• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Stubborn Trojans

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

situman

Member
Joined
Sep 18, 2003
Anyone know how to remove Trojans that cannot be removed by Antivirus softwares? I also scanned with spyware softwares and etc. It never goes away. I tried looking for the physical file, but it doesnt show up. HELP guys.
 
Boot from a guaranteed uninfected boot medium. A Knoppix CD would be a very good way or, perhaps a PEBuilder CD. Then go to your harddisk and look for the trojan binary.
 
Must resist condom joke.....arrgggghhhhhhhh

Seriously, does your antivirus detect it and not remove it or does it not even detect it. A couple things you may want to try is scanning in SAFE MODE, inspecting the registry for suspicious entries, using HIJACK THIS! to find suspicious entries and using MSCONFIG (if running XP) to shut down anything suspicious at start-up.
 
McAfee picks it up, but it seems to replicate itself. I disable it in MSCONFIG and a new version pops up. McAfee sees it as trojan and it can remove the replications, but it cannot remove the main file. I was finally able to get rid of it by uninstalling a program www.Pctuneup.com or some **** like that installed in my comp without my permission.
 
just a small note: MSCONFIG is not just for windows XP. it works in me, 98, and win2k.
win2k just needs it installed and isnt packed with it.
 
somthingQQQ. but its all gone now i hope after i uninstalled everything.
 
Alot of the newer trojans and spyware will run two processes. The two processes will check on each other and even if you manage to end one, the other will start it back up. Also if you edit the registry/msconfig, the program will continually check to see if its "run" line is in the registry. Best way to remove anything is to boot up into safemode. If for some reason safe mode doesn't work, then I like to edit the registry manually or using hijack this, then right after I make the changes, I pull the plug on the system then reboot. This way the programs have no hope of undoing my work.
 
thanks for the responses guys. as of now there doesnt seem to be any signs of the damn thing left.
 
Back