Search : in
By :

How to get rid of trojan virus

Last answer on Sep 3, 2009 9:08:35 am BST ziggy7, on Feb 7, 2009 5:00:09 am GMT 
 Report this message to moderators

Hello,
i have a mischievous virus it is trojan n i cant get rid of it can someone tell me step mby step how its done please;-)

Configuration: Windows XP
Firefox 2.0.0.11

Best answers for « how to get rid of trojan virus » in :
Getting rid of Vundo Trojan Show Getting rid of Vundo Trojan What is a Vundo Trojan? How to remove a Vundo Trojan Manually Step 1: Locate the Trojan Step 2: Use Registry Editor to eliminate Registry Values Step 3: Using Command Prompt for Vundo unregistration Download...
How to get rid of Actulice/ No ModF/ Funk Popups ShowHow to get rid of Actulice/ No ModF/ Funk Popups Actulice is actually a Trojan that makes very annoying pop ups that will appear all over your screen. It starts with a small window that is displayed at the center of the screen and reads...
How to get rid of W32.Netsky ShowHow to get rid of W32.Netsky Symantec Security has developed a cleaning tool to clean the following the below mentioned variants of virus W32.Netsky@mm: W32.Netsky.B@mm W32.Netsky.C@mm W32.Netsky.D@mm W32.Netsky.E@mm W32.Netsky.K@mm...
How to get rid of SPY AXE? ShowHow to get rid of SPY AXE? Methods of elimination Deactivate System Restore Download Smitfraudix and Hoster Download and unzip smitfraudix Download and unzip Hoster Run SmitfraudFix.exe Spy Axe is a rogue application that pretends...
Download Clean Virus MSN ShowViruses meet hereafter a bit on the net by all thinkable means everywhere. After mails , supporting they attack instantaneous freight forwarding. Clean Virus MSN is a tool which discerns automatically the viruses which circulate on MSN Messenger....
Download Windows Error Message Creator ShowThe chains which alert on viruses do not work any more, then made more extremely. If you want to scare your colleagues or your friends on their computer, the best means is of their envoy a message of error. Windows Error Message Creator is a very...
The Sasser worm ShowIntroduction to the Sasser virus Appearing in May 2004, the Sasser virus (also known as the W32/Sasser.worm, W32.Sasser.Worm, Worm.Win32.Sasser.a, Worm.Win32.Sasser.b or Win32.Sasser) is a virus which exploits a security hole in the LSASS (Local...
Ascv - ascv.exe Showascv - ascv.exe The presence of the process ascv.exe (ascv) may indicate the presence of a Trojan horse. How do you get rid of ascv.exe? Here is a list of teps to help you disinfect your machine and learn about the mechanisms of viruses, worms,...
Igfxtray - igfxtray.exe Showigfxtray - igfxtray.exe The process igfxtray.exe (igfxtray) may indicate the presence of the Trojan horse Troj/PAdmin-A. How do you get rid of igfxtray.exe? Here is a list of tips to help you disinfect your machine and learn about the mechanisms of...

1

ocean_85, on Feb 7, 2009 6:36:55 am GMT
  • +2

HI,

try using malwarebytes..u can find it on this site also.

Reply to ocean_85

2

Keifermail, on Feb 8, 2009 11:27:54 pm GMT
  • +6

I am writing to express gratitude for Morphine on this forum for solving my problem. This invasive "virus/malware/painintheass" seems to be diffrent on every machine and it may take several tries to find the solution as I discovered. I also would like to try and figure out where the "bug" came from. I have related below two possible causes. Please others post their stories and let's see if we can come up with the vector.

I acquired this "virus/malware/headache" on 1/27/2009. My last download from Microsoft was a routine updating of Office 2007. I know this because when I tried to use system restore my last save point was the day before I updated Office. I do not believe that Office is the culprit but I would like to know what the last thing others downloaded before they acguired "the bug." A more likely cause would be my habit of occassionally watching videos on Pornhub. This may be TMI, but hey, if we are to figure out where this thing came from I will be the first to admit to frequenting Pornhub as a possibility. If others suspect the same please post your thoughts.

Now about this bug....

This thing is incredible!

