Code Newbie
News     Forums     Search     Members     Sign Up    

My Code Newbie
Username

Password

Articles/Snippets
ASP Classic
ASP.NET
C
C#
C++
HTML / CSS
Java
Javascript
Linux / BSD
Perl
PHP
Python
Ruby
SQL
VB 6
VB.NET

C.N. Friends
  Planet Rome

Link to Us!
Code Newbie
  Code Newbie
    forums

Go Back   Code Forums > Systems > Windows

Reply
 
LinkBack Thread Tools Display Modes
Old 10-07-2005, 06:19 AM   #1 (permalink)
Molly
Registered User
 
Molly's Avatar
 
Join Date: Sep 2005
Location: London
Posts: 8
Molly is on a distinguished road
How do I get rid of a Trojan?

Hi I've got stuck, my computer has been infected with a Trojan Horse virus. I know this because my Virus detecter tell me every 15 seconds. It says it can't do anything about it but identify the file as : C:/system32.exe I have tried to go in and delete it myself or change it names, but apparently I don't have any rights on that file.

I'm kind of stuck, I don't want to turn off my anti Virus but It just won't shut up. I don't think I have the CD to rebuild the machine and I don't really want reformat the hard drive, god know what I would loose.

Can anyone suggest anything?

Thanks Molly
Molly is offline   Reply With Quote
Old 10-08-2005, 04:54 AM   #2 (permalink)
DJMaze
Senior Contributor
 
DJMaze's Avatar
 
Join Date: Mar 2005
Posts: 651
DJMaze is on a distinguished road
Which virusscanner ?
Which trojan ?
Windows version ?
DJMaze is offline   Reply With Quote
Old 03-16-2006, 05:39 AM   #3 (permalink)
Smith
Registered User
 
Join Date: Mar 2006
Posts: 4
Smith is on a distinguished road
Try NOD 3.2 - IMO it's the best!
Smith is offline   Reply With Quote
Old 03-16-2006, 08:03 AM   #4 (permalink)
DJMaze
Senior Contributor
 
DJMaze's Avatar
 
Join Date: Mar 2005
Posts: 651
DJMaze is on a distinguished road
Start -> Run -> regedit

In the registry editor tree browse to:

HKEY_LOCAL_MACHINE -> SOFTWARE -> Microsoft -> Windows -> CurrentVersion -> Run

Look in there for strange entries.
Also check RunOnce and RunOnceEx

Other pesky spy/trojan stuff even gets more integrated thru (Internet) Explorer.
Thanks to the integration of IE inside Windows OS it made it easier for virusses, trojans and spyware to infect the machine and stay infected.

For example "ActiveDesktop" can be manipulated to force and stay active thru an registry entry named "ForceActiveDesktopOn" in:
HKEY_USERS\S-x-x-xx-xxxxxxx-xxxxxxx-xxxxxx-xxxx\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer
(xxxx is random number)
That in combination with other registry entries (like about:home manipulation, etc.) it will make your OS a real spam system.

As you can see the windows registry is the most important thing to execute this stuff so to remove trojans and stuff you must delete the executables but also fix the registry.

To check this all manualy you must know your system very well or you're screwed.
A good thing to start with is to have the taskmanager open (Ctrl+Shift+Esc) to see if there are unknown processes. When you have no clue compare the list with the list of a uninfected system. That way you can see which unknown exe's are running from c:\, c:\windows, or c:\windows\system32
DJMaze is offline   Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Getting rid of tables my !@#$ Belisarius HTML, XML, Javascript, AJAX 8 02-21-2005 10:47 AM
Trojan targets user's financial information redhead Code Newbie News 0 07-01-2004 05:52 AM
Trojan turns victims into DDoS, spam zombies redhead Code Newbie News 1 07-17-2003 04:51 PM


All times are GMT -8. The time now is 11:50 PM.


Powered by vBulletin® Version 3.7.0
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0 RC8





Copyright © 2000-2008, Milano Interactive
Web Hosting provided by Portal 360 Web Hosting