Go Back   Technibble Forums > Technical Discussions > Security, Viruses and Trojans

  Technibble Sponsor
Need an IT Service Management Software? - Download Free Trial Now

CommitCRM is a complete software solution that helps you better manage your service, sales and business processes.
  • Complete Solution offering tickets, assets, tracking & dispatching, contract management & CRM, billing, knowledge base, reports & sales opportunities.
  • Priced for small businesses – affordable owned licenses with no recurring charges.
  • Easy to setup & learn – be up and running immediately.
  • Supports continuous service for office and remote services.
  • FREE Support, that’s friendly and personal.
Get the fully functional 30-day free trial now! Only two minutes to install.


Closed Thread
 
Thread Tools Display Modes
  #1  
Old 07-07-2007, 01:31 AM
robart robart is offline
Junior Member
 
Join Date: Jul 2007
Posts: 6
robart is on a distinguished road
Default I have a Trojan!!

I got this Trojan Virus from a 'Noble Poker' program I haven’t used in years. My Norton Anti-Virus and XsoftSpySE wont get rid of it. Is there anyone out there that can help me remove it before my computer crashes?
  #2  
Old 07-07-2007, 12:46 PM
Buzz's Avatar
Buzz Buzz is offline
Junior Member
 
Join Date: Jun 2007
Location: Mississippi
Posts: 26
Buzz is on a distinguished road
Default

Hey Robart

Try KillBox you can get it here...http://killbox.net/

KillBox is a tool to delete in-use files, if the file is running, KillBox will attempt to end the process (close the running file) and delete it.

Enter the location of the file and select the option you wish to kill / delete or replace the file with.

The KillBox site also has documentation on the use of the program if you need that information.

I have got rid of a few Trojans with this.

-Buzz

Last edited by Buzz; 07-07-2007 at 12:48 PM.
  #3  
Old 07-07-2007, 05:25 PM
Mac's Avatar
Mac Mac is offline
Member
 
Join Date: Apr 2007
Location: Sydney.au
Posts: 55
Mac is on a distinguished road
Default

One thing with malware, they all have to start up again after the computer is rebooted. Find the start up entry and delete it. No more trojan.
You say it’s old so it’s probably a run key in the registry or it’s installed as a service. Could be an active x key which all the kids use now. Could be in a number of places. If you know the name of the executable file search the registry for it.
If you don’t know what your doing forget everything I just said or you could mess up your computer. If all else fails…. Google = God … ask and yi shall receive
  #4  
Old 07-07-2007, 05:33 PM
Blues's Avatar
Blues Blues is offline
Senior Member
 
Join Date: Jun 2006
Location: Tennessee, US
Posts: 1,171
Blues is on a distinguished road
Send a message via AIM to Blues Send a message via MSN to Blues Send a message via Yahoo to Blues
Default

I used to delete things by rebooting in safe mode after getting software to ID the file. I would reboot into safe mode with command prompt and from there delete as nothing has been called to start up yet so you have exclusive access to most the files. Haven't done it in a while as haven't had a need.
  #5  
Old 07-08-2007, 08:53 PM
Bryce W's Avatar
Bryce W Bryce W is online now
Administrator
 
Join Date: Feb 2006
Location: Melbourne, Australia
Posts: 1,600
Bryce W is on a distinguished road
Default

Try killbox as Buzz said, if you need some help on how to use it, check out this tutorial:
http://www.technibble.com/delete-tho...lbox-tutorial/
__________________
Owner and Admin of Technibble - If you have a problem with any user, they are flaming/being elitist/making snide comments etc.. Press the report button which is on the top right of every post. This will highlight the post in an admin area for staff to see and deal with.

Check out Technibbles twitter: http://www.twitter.com/technibble
  #6  
Old 07-10-2007, 12:27 AM
marina_meggy marina_meggy is offline
Junior Member
 
Join Date: Jul 2007
Posts: 2
marina_meggy can only hope to improve
Default

I recommend you to download the free program called Spy ware sweeper from <URL Removed> This is one of the very few tested anti-spy ware programs that can help you to remove the Trojan successfully. You would find detailed instructions at the site

Last edited by Bryce W; 07-20-2007 at 07:59 PM.
  #7  
Old 07-10-2007, 12:55 PM
Buzz's Avatar
Buzz Buzz is offline
Junior Member
 
Join Date: Jun 2007
Location: Mississippi
Posts: 26
Buzz is on a distinguished road
Default

Do not download the Program that marina_meggy recommends because it is a Rogue program (a fake spyware remover and is actually malware).

Here is a little information on it..

Spyware Sweeper is a rogue antispyware program that is often downloaded and installed by Trojans, through browser security exploits, or via other nefarious mechanisms. SpywareSweeper launches on Windows startup and may generate excessive popup adverts. It will also display notifications of imaginary security risks in its attempts to get the user to purchase the full version. This program can be extremely difficult to remove manually, and will continue to try to recreate itself. Spyware Sweeper is from the same family as IGetNet.

This program is not to be confused with Spysweeper from Webroot.. as they would like it to be confused with.

Always do research on Anti-Spyware and Virus programs before installing them, as there are many Rogue programs for download on the Internet.

-Buzz

Last edited by Buzz; 07-10-2007 at 01:05 PM.
  #8  
Old 07-10-2007, 09:03 PM
Bryce W's Avatar
Bryce W Bryce W is online now
Administrator
 
Join Date: Feb 2006
Location: Melbourne, Australia
Posts: 1,600
Bryce W is on a distinguished road
Default

Locked the topic. Keep this thread around for example purposes of this type of rogue program spreading.
__________________
Owner and Admin of Technibble - If you have a problem with any user, they are flaming/being elitist/making snide comments etc.. Press the report button which is on the top right of every post. This will highlight the post in an admin area for staff to see and deal with.

Check out Technibbles twitter: http://www.twitter.com/technibble
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:09 PM.


Powered by vBulletin®
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.