It hijacks every browser on your computer- Explorer, Firefox, Chrome and Safari. When you attempt to Update Windows it sends you to a very good "fake Google page." Every click or search in the fake google page seems to add more malware and directs one to porn sites. i.e. Gay Porn (not that there is anything wrong with that) Just happens that I am straight. I also believe that this is the reason it is worse on some machines than others. I recognized the Google page as fake because I use iGoogle as my home page and there was no button for iGoogle. When I attempted to search is when it became very apparent. It sent you straight to the page it wanted to. It seems that the more you use this fake page the worst the infection becomes.

It doesn't stop at hijacking the browser, it also prevents your Antivirus from updating. I had Trend Micro orginally and went out and bought Kaspersky after being told that it was the best by the IT guys at work This thing shut down Kaspersky's like it owned it. (I had a Disk version of Kaspersky manufactured in Oct 2008. I do believe that had I had Kaspersky before and it was updated, instead of Trend Micro, I would have never caught the bug.) I found this forum yesterday morning Googling "virus hijacks browser and disables updates."

As Morphine sugested: I downloaded the free Trojan Remover 6.7.5. (It is free for 1st 30 days) Find it here:

http://www.simplysup.com/tremover/download.html

Then I ran it. It found the offending file and it stated that it needed to be deleted- which I did by clickin OK or something. I thought I had solved the problem and did nothing else other than attempt to update Kaspersky and Windows. Both failed before completing.

Whoever wrote this "bug" is a genuis, and a sadistic bastard! It is like the last boss fight in good Videogame, you can't kill it with just one weapon. It apprently hides in your RAM and attaches itself back into the registry. That is why you have to have SmitFraudFixTool. Find it here:

http://smitfraudfixtool.com/

This program will cost you unfortnately. I already had RegCure but it did not work- its not made to chase bugs. I paid $39.00 for it and can run it on three computers. Anyway, after running the Trojan Remover again and immediately afterwards running SmitFraudFixTool and cleaning out 3156 so called "bad files." I then updated Kaspersky and ran a system scan which finally put the noose on the damn thing for good. This forum was a godsend!

My computer is now running like a dream! Thank you Morphine for the solution. Please others post their battles with this Monster.

Reply to Keifermail

7

linkfutrue, on May 11, 2009 2:58:33 pm BST

The most easy way here.
try registr Easy.
this tool help you clean annoying trojan.
http://www.google.com/search?hl=en&newwindow=1&q=make1-pc-faster.com&btnG=Search

Reply to linkfutrue

3

karine555, on Feb 9, 2009 8:34:18 am GMT

Hi ziggy ;-)
have u beeen able to fix ur problem dear?????

Reply to karine555

4

Keifermail, on Feb 15, 2009 6:38:26 am GMT
  • +4

This thing is called the "Kido Worm" , "Downadup" and "Conficker." It began in Oct. 2008 but in December it evolved into a Superworm. Its ability to thwart any attempt to delete it and to spread via USB devices is confounding.

There is a lot of info out there if you Google these names. It is an interesting Worm as it seems to disable every defense before the victim can even launch a counter attack. It disables system restore, shuts off Microsoft updates, blocks Antivirus updates, hijacks the browser (Safari, Explorer, Chrome and Firefox) and finally it downloads more malicious software as it goes. It is impossible to give one set of instructions to remove the Virus as it is different on every machine.

The latest variant of the worm now lets it spread via thumb drives. It operates by copying itself in a random folder created inside the Recycler directory, which is used by the Recycle Bin to store deleted files, and creating an autorun.inf file in the root folder. The worm executes automatically if the Autorun feature is enabled.

Certain TCP functions are also patched to block access to security-related Web sites by filtering every address that contains certain strings. This makes it harder to remove because information about it is difficult to gather from an infected computer. Additionally, the sneaky little worm removes all access rights of the user, except execute and directory usage, to protect its file. Microsoft has created a removal tool for this worm, but if you are infected you must find an uninfected computer to download Microsoft's Malicious Software Removal Tool.

See the following link: http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx

If you have the Kido/Conficker worm you will no be able to link to the above link.

Microsoft states,
"If your computer is infected with the Conficker worm, you might be unable to download certain security products, such as the Microsoft Malicious Software Removal Tool or to access certain Web sites, such as Microsoft Update. If you can't access those tools, try using the Windows Live OneCare Safety Scanner. If that doesn't work, read the following Microsoft Help and Support articles on an uninfected computer. "

My advise is to get the removal tool on a brand new/clean USB device from another computer and then load it onto your computer. The surprising thing is that this thing started in Oct. and already has infected 12.9 million computers. Microsoft has offered a 250K reward to help catch the culprits that created this worm.

Hope this helps,

Keifer

Reply to Keifermail

5

wizkids, on Mar 2, 2009 12:21:51 pm GMT
  • +2

Trojan virus are very dangerous viruses and attacks different files on your computer and they are besically gotten from the internet.
A Trojan horse appears to be nothing more than an interesting computer program or file, The Trojan virus once on your computer, does not reproduce, but instead makes your computer vulnerable to malicious attacks by allowing them to access and read your files. This makes the virus extremely dangerous to your computer. This virus can be minimized when you avoid downloading unnecessary files and software’s, and only download software’s and files that you are sure of. This virus is an application that is installed in your computer and it adds itself to all user favorite folder and the current user favourite folder. Also it is in you program files.

If you want to remove this virus, you have to be very careful and use your common sense, for you to find it. So you have to try and identify one name that the virus uses, then use that name to get every other name that it may also be using to run.

Open my computer, double click drive C: double click document and settings, double click all users, and open my favourite folder look for the name of the virus. It might be virus scan.com. Select all the files related to virus scan.com and delete them. Do the same for all the user accounts in that computer. Also, look for the virus in your user account application data. Open document and settings and double click on all users , open application data also look for the virus there if you find it delete it and do same for all the other user account

Secondly click start, click run and type Regedit. Registry editor will open. Click the minus button beside my computer to close the tree view such that the registry editor looks like the one below. Click edit menu and click find in the menu. On the find box, type the name of the virus in the search box and press find next. You will see the registry file by the right pane. Make sure that it is the right file else do not delete because if you delete what you are not sure of you may delete an important registry entry that may cause crash of data lose. So make sure the file you are about to delete is name that the virus uses to run.

Make the search again until you have removed all the registry entries related to the virus. Download no adware from http://www.noadware.net and install it. Update the application and Use it to scan your computer, you will see all the viruses, their location, where they are installed on your computer. Because you are using a trial version, you will not be able to remove the viruses. Look at the items, their location, type, danger rate. For all the items that show severe, open the location shown in the location field and delete the files, e.g. C:\Documents and Settings\netways ltd\Application Data\antivirus scan.com. Do so for all other files that are flagged dangerous. Then rescan your computer again with NoAdware you will notice that items that you have remove manually will not be displayed again.

Furthermore click start, control panel double click add and remove program in the control panel. When the add and remove program window opens look for installed application relating to that virus, if you see any one uninstall it.
to read the full details with screen shorts visit http://online-computer-repairs.blogspot.com/2008/12/how-to-r­emove-desktop-virus.html

Reply to wizkids

6

master, on May 11, 2009 12:36:33 pm BST

Get a life, sorry get a anti virus software to skan and delete the viruses

Reply to master

8

carl Johnson, on Jul 16, 2009 8:53:02 am BST

I think someone really does need to get a life. These questions are asked by people with problems - and answered by people with the answers, so if anyone finds the need to just come here to make pointless remarks - well, what can i say ?? Get a life.

As for me - ive been attacked by the conficker worm, it ruined my PC, iv had to reformat. (it came through the up-2-date-antivirus too, so I for one, am really gratefull for theses answers.

Cheers guys.

Master...get a life.

(what is master short for i wonder)

Reply to carl Johnson

9

redskinsfan33, on Jul 16, 2009 6:57:40 pm BST
  • +5

Some viruses are tricky to remove as they will hijack your computer and not allow you to open virus scanners or use web browsing, before you attempt to download a virus scanner or anything do this

1) open task manager (ctrl + alt + del) and kill the .exe process for the virus, so for Antivirus System Pro, kill antivirussystempro.exe

2) go to run and then msconfig and uncheck anything that looks suspicious in the startup

Now you can go about downloading a good virus scanner to remove the virus or use your own virus scanner,

if none of that works, you cant find any .exe process or anything in msconfig then restart your computer in safemode with networking by tapping f8 on the load screen

you can do a free Virus Scan Download and read more removal guides

good luckk :)

Reply to redskinsfan33

10

 huz23, on Sep 3, 2009 9:08:35 am BST

Install windows vista or windows xp again then it will be ok.

Reply to huz23