Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Closed Thread
Old 04-06-2005, 08:18 PM   #1 (permalink)
 
Newb Techie

Join Date: Apr 2005

Posts: 5

mambos66

Unhappy Reboot R Torjan

hay i cleverly got a Trojan, from what i can tell with all my years of NO experience.

Every time i restart it comes up with a little black box, which runs a script, shutting down. then it does. From what i can tell it is a Trojan, but no software spy ware any thing can pick it up. I have to restart in safe mode. Any ideas help? It must be possible to remove this manually
mambos66 is offline  
Old 04-06-2005, 09:22 PM   #2 (permalink)
 
Super Techie

Join Date: Dec 2003

Posts: 324

sunsider

Default

http://www.virus-scan-software.com/l...reboot-r.shtml
sunsider is offline  
Old 04-06-2005, 10:16 PM   #3 (permalink)
 
Newb Techie

Join Date: Apr 2005

Posts: 5

mambos66

Default

thanks but it doe snot tell me how to romve it, all virus scans come up with a blank, and i have run about 4 and spy wear.

Any ideas?
mambos66 is offline  
Old 04-06-2005, 10:44 PM   #4 (permalink)
 
Super Techie

Join Date: Dec 2003

Posts: 324

sunsider

Default

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rundll32.exe

remove this file and you should be fine
sunsider is offline  
Old 04-06-2005, 10:53 PM   #5 (permalink)
 
Newb Techie

Join Date: Apr 2005

Posts: 5

mambos66

Default

i am having trouble getting ot rndll32.exe, i only have images of files or prgarams, would it be within one of those possibly?

Thanks
mambos66 is offline  
Old 04-06-2005, 10:59 PM   #6 (permalink)
 
Newb Techie

Join Date: Apr 2005

Posts: 5

mambos66

Default

i dnt have rundll.exe under that i have three files acrobat office, and logi tech (for mouse).

Any ideas?
mambos66 is offline  
Old 04-06-2005, 11:03 PM   #7 (permalink)
 
Super Techie

Join Date: Dec 2003

Posts: 324

sunsider

Default

unfortunately no, that is the way all the sites i went to tell me how to get rid of it. try making sure u can view all files (tools>folder options) and going into safe mode to pull it out. maybe even try hijackthis, which will show it loaded at boot, and maybe let u remove it that way
sunsider is offline  
Old 04-07-2005, 02:27 PM   #8 (permalink)
 
Monster Techie

Join Date: Jan 2005

Posts: 1,101

Blitze105 is on a distinguished road

Send a message via AIM to Blitze105 Send a message via Yahoo to Blitze105
Default

i have a question..
what does it say? when it shuts down? does it give u a warning?

use spyware search and destroy... if not try free online scans.. see if they pick it up.. and if they do u can look up the exact name of ur trojan.. maybe thatll help.. or u can post the name here and im sure some one here can help. some brilliant ppl on here..
__________________
I'm Forgetful! so if i stop posting on something that i was helping you with... PM me or IM me
yahoo and aol: blitze105
you can always IM or PM me if i offend you as well, i will edit the post if i have.
Blitze105 is offline  
Old 04-07-2005, 09:39 PM   #9 (permalink)
 
Newb Techie

Join Date: Apr 2005

Posts: 5

mambos66

Default Fixed it

I tried every torjan ad wear, any thing that looked like virus removal nothing.

Any hoooo took it to a comp shop and they fixed it in 30 secs, they removed a file from the start up registry called DRIVER.BAT. I had no idea it was not supposed to be there.

Problem fixed.

Thanks
mambos66 is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On