PDA

View Full Version : Trojan_Backdoor_Retro64



asmithz
07-11-2005, 04:28 AM
Dunno how it keeps getting on my computer, but i want to know how to stop it. ;)

Afronaut
07-11-2005, 04:57 AM
Clean ReInstall + all patchess is teh 99% way, there's a little chance your install CD is fuckt
if you made it yourself. If you reinstall, remember it takes about a few minutes of unpatched windows
to get infected on the net.
I mean, faster than one can DL critical updates.
Thats why its usefull to have/make slipstreamed windows cd.
More info n the guides section.

Some software like TDS (http://tds.diamondcs.com.au/) could maybe remove it for good.
(Has a memory scasnner too, for tracking....)

I can think atleast 2 ways of that worm coming pack.
1. Exploits. To avoid this, run the security updates. (And no wmp10 is not a security update, its justa crappy player.)
2. Windows File Protection, the worm/wiri is hiding on dll-cache or somewhere,
you think you removed it but windows will automatically reinstall it for you.
I thats one of the default things malware does, using windows automated
things to re-appear.
Booting to Safe Mode and scanning + removing helps,
but it is crucial to understand where the shitz is coming from.

Of course, there might be something im completely missing,
just woke up...

ps.
if you want more specific help, you need to post what kind of PC you have,
what Antiapps, OS etc. stuff...

:D

Skiz
07-11-2005, 06:25 AM
I though maybe this was for Trojan Backdoor condoms. :shifty: :naughty:





:sadwalk:

S!X
07-11-2005, 06:57 AM
I though maybe this was for Trojan Backdoor condoms. :shifty: :naughty:





:sadwalk:

I dont believe trojans are "Soft" ware. :blink:

Snee
07-11-2005, 02:52 PM
Look for processes that look weird, and google any you don't recognize.

If it's one of them, turn it off, then remove the virus. In my experience, the ones that keep coming back are reinstalled by a running process.

It's prolly stuck in your system restore backups as well, so you might want to turn them off after the trojan is gone.

Run an online scanner as well as your own.

asmithz
07-11-2005, 09:50 PM
I just reformatted, I think Afronaut it was reinstalling itself off a dll-cache. I just couldn't find it, so i said screw it and reformatted. Now that it reformatted, it fixed other probelm too, where it would just restart out of no where.

Backed up everything on my other hard drive, so everthing is good. Thanks for the help tho... :)

Afronaut
07-11-2005, 10:21 PM
Look for processes that look weird, and google any you don't recognize.

If it's one of them, turn it off, then remove the virus. In my experience, the ones that keep coming back are reinstalled by a running process.

It's prolly stuck in your system restore backups as well, so you might want to turn them off after the trojan is gone.

Run an online scanner as well as your own.

Yes, the first step which I forgot to mention is,
it needs to be shut down, if the worm is running. Just a Snny said.
Cuz it will re-install itself from memory no matter if you remove it.

There's the wicked ones that dont show up on Process lists etc.
Due to the way Windows is built ie. M$ automated things, hiding things from you
it can be difficult to find the worm.

Since you re-installed the OS, be sure the worm is not on any of your
backups of other files you made.

:D

Snee
07-11-2005, 10:58 PM
Look for processes that look weird, and google any you don't recognize.

If it's one of them, turn it off, then remove the virus. In my experience, the ones that keep coming back are reinstalled by a running process.

It's prolly stuck in your system restore backups as well, so you might want to turn them off after the trojan is gone.

Run an online scanner as well as your own.

Yes, the first step which I forgot to mention is,
it needs to be shut down, if the worm is running. Just a Snny said.
Cuz it will re-install itself from memory no matter if you remove it.

There's the wicked ones that dont show up on Process lists etc.
Due to the way Windows is built ie. M$ automated things, hiding things from you
it can be difficult to find the worm.

Some proggies, like spybot, will let you have a look at stuff that starts with windows, with a bit of luck you can find some hidden stuff there.

asmithz
07-11-2005, 11:01 PM
Since you re-installed the OS, be sure the worm is not on any of your
backups of other files you made.:D


First thing i did, its gone. :D