Overclock.net › Forums › Software, Programming and Coding › Operating Systems › Ahh trojan on my pc!
New Posts  All Forums:Forum Nav:

Ahh trojan on my pc!

post #1 of 28
Thread Starter 
how do i get rid of it, i ended the process moved to volt and deleted folder it makes in programs. but then it comes back a while later witha new procress name, and the folder is there again. any way to delete this thing/ I jus finished getting everything on my conroe rig
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
post #2 of 28
install avg free: http://free.grisoft.com/freeweb.php/doc/2/
Ryzen 7 1700
(13 items)
 
  
CPUMotherboardGraphicsRAM
Ryzen 7 1700 Asus X370 Crosshair VI Hero EVGA GTX 1080 FE Geil 16GB RGB DDR43000 
Hard DriveCoolingOSMonitor
Samsung 950 Pro 512GB PCIe/NVME SSD Xigmatek Scylla 240 AIO Win10 Pro X64 Qnix QX2710LED @ 110hz 
KeyboardPowerCaseMouse
Cooler Master Masterset MS121  EVGA G2 850 w/EVGA Black Cableset Lian Li Test Bench Cooler Master Masterset MS121  
Audio
Sanyo Soundbar FWSB405F 
  hide details  
Reply
Ryzen 7 1700
(13 items)
 
  
CPUMotherboardGraphicsRAM
Ryzen 7 1700 Asus X370 Crosshair VI Hero EVGA GTX 1080 FE Geil 16GB RGB DDR43000 
Hard DriveCoolingOSMonitor
Samsung 950 Pro 512GB PCIe/NVME SSD Xigmatek Scylla 240 AIO Win10 Pro X64 Qnix QX2710LED @ 110hz 
KeyboardPowerCaseMouse
Cooler Master Masterset MS121  EVGA G2 850 w/EVGA Black Cableset Lian Li Test Bench Cooler Master Masterset MS121  
Audio
Sanyo Soundbar FWSB405F 
  hide details  
Reply
post #3 of 28
Thread Starter 
Already got that, moved to vault, deleted, it came back under a new process. i think I may have finally isolated it.
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
post #4 of 28
Boot into safemode and use an anti-virus app. Some trojans require manual deletion. If nothing else, use Google. People have material documented to remove specific spyware/trojans.
Legendary
(13 items)
 
  
CPUMotherboardGraphicsRAM
E6750 ASUS P5B Deluxe XFX 8600GT 2 x 2GB G.Skill PQ 
Hard DriveOSMonitorKeyboard
Seagate 250GB Windows 7 x64 Samsung 225BW Saitek Eclipse 
PowerCaseMouseMouse Pad
PC P&C Quad 750W Silencer Thermaltake Tsunami Dream Logitech MX518 Func 1030 
  hide details  
Reply
Legendary
(13 items)
 
  
CPUMotherboardGraphicsRAM
E6750 ASUS P5B Deluxe XFX 8600GT 2 x 2GB G.Skill PQ 
Hard DriveOSMonitorKeyboard
Seagate 250GB Windows 7 x64 Samsung 225BW Saitek Eclipse 
PowerCaseMouseMouse Pad
PC P&C Quad 750W Silencer Thermaltake Tsunami Dream Logitech MX518 Func 1030 
  hide details  
Reply
post #5 of 28
Thread Starter 
Ill try safemode, in my panic i overlooked that simple procedure, thanks.
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
post #6 of 28
You might need to go into your registry, and delete all signs of it that way. Sometimes, a missed dll or pf file sets to run the virus, and if a needed file is not found, it can be scripted to open a port and redownload the files. My advice to you would be to find the application, if any, in task manager and find the process tree. Or in task manager, find the process, ie. lsass.exe, and then boot into safe mode without networking, if that is how your connection is set up, or unplug your ethernet cable, do not rely on just disabling your network connection via windows. While in safe mode,delete all branches of the virus, then search the registry via the "find next" option, delete all instances of the virus, and before shutting down out of safe mode, empty recycling bin, AND delete them from the RECYCLER file in C:\\.(NOTE: you cannot just delete the main or subfolders for RECYCLER, you have to go inside and manually delete the files. ALSO, to find the RECYCLER folder, you need to go to tools, folder options, view, and then tick the show hidden files and folders, then click apply. After all that, restart back into windows to see if it is gone.

