you aren't running any rootkit malware. Go to www.sysinternals.com and get the Rootkit Revealer tool. Many times viruses and trojans hide themselves using rootkits.

There are 10 types of people in the world, those who know binary, and those who don't.


0

Response Number 2
Name: Chxta
Date: September 26, 2005 at 23:04:13 Pacific
Reply:

Do the following:

Run regedit
Go to Hkey-Current user
Then go to software
Microsoft
Current version
Run

Find the path that the trojan uses to start up, then edit it to point away from the trojan (preferably to a blank).
Then open notepad and overwrite the trojan, for example if the trojan is gmbh.exe save the notepad file as gmbh.exe

(It should work, been a while since I used Windows to be honest, but I have done that a number of times with success).


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: Trojan Horse

trojan horse virus www.computing.net/answers/windows-xp/trojan-horse-virus/91895.html

trojan horse www.computing.net/answers/windows-xp/trojan-horse/81553.html

Virus Trojan horse Keybiz.A www.computing.net/answers/windows-xp/virus-trojan-horse-keybiza/83387.html