Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:07:56 Have got a Trojan DL programme embedded in system 32 within windows.
Ill be fucked if I can get the little fucker out, as the programme is constantly being used by windows and making it undeletable. have tried the usual, running anti virus and anti spyware in safe mode etc, but cant seem to get rid of it and it's trowing warnings up left right and centre. Any ideas chaps (sonic, JJ ????) Title: Techi help Post by: jayohaitchenn on Tuesday, December 4, 2007, 19:10:49 if you know wht it is called, start up in safe mode, then check your processes in task manager. Find the process called whatever it is and end it, then run your virus scan or whatever...
try that :D Title: Re: Techi help Post by: BANGKOK RED on Tuesday, December 4, 2007, 19:16:36 Quote from: "Fred Elliot" Have got a Trojan DL programme embedded in system 32 within windows. Ill be fucked if I can get the little fucker out, as the programme is constantly being used by windows and making it undeletable. have tried the usual, running anti virus and anti spyware in safe mode etc, but cant seem to get rid of it and it's trowing warnings up left right and centre. Any ideas chaps (sonic, JJ ????) I had something a similar quite some time back Fred, and the reason that no virus programme was able to remove it was that it was embedded into the registry (Hence always in use by a windows programme). I google searched the virus and eventually found a way to delete it, which meant literally going into the registry myself and deleting it, after having to find which registry key it had latched itself onto. A real bugger which took alot of time, but I got there in the end. Sorry I can't be more specific but s I said it really was some time ago. Hope this helps. Just a quick edit, becuase I forgot to emphasize that it took ONE HELL OF ALOT OF TIME. Title: Techi help Post by: Lash_sumthin on Tuesday, December 4, 2007, 19:17:09 google the trojan name too, places like the trend micro site have full instructions on how to remove most of them
http://www.trendmicro.com/vinfo/virusencyclo/ EDIT - what BG beat me to really - the above site should tell u where to go in the registry if thats indeed (and probably) necessary Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:18:29 Thanks lads
Title: Techi help Post by: sonic youth on Tuesday, December 4, 2007, 19:18:50 if it's embedded itself in the registry, you'll probably need to remove it manually...
CCleaner might do it for you though, get it here (http://www.ccleaner.com/). what's the trojan called? Title: Techi help Post by: Peter Venkman on Tuesday, December 4, 2007, 19:20:03 What is the exact name of the trojan?
Some can be total bastards to remove, I do have some trojan removal programs I can email you but they will only work with certain types of trojans, and some need editing of the regedit in safe mode afterwards. Not really difficult but not for the novice user. Most of it is common sense stuff. Let us know the name and I will investigate for you Fred. Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:22:44 TR/Dldr.Agent.fnw.1
THAT'S THE FUCKER Title: Techi help Post by: Peter Venkman on Tuesday, December 4, 2007, 19:26:45 http://www.avira.com/en/download/index.html
They say they can remove it for you with a free download fred, give that a go first and then report back! Another option.....download the free trial of Norton Internet Security, remove the trojan...if it can find it...then uninstall the Norton www.norton.com has it for free trial. Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:29:16 Thats the anti virus I use as standard JJ, wont even touch it mate.
Have tried it all ways, even in safe mode Title: Techi help Post by: Lash_sumthin on Tuesday, December 4, 2007, 19:30:03 yeah surprisingly very little on it but that avira product appears to have updated its definitions to deal with it
Title: Techi help Post by: Simon Pieman on Tuesday, December 4, 2007, 19:32:55 Fred. Sometimes the fuckers embed themselves in your system restore - so it wont get removed unless you disable system restore. If nothing else works you might need to give it a go.
Unfortunately you lose your restores points doing this, but then again if you need to clean it up it's worth it. You'll need to disable sys restore and do what Jayohfuckface said (safe mode etc) Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:37:47 Quote from: "Si Pie" Fred. Sometimes the fuckers embed themselves in your system restore - so it wont get removed unless you disable system restore. If nothing else works you might need to give it a go. Unfortunately you lose your restores points doing this, but then again if you need to clean it up it's worth it. You'll need to disable sys restore and do what Jayohfuckface said (safe mode etc) Wont even let me do a SR Si Ill try it through applications in the task manager Title: Techi help Post by: Simon Pieman on Tuesday, December 4, 2007, 19:39:31 Have you tried turning off system restore....may as well if it wont let you do it anyway
Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:40:44 Quote from: "Si Pie" Fred. Sometimes the fuckers embed themselves in your system restore - so it wont get removed unless you disable system restore. If nothing else works you might need to give it a go. Unfortunately you lose your restores points doing this, but then again if you need to clean it up it's worth it. You'll need to disable sys restore and do what Jayohfuckface said (safe mode etc) How do I disable SR Si ? Title: Techi help Post by: Simon Pieman on Tuesday, December 4, 2007, 19:43:04 You on XP?
Right click on my computer and there's a system restore tab. There's a tick box in there to turn it off. You'll need to shut down and then boot in safe mode and use removal tools/anti-virus & spyware etc that say they can remove it. Before you do that - do you have more than one anti-virus installed? Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:45:11 just the one mate
got anti spy running concurrently Title: Techi help Post by: Simon Pieman on Tuesday, December 4, 2007, 19:47:11 Well have a go at the sys restore idea and if it don't work then chuck the computer away (just kidding, there should be a fix).
Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 19:57:44 ill do it later
footie and pintage now Title: Techi help Post by: Simon Pieman on Tuesday, December 4, 2007, 19:58:39 If you break it cos you're pissed it ain't my fault :mrgreen:
Title: Techi help Post by: Fred Elliot on Tuesday, December 4, 2007, 20:01:43 :mrgreen:
|