NOTE: The reference I made to lsass.exe, is this: Because of the default font of Windows, uppercase I and lowercase L look exactly the same. So the process lsass.exe(Uppercase I) is indeed a system process, on the otherhand, lsass.exe(Lowercase L) is a trojan/malware/browser pirate.

Hope this little tidbit helped you any, and good luck
My System
(13 items)
 
  
CPUMotherboardGraphicsRAM
AMD FX-55 CABCE DFI Lanparty UT CFX3200DR Sapphire X850XT PE 1024Mb 2X 512 Dual Mode 
Hard DriveOSMonitorKeyboard
Seagate SATA 500Gb 3G/sec Windows XPSP2/Ubuntu 6.10 Acer 17" 6ms Flat-LCD Micro 107 Key 
PowerCaseMouse
Aspire 680W "Beast" Dual User Created Micro Laser 
  hide details  
Reply
My System
(13 items)
 
  
CPUMotherboardGraphicsRAM
AMD FX-55 CABCE DFI Lanparty UT CFX3200DR Sapphire X850XT PE 1024Mb 2X 512 Dual Mode 
Hard DriveOSMonitorKeyboard
Seagate SATA 500Gb 3G/sec Windows XPSP2/Ubuntu 6.10 Acer 17" 6ms Flat-LCD Micro 107 Key 
PowerCaseMouse
Aspire 680W "Beast" Dual User Created Micro Laser 
  hide details  
Reply
post #7 of 28
Thread Starter 
Wow nice detail, thanks man So far it hasnt re appeared I scanned several times, and manually found a .dll file called toolbar888, which i think created the file called iget2 or something with got the virus, after ending a few random processes, b111 (i knew that aint real) exentually think i got it. if it reoccurs i may tap into registry, but thats dangerous, thats the lifestream of ones PC
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
post #8 of 28
Thread Starter 
I want to schedule a boot scan, any program thatll do that other then avast
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
post #9 of 28
Quote:
Originally Posted by SilentStryke
... created the file called iget2 or something

... if it reoccurs i may tap into registry, but thats dangerous, thats the lifestream of ones PC
This will find what is putting it back.
http://en.wikipedia.org/wiki/Dependency_walker
My System
(15 items)
 
  
CPUMotherboardGraphicsRAM
FX6300 Black M5A99X EVO R2.0 Nvidia GTS450 Team Vulcan PC3 12800 
Hard DriveOptical DriveCoolingOS
Samsung 840 PRO Asus DRW-1608P (x2) Custom Water Cooling Win7 (Ult), Win 8.1 & Win Server 2012 R2 
MonitorKeyboardPowerCase
2 X Samsung 915N Ducky Shine III, Blue Cherry/Blue LEDs PCP&C 1kw Lian Li PC-71 (W/Window) 
MouseAudio
Logiteck G400s none 
  hide details  
Reply
My System
(15 items)
 
  
CPUMotherboardGraphicsRAM
FX6300 Black M5A99X EVO R2.0 Nvidia GTS450 Team Vulcan PC3 12800 
Hard DriveOptical DriveCoolingOS
Samsung 840 PRO Asus DRW-1608P (x2) Custom Water Cooling Win7 (Ult), Win 8.1 & Win Server 2012 R2 
MonitorKeyboardPowerCase
2 X Samsung 915N Ducky Shine III, Blue Cherry/Blue LEDs PCP&C 1kw Lian Li PC-71 (W/Window) 
MouseAudio
Logiteck G400s none 
  hide details  
Reply
post #10 of 28
Thread Starter 
It keeps installing stuff When I boot, which re downloads the trojan, getting annoying.
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
Little Smoky
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel E8400 Wolfdale 3.0GHz Gigabyte GA-EP45-UD3P EVGA GTX 260 896MB G.Skill 4GB DDR2 1000 
Hard DriveOptical DriveOSMonitor
Western Digital Caviar 500gb Samsung DVD +/- RW Windows 7 64 Bit 22 Acer LCD 5ms Response 
KeyboardPowerCaseMouse
Logitech Corsair 750WATT Coolermaster Sniper Logitech 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Operating Systems
Overclock.net › Forums › Software, Programming and Coding › Operating Systems › Ahh trojan on my pc!