Trojan in registry that returns after reboot

Discussion in 'Malware Help (A Specialist Will Reply)' started by The_Biggest_Geek, Jun 22, 2006.

  1. The_Biggest_Geek

    The_Biggest_Geek Private E-2

    I ran all the recomended programs and followed all the steps, and it removed most of the problem, but there's one trojan file in my registry that refuses to budge. It's listed as being called 'Trojan.Generic' in HKLM\Software\Microsoft\Windows\CurrentVersion\Run\159f2487.exe I've tried to remove it with various programs (Trojan Hunter, Windows defender, Spybot search and destroy, trojan remover, a-squared, and quite a few others, most of which I found here. I know you said not use multiple programs, but some of them seem to be unable to detect this trojan, as it doesn't show up in the scan, and sense none of them removed it effectively I thought I'd try a few different ones. I removed the ones that didn't work after I was done with them.) to no avail. It's always back after I reboot. It doesn't seem to affect my PC (That I notice) beyone the fact that my desktop is locked to where I can't change the wallpaper and the windows firewall won't let me open the control panel. It always has an 'unknown error' everytime I try.

    My computer is a Compaq laptop with windows XP, 512MB system memory, 80GB hard drive, 1.8GHz, 512KB L2 cache with up to 1800MHz system bus.

    I'm running out of ideas for how to fix this problem, and being rather a novice with technical things I really don't know too much about what I'm doing and I'm hoping someone can give some advice for how to fix this problem.
     
    Last edited: Jun 22, 2006
  2. The_Biggest_Geek

    The_Biggest_Geek Private E-2

    Well, I think I fixed the trojan atleast. Reran highjackthis on a whim and when I restarted, it was gone. Hopefully it'll stay that way. But the firewall and the desktop still aren't working... I don't suppose anyone has any ideas on what that could be?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds