Locating a problematic Trojan?
Discussion
I seem to have got some sort of Trojan on my home PC. My virus checker stops it from doing damage, but nonetheless it is still there.
Basically it is some form of trojan which keeps trying to replace my HOSTS file to prevent access to all sorts of things. But, I cant seem to find it anywhere!
Checked the registry etc, but no luck.
But the funny thing is that the virus checker is tripped on resume of the PC; not reboot or anything else. Anyone know what is run / started / executed on resume and where do I need to look?
Think I got this through an IE vulnerability so Firefox all the way now, but still need to get rid of this thing.
Suggestions?
Basically it is some form of trojan which keeps trying to replace my HOSTS file to prevent access to all sorts of things. But, I cant seem to find it anywhere!
Checked the registry etc, but no luck.
But the funny thing is that the virus checker is tripped on resume of the PC; not reboot or anything else. Anyone know what is run / started / executed on resume and where do I need to look?
Think I got this through an IE vulnerability so Firefox all the way now, but still need to get rid of this thing.
Suggestions?
Any idea as to the name of the trojan??
Try this (it's free!!) gets rid of a number of Trojans...
If you're concerned, it comes from McAfee, it gets updated every so often, so worth checking back..
http://vil.nai.com/vil/stinger/
hth
Try this (it's free!!) gets rid of a number of Trojans...
If you're concerned, it comes from McAfee, it gets updated every so often, so worth checking back..
http://vil.nai.com/vil/stinger/
hth
try getting "autoruns" from www.sysinternals.com. It shows where everything is starting from!
jimbro1000 said:
This sounds very similar to the problem I've been having. Locking down the hosts file has prevented extra problems but there is no doubt my machine is still infected but *nothing* is finding it...
Yeah, just noticed your thread - and mine keeps coming out of suspend too!!! I will try the stuff that you found out and see if it fixes it....
Oh the benefits of PH...
This may be more a problem for anti-virus software to solve, not anti-spyware. Have you tried running a different anti-virus program to compare results?
Does the antivirus software state what virus it has found?
One way to find it might be to bring up task manager (ctrl-alt-delete in win2k, xp....) and go through the list of processes and figure out which one doesn't belong. That gives you the file name of the program and a good start to ripping it out.
Misc notes:
If this is XP, try turning off your 'system restore' feature. It could be that the virus has told windows that it is an important system file and windows will check to see if it has been deleted and promptly restore it back.
In a recent test of various anti-spyware programs, including spybot, none of the programs dectected everything. At the end of the test the authors were advising to run several different anti-spyware programs to keep your system clean. God what a mess this has turned into.
Does the antivirus software state what virus it has found?
One way to find it might be to bring up task manager (ctrl-alt-delete in win2k, xp....) and go through the list of processes and figure out which one doesn't belong. That gives you the file name of the program and a good start to ripping it out.
Misc notes:
If this is XP, try turning off your 'system restore' feature. It could be that the virus has told windows that it is an important system file and windows will check to see if it has been deleted and promptly restore it back.
In a recent test of various anti-spyware programs, including spybot, none of the programs dectected everything. At the end of the test the authors were advising to run several different anti-spyware programs to keep your system clean. God what a mess this has turned into.
Never one to be prevented from doing things, I decided to take this one on.....
Anyway, rather nasty one which was spotted by HJT. As you might expect, it did all of the usual stuff. Locked the file, ran from Winlogon and used system restore to prevent itself from being deleted.
I tried everything, even DrDelete and KillBot. Each time it re-set itself (even with SR turned off!). Running out of ideas I was about to resort to NTFSDOS Professional to delete the file. Then I had a brain wave! Boot to safemode (its XP home) and set the permissions on the file to be Deny everything! Bingo.
Cant run it therefore HJT deletes everything correctly. File gone and rid of this scurge.....
But there is a next question - why on earth do these people write these things? What possess them to do this? Probably never get an answer to that I suppose, but its bloody annoying though....
Oh, and thanks for the help chaps, nearly forgot there!
Anyway, rather nasty one which was spotted by HJT. As you might expect, it did all of the usual stuff. Locked the file, ran from Winlogon and used system restore to prevent itself from being deleted.
I tried everything, even DrDelete and KillBot. Each time it re-set itself (even with SR turned off!). Running out of ideas I was about to resort to NTFSDOS Professional to delete the file. Then I had a brain wave! Boot to safemode (its XP home) and set the permissions on the file to be Deny everything! Bingo.
Cant run it therefore HJT deletes everything correctly. File gone and rid of this scurge.....
But there is a next question - why on earth do these people write these things? What possess them to do this? Probably never get an answer to that I suppose, but its bloody annoying though....
Oh, and thanks for the help chaps, nearly forgot there!
Well done!
I've always been rather reluctant to perform manual clean ups as I only ever seem to make things worse...
Still a bit bemused by my AV not picking it up until yesterday. Must have been infected for nearly two weeks and it is one they've known about for six months. Anyone have any ideas as to why the pattern files would abandon looking for an older virus?
I've always been rather reluctant to perform manual clean ups as I only ever seem to make things worse...
Still a bit bemused by my AV not picking it up until yesterday. Must have been infected for nearly two weeks and it is one they've known about for six months. Anyone have any ideas as to why the pattern files would abandon looking for an older virus?
Finding a similar problem myself... Anybody know any good software to find out which processes are trying to access a net connection?
Edited to add I'm a fool. A decent piece of firewall software should do...
>> Edited by kenny320 on Friday 29th April 09:52
>> Edited by kenny320 on Friday 29th April 10:10
Edited to add I'm a fool. A decent piece of firewall software should do...
>> Edited by kenny320 on Friday 29th April 09:52
>> Edited by kenny320 on Friday 29th April 10:10
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff




