XP Home Edition and TROJ_DLOADER.VIN

Discussion in 'Malware Help (A Specialist Will Reply)' started by Hiero, Aug 25, 2008.

  1. Hiero

    Hiero Private E-2

    First off, big thanks to everybody that helps out on the site.

    My brother has a Dell computer, XP Home Edition, McAffee antivirus. Does not have the OS or the recovery disk from Dell. He's surfing the net and McAffee goes off saying it blocked a trojan. Now while most of us would have stopped what we we're doing and done a full system scan he just keeps on surfing. Two days later he logs in and finds the computer is completely hosed.

    If I could get to the internet on it I think I could fix it but there's a major issue. Only 2 services are running... Event Viewer and Plug and Play. Everything else is stopped. If I try to start something it either says the dependency group or service is off or it does not start in timely manner. If I right-click a service and try to view properties then nothing happens. If I go to the Event Viewer and double click an event for more info then nothing happens.

    I tried to do a system restore from "My computer" and it failed. I rebooted in safe mode w/ command and tried to restore that way and it failed.

    Some of the nasties I found were: maomaochong.exe, beauty.exe, a.exe, b.exe, c.exe. Most of which point to TROJ_DLOADER.VIN. One of the things that happens with this trojan is that it modifies the LSP chain. I've fixed that but still can't get anywhere w/out the services running.

    Any suggestions?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You may actually be better off reinstalling. With your system running like this, there is not too much we can do to help you in the Malware Forum. Yes we could try removing any malware that we may be able to find, but odds are that removing the malware is not going to reactivate all the necessary system services that may have been disable.

    Problems like you are describing often occur when the Remote Procedure Call (RPC) service is stop and or disabled. Restarting it may or may not help and it also may not work which is why a reinstall my be necessary because you can waste a load of time recovering from issues that occur after terminating this service.

    You may want to look at Black Viper to get information about settings for Windows Services which you can attempt to reset to proper values. Also it will help you identify the dependancies for each service. For example, you can see a lot of services are dependant upon the RPC service I mentioned above. See this: http://www.blackviper.com/WinXP/Services/Remote_Procedure_Call_(RPC).htm
     
  3. Hiero

    Hiero Private E-2

    Thanks Chas,

    I kinda figured as much. My brother didn't have the OS or a recovery disk so I called Dell and found out that you can restore the computer to factory specs by pushing CTL + F11 at startup. I tried it and it worked. Unfortunately it completely wiped the computer and I wasn't able to save off any of their data but at least it's up and running now.

    Once again, thanks.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds