Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 10-29-2009, 02:27 PM   #1 (permalink)
Registered User
 
Join Date: Jul 2008
Posts: 19
OS: Windows XP SP2


Is this a Valid Way to Get Rid of a Trojan?

Funny (not!) thing happened to me today. I clicked on a Google link and it took me to an entirely irrelevant page. I smelled a rat immediately, and a full system scan with F-Secure revealed the Trojan-PWS.Win32.Kates.c in a [can't remember the name].obx file in C:/Windows. I attempted to delete it (through F-Secure) and yes, I'm sure you know the rest. It replicated itself. It did that also when I tried to rename it. Another symptom was that attempting to open the registry (either by double-clicking regedit or by entering 'regedit' in Run) resulted in the taskbar disappearing for a second or two - without registry editor ever running.

I read numerous threads with similar problems and they all suggest the combofix method. I tried something else. I opened the infected file with wordpad, deleted all the contents and saved it with the same name. It didn't replicate itself, it shows 0 KB size (of course), and F-Secure doesn't recognize it as a virus (of course). Regedit works. Full system scan with F-Secure doesn't find anything anywhere. After a couple of reboots, nothing has changed. File still 0 KB, regedit works, no viruses reported.

Is it safe to assume the problem is taken care of? I find it hard to believe - where is the initiator of the replication action?

Is there a specific registry entry (or anything else) I should check to see if there is still an infection lurking?

Thanks!
__________________
--
Windows XP SP2, Desktop PC (HP), USB mouse, PS2 keyboard, 512 RAM, MSI-AMETHYST-M, AMD Athlon 64 3500+
Gyroscope is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 10-29-2009, 03:00 PM   #2 (permalink)
Moderator/ Rangemaster TSF Academy; Analyst, Security Team; Oor Wullie; TSF Surgeon and Resident Comic
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 25,377
OS: Win XP Pro SP3 / Win 7 Pro

My System

Blog Entries: 10
Re: Is this a Valid Way to Get Rid of a Trojan?

Hi

Quote:
Is it safe to assume the problem is taken care of? I find it hard to believe - where is the initiator of the replication action?
Therein often lies the problem. Although you may have disabled this one bad file, there may be others hidden away (an AV will not detect everything) - including the infector or the main loading point.

We cannot give you any advice until you start here and follow the instructions.

NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help

Do not post your logs back in this thread - follow the guidance in the above link!

If you have problems with any of the steps, simply move on to the next one and make a note of the problem in your reply.

Please note that the Security Forum is always busy, so I would ask for your patience while waiting for a reply - it may take a few days.
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.



PC Safety & Security::PC running a bit slow?::Donate::Photographers Corner
Glaswegian is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 02:48 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85