HardwareHeaven.com

HardwareHeaven.com

Looking for the skin chooser?
 
 
  • Home

  • Hardware reviews

  • Articles

  • News

  • Tools

  • Gaming at HardwareHeaven

  • Forums

 

Go Back   HardwareHeaven.com > Forums > Hardware and Related Topics > Hardware Discussion & Support


Hardware Discussion & Support Discuss your computer - its components or ANY hardware, past/current/future you want, or ask our forum experts if you have a general problem with your hardware.

Reply
 
Thread Tools
Old Oct 23, 2002, 08:37 PM   #1
DriverHeaven Junior Member
 
Join Date: Jul 2002
Location: Ohio
Posts: 40
Rep Power: 0
Joneser is on a distinguished road

Default Post IRC backdoor trojan

Does anyone know how to get rid of this trojan. It is attached to Windows/explorer.exe. I am running XP pro.

Any help would be greatly appreciated.

Joneser
__________________
[color=yellow]<<Athlon XP 1800>><<512 Infin. PC2100>><<ECS K7S5A>><<GXP120 80 Gig>><<Geforce 3 Ti500>><<Turtle Beach Santa Cruz>><<56x CD-Rom>><<40x12x48x Lite-On>><<400 Watt Mofo. PS.>><<WinXP Pro>>[/color]
Joneser is offline   Reply With Quote


Old Oct 24, 2002, 02:05 AM   #2
A Legend in Underwear
 
UberLord's Avatar
 
Join Date: May 2002
Location: Unknown
Posts: 5,255
Rep Power: 0
UberLord will become famous soon enough

Default Post

Run an upto date anti-virus tool. AVG make a free one.
__________________
Gentoo Linux - Developer (baselayout)
Read my blog

"I contend that we are both atheists. I just believe in one fewer god than you do. When you understand why you dismiss all the other possible gods, you will understand why I dismiss yours."
Stephen Roberts
UberLord is offline   Reply With Quote
Old Oct 25, 2002, 12:29 AM Threadstarter Thread Starter   #3
DriverHeaven Junior Member
 
Join Date: Jul 2002
Location: Ohio
Posts: 40
Rep Power: 0
Joneser is on a distinguished road

Default Post Re:

Quote:
Originally posted by UberLord
Run an upto date anti-virus tool. AVG make a free one.
I ran the program fromAVG w/ no luck. The program didn't even turn up the trojan. Is it possible this is a false hit by Norton?? I'm open to all options, formatting my hard drive just doesn't seem like very much fun

Any other ideas
__________________
[color=yellow]<<Athlon XP 1800>><<512 Infin. PC2100>><<ECS K7S5A>><<GXP120 80 Gig>><<Geforce 3 Ti500>><<Turtle Beach Santa Cruz>><<56x CD-Rom>><<40x12x48x Lite-On>><<400 Watt Mofo. PS.>><<WinXP Pro>>[/color]
Joneser is offline   Reply With Quote
Old Oct 25, 2002, 01:16 AM   #4
Get off my lawn!
 
Erroneus's Avatar
 
Join Date: Aug 2002
Location: Denmark
Posts: 13,417
Rep Power: 119
Erroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seen
System Specs

Default Post Symantec

go to http://securityresponse.symantec.com/ and find your virus, they properly have guide how to remove it..
__________________
Erroneus is offline   Reply With Quote
Old Oct 25, 2002, 01:34 AM   #5
A Legend in Underwear
 
UberLord's Avatar
 
Join Date: May 2002
Location: Unknown
Posts: 5,255
Rep Power: 0
UberLord will become famous soon enough

Default Post Re:

Quote:
Originally posted by Joneser
I ran the program fromAVG w/ no luck. The program didn't even turn up the trojan. Is it possible this is a false hit by Norton?? I'm open to all options, formatting my hard drive just doesn't seem like very much fun

Any other ideas
You mention Norton - I take it ur running Norton AntiVirus 2002 or later. So it detects the virus but cannot remove it?

Hmmm. Try disabling heurstic (spelling?) checking as this does pattern matching and can produce a few false positives. Saying that, I use Norton at home occasionally (normally I don't run anti-virus) and McAfee at work. Norton's yet to throw up a false positive at it's maximum settings, but McAfee throws up loads of false positives.
__________________
Gentoo Linux - Developer (baselayout)
Read my blog

"I contend that we are both atheists. I just believe in one fewer god than you do. When you understand why you dismiss all the other possible gods, you will understand why I dismiss yours."
Stephen Roberts
UberLord is offline   Reply With Quote
Old Oct 25, 2002, 02:43 AM   #6
JAV
Banned
 
Join Date: Jul 2002
Location: California, USA
Posts: 283
Rep Power: 0
JAV is on a distinguished road

Default Post

Just a thought: Try deleting all your .~tmp (temporary) files & scrub your cookies (sounds funny, don't it) & cached files. Then reboot & run the AV again. You may then be able to remove it & it won't re-install.

You can also try 'System Mechanic' & run the registry scan & see if the Trojan is in there & remove it. Then reboot & run AV again.

Can't say for sure these *will* solve your problem, but it couldn't hurt anyway & is easier than reformatting. You'll have to sign in @ all your regular sites (DH) when you visit because your cookies will be gone & you won't be reconized.

HTH,

JAV
GBA!
JAV is offline   Reply With Quote
Old Oct 25, 2002, 08:54 PM   #7
DriverHeaven Founder
 
Join Date: May 2002
Posts: 32,480
Rep Power: 179
Zardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refuteZardon has a reputation beyond refute

Default Post

http://www.anti-trojan.net/en/home.aspx
Zardon is offline   Reply With Quote
Reply

Thread Tools