Approve the Cookies
This website uses cookies to improve your user experience. By using this site, you agree to our use of cookies and our Privacy Policy.
OK
Forums  •   • New posts  •   • RTAT  •   • 'Best of'  •   • Gallery  •   • Gear
Guest
Forums  •   • New posts  •   • RTAT  •   • 'Best of'  •   • Gallery  •   • Gear
Register to forums    Log in

 
FORUMS General Gear Talk Computers 
Thread started 12 Mar 2009 (Thursday) 13:58
Search threadPrev/next
sponsored links (only for non-logged)

Trojan Horse help needed

 
Roy ­ C
Goldmember
Avatar
2,088 posts
Likes: 21
Joined Aug 2005
Location: N.Devon, UK
     
Mar 12, 2009 13:58 |  #1

Somehow I have picked up a Trojan horse BackDoor Agent and it is driving me nuts. I always keep AVG up to date and also use Ccleaner on a very regular basis. I also use a registry scanner/cleaner regularly.

AVG's Resident Shield is picking up the BackDoor agent in the file C\windows\System32\use​rinit.exe which is a genuine windows file and cannot be deleted or healed - It is also turning off the Windows Firewall (which I turn back on again).

Anyone know how to get rid of this virus ?

P.S. when I run a full AVG scan it does not pick anything up


TOP BIRD SHOTS (external link)
MY PHOTOSTREAM (external link)

500px gallery (external link)

  
  LOG IN TO REPLY
In2Photos
Cream of the Crop
Avatar
19,813 posts
Likes: 6
Joined Dec 2005
Location: Near Charlotte, NC.
     
Mar 12, 2009 14:02 |  #2

Have you googled the trojan name for removal instructions?


Mike, The Keeper of the Archive

Current Gear and Feedback

  
  LOG IN TO REPLY
Roy ­ C
THREAD ­ STARTER
Goldmember
Avatar
2,088 posts
Likes: 21
Joined Aug 2005
Location: N.Devon, UK
     
Mar 12, 2009 14:15 |  #3

In2Photos wrote in post #7510238 (external link)
Have you googled the trojan name for removal instructions?

Yep, i have googled myself to death for a couple of days trying to find a solution but have got nowhere, the solutions either do not work or they do not make sense.


TOP BIRD SHOTS (external link)
MY PHOTOSTREAM (external link)

500px gallery (external link)

  
  LOG IN TO REPLY
overclicker
Member
98 posts
Joined Jun 2008
     
Mar 12, 2009 15:47 |  #4

Roy C wrote in post #7510209 (external link)
Anyone know how to get rid of this virus ?

P.S. when I run a full AVG scan it does not pick anything up

Well, you at least you're getting what you paid for then... :)

Try the Kaspersky free online virus scanner (external link) and see if that'll zap it for ya.




  
  LOG IN TO REPLY
ocabj
Goldmember
Avatar
1,120 posts
Likes: 3
Joined Jan 2008
Location: Riverside, CA (USA)
     
Mar 12, 2009 17:16 |  #5

I would reformat.

But if you are adamant about trying to clean the OS without having to reformat+reinstall, I would:

1. Download and use the clamav live cd to scan the host for viruses and clean from a clean boot environment.

2. Start computer in native OS. Install all patches.

3. Rescan using clamav live cd.

4. Check for Services that do not belong. Check Service dependencies. Remove/delete any services that are malicious and the respective binaries.

5. Check for spyware. Important to get one that will scan for keyloggers.

6. Check to see if there are any created user accounts on the host that do not belong. Remove them.

7. Change passwords for all accounts on the host.


Jonathan Ocab - https://www.ocabj.net (external link) - http://jocabphoto.com (external link)

  
  LOG IN TO REPLY
Tsmith
Formerly known as Bluedog_XT
Avatar
10,429 posts
Likes: 26
Joined Jul 2005
Location: South_the 601
     
Mar 12, 2009 19:04 |  #6

Roy C wrote in post #7510209 (external link)
P.S. when I run a full AVG scan it does not pick anything up

This is why I quiet using AVG and moved up to ESET NOD32. Yeah it cost but so far has been worth every penny of the $29.95 I paid for a two year subscription, which was a special promotion at the time.

NOD32 runs circles around around AVG.




  
  LOG IN TO REPLY
Zepher
Goldmember
Avatar
1,626 posts
Likes: 1
Joined Nov 2005
Location: Norfolk,VA
     
Mar 12, 2009 23:41 |  #7

Tsmith wrote in post #7512030 (external link)
This is why I quiet using AVG and moved up to ESET NOD32. Yeah it cost but so far has been worth every penny of the $29.95 I paid for a two year subscription, which was a special promotion at the time.

NOD32 runs circles around around AVG.

It doesn't find everything though.
I have been here all day trying to get rid of a Win32/Spy.Zbot.AE
trojan on my machine. NOD32 sees it trying to do something and quarantines it but it's still on the PC.


Manny Desantos
Intel C2Q Q6600 3.06Ghz, 8GB Ram, 8.1TB, XFX HD5850, Windows 7 Ultimate 64bit, PS CS4 EXT (external link)

Canon 40D, EF 28-70L, 2x Canon XH-A1 HDV, Canon HV30 HDV
❶_______________

  
  LOG IN TO REPLY
wardie
Goldmember
Avatar
1,436 posts
Gallery: 12 photos
Likes: 116
Joined May 2005
Location: Central Coast, NSW, Australia
     
Mar 12, 2009 23:52 |  #8

I use a combination of Malwarebytes Anti- Malware and SuperAntiSpyware. Each scans differently and if up to date then catch a lot of the Trojans that are prelevant. You may need to run Malwarebytes in Safe Mode if it can't get rid of the virus/trojan. I usually run one then the other, then reboot and run again.

Wardie


Wardie
40D w/Grip,
30D w/Grip, 24-70 f2.8L, 100-400L,
Accessories - Kenko Pro 300DG 2x, Sunpack 4205G Flash
Gallery (external link)

  
  LOG IN TO REPLY
Tsmith
Formerly known as Bluedog_XT
Avatar
10,429 posts
Likes: 26
Joined Jul 2005
Location: South_the 601
     
Mar 13, 2009 06:50 |  #9

Zepher wrote in post #7513667 (external link)
It doesn't find everything though.
I have been here all day trying to get rid of a Win32/Spy.Zbot.AE
trojan on my machine. NOD32 sees it trying to do something and quarantines it but it's still on the PC.

Well its quarantined the file so that's a plus. Have you contacted ESET support for their input on removal?




  
  LOG IN TO REPLY
Highlight_Photography
Senior Member
Avatar
874 posts
Likes: 1
Joined Jan 2009
Location: Melbourne, Australia
     
Mar 13, 2009 06:57 |  #10

Roy C wrote in post #7510209 (external link)
Somehow I have picked up a Trojan horse BackDoor Agent and it is driving me nuts. I always keep AVG up to date and also use Ccleaner on a very regular basis. I also use a registry scanner/cleaner regularly.

AVG's Resident Shield is picking up the BackDoor agent in the file C\windows\System32\use​rinit.exe which is a genuine windows file and cannot be deleted or healed - It is also turning off the Windows Firewall (which I turn back on again).

Anyone know how to get rid of this virus ?

P.S. when I run a full AVG scan it does not pick anything up

Try Malwarebytes. Great free software


Regards,
Cameron

Website (external link) - Gear List -
Facebook (external link) -  (external link)Flickr (external link)

  
  LOG IN TO REPLY
Mark1
Cream of the Crop
Avatar
6,725 posts
Likes: 7
Joined Feb 2008
Location: Maryland
     
Mar 13, 2009 08:38 |  #11

I would just reformat. Viruses are now getting to be something you can't just remove. ( and I would run away from anyone that says they can remove any virus)The newer ones are no longer one file in one place. The writers have learned how to divide up the program into several places. And some can regenerate the missing parts that do get removed. While some can be simply removed. I would not take the chance. Just reformat. Then be better at what you do online.


www.darkslisemag.com (external link)

  
  LOG IN TO REPLY
LordV
Macro Photo-Lord of the Year 2006
Avatar
62,299 posts
Gallery: 9 photos
Best ofs: 2
Likes: 6874
Joined Oct 2005
Location: Worthing UK
     
Mar 13, 2009 08:44 |  #12

Method of replacing userinit.exe here http://www.f-prot.com …indows/fpwin_fa​q/106.html (external link)
Brian V.


http://www.flickr.com/​photos/lordv/ (external link)
http://www.lordv.smugm​ug.com/ (external link)
Macro Hints and tips
Canon 600D, 40D, 5D mk2, 7D, Tamron 90mm macro, Sigma 105mm OS, Canon MPE-65,18-55 kit lens X2, canon 200mm F2.8 L, Tamron 28-70mm xrdi, Other assorted bits

  
  LOG IN TO REPLY
Titus213
Cream of the Crop
Avatar
19,403 posts
Gallery: 4 photos
Likes: 36
Joined Feb 2005
Location: Kalama, WA USA
     
Mar 13, 2009 16:24 |  #13

A couple of cases at the AVG free forum on this right now with no responses.....

They seem fussy about following this simple rule... http://freeforum.avg.c​om …p?15,132356,bac​kpage=,sv= (external link)

http://freeforum.avg.c​om …,176118,176125#​msg-176125 (external link)


Dave
Perspiring photographer.
Visit NorwoodPhotos.comexternal link

  
  LOG IN TO REPLY
Roy ­ C
THREAD ­ STARTER
Goldmember
Avatar
2,088 posts
Likes: 21
Joined Aug 2005
Location: N.Devon, UK
     
Mar 14, 2009 07:37 |  #14

Just an update to the situation Guys. I have installed and run, Stinger, Malwarebytes and SpyDoctor all tried in Safe mode and with the sytem retore tuned off. Each time it picks up the trojan(s) but fails to remove - it is looking like a complete sytem reformat :(


TOP BIRD SHOTS (external link)
MY PHOTOSTREAM (external link)

500px gallery (external link)

  
  LOG IN TO REPLY
Highlight_Photography
Senior Member
Avatar
874 posts
Likes: 1
Joined Jan 2009
Location: Melbourne, Australia
     
Mar 14, 2009 07:39 |  #15

Sorry to hear. Looks like a reformat is the way to go :( Make sure you have everything important backed up!


Regards,
Cameron

Website (external link) - Gear List -
Facebook (external link) -  (external link)Flickr (external link)

  
  LOG IN TO REPLY
sponsored links (only for non-logged)

2,214 views & 0 likes for this thread, 17 members have posted to it.
Trojan Horse help needed
FORUMS General Gear Talk Computers 
AAA
x 1600
y 1600

Jump to forum...   •  Rules   •  Forums   •  New posts   •  RTAT   •  'Best of'   •  Gallery   •  Gear   •  Reviews   •  Member list   •  Polls   •  Image rules   •  Search   •  Password reset   •  Home

Not a member yet?
Register to forums
Registered members may log in to forums and access all the features: full search, image upload, follow forums, own gear list and ratings, likes, more forums, private messaging, thread follow, notifications, own gallery, all settings, view hosted photos, own reviews, see more and do more... and all is free. Don't be a stranger - register now and start posting!


COOKIES DISCLAIMER: This website uses cookies to improve your user experience. By using this site, you agree to our use of cookies and to our privacy policy.
Privacy policy and cookie usage info.


POWERED BY AMASS forum software 2.58forum software
version 2.58 /
code and design
by Pekka Saarinen ©
for photography-on-the.net

Latest registered member is Mihai Bucur
1430 guests, 166 members online
Simultaneous users record so far is 15,144, that happened on Nov 22, 2018

Photography-on-the.net Digital Photography Forums is the website for photographers and all who love great photos, camera and post processing techniques, gear talk, discussion and sharing. Professionals, hobbyists, newbies and those who don't even own a camera -- all are welcome regardless of skill, favourite brand, gear, gender or age. Registering and usage is free.