Tenacious Trojan that won't be deleted...

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Disco Albino, Jul 13, 2006.

  1. Disco Albino

    Disco Albino Private E-2

    LOG INCLUDED

    Earlier today, a scan I ran on Norton AV detected what it termed a "downloader" trojan. It was not able to be fixed, quarentined, or deleted. I attempted to delete the file manually, which was located in the system32 folder. It said it could not be deleted because it was "being used by another person or program".

    I followed the instructions and ran the programs detailed in the sticky (hopefully correctly). The only program to detect anything besides some adware was bitdefender, which detected and deleted and additional trojan, and detected the trojan in question but was again unable to delete it. I have attached the BDscan log. I would be eternally grateful for any help, please save my computer!!
     

    Attached Files:

    Last edited: Jul 13, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Did you boot into safe mode with networking to run the scans? If not do so.


    If you did then please attach the other logs as requested in the guide.
     
  3. Disco Albino

    Disco Albino Private E-2

    Yes, I ran all the scans in safe mode. Here are the other two logs. Neither seems to have detected the trojan I'm trying to get rid of. I also ran Norton AV in safe mode and it gave me the same resonse (detected the virus, couldn't delete). Thanks for the post, hopefully someone can help me get rid of this thing...
     

    Attached Files:

  4. Disco Albino

    Disco Albino Private E-2

    Bump! Sorry to self-promote but I really need some help getting rid of this thing. Any advice on removal would be GREATLY appreciated.
     
  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Your Hijackthis log needs to be run from Normal Mode for a full picture.


    But do try this for me as I see that the trojan that is highlighted is locatied in the Java Cache, open the Java plugin control panel which is located in Control Panel, click Cache then Clear and re-scan.
     
  6. Disco Albino

    Disco Albino Private E-2

    Here's a HJT normal mode scan of my computer done after the Java Cache was cleared. All programs (norton, bdscan, HJT) still can't remove the trojan. Thanks for helping me, this thing is a real pain in the ass...
     

    Attached Files:

  7. Disco Albino

    Disco Albino Private E-2

    BUMP...sorry to keep doing this, but I can't find a way to remove this file (d3delp.dll). Any ideas on how to remove this would be greatly appreciated.
     
  8. Disco Albino

    Disco Albino Private E-2

    http://forums.majorgeeks.com/showthread.php?t=97091 could I use the steps detailed in response to this person's thread, but with the filename changed to the one I'm getting rid of? He has virtually the same exact problem (a .dll downloader trojan that won't delete).
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Yes you can, use PocketKillBox and those instructions to try and delete that file.

    also you can try these if the above one doesnt work,


    MoveOnBoot this one, once you dragNdrop the file or browse for its location, deletes the file on reboot, so any applications that have locked the file are not running so cannot lock it before deletion.. my fav!

    Unlocker
     
  10. Disco Albino

    Disco Albino Private E-2

    You guys are awesome, thanks so much for taking the time to help me out Halo! I got rid of the .dll using process explorer and killbox following the procedure. I posted a HJT log so hopefully I can be told if my comp's clean. There's another .dll trojan that I deleted a while ago that shows up as "file missing". I guess I probably should follow the same procedure and delete it from my registry? Thanks again for the help!
     

    Attached Files:


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds