Jump to content

Trojan found....cant delete..wtf?


raid
 Share

16 posts in this topic

Recommended Posts

Renos.y is the name of the trojan that my AV software picked up (trend micro antivirus), but it's unable to delete the Trojan and I can’t open the drive D, E, F. so what do i do now?

 

 

Maybe I should reinstall my computer and restore the data with EASEUS data recovery wizard or other data recovery programs.

Link to comment
Share on other sites

Renos.y is the name of the trojan that my AV software picked up (trend micro antivirus), but it's unable to delete the Trojan and I can’t open the drive D, E, F. so what do i do now?

 

 

Maybe I should reinstall my computer and restore the data with EASEUS data recovery wizard or other data recovery programs.

 

I don't quite understand whether you can access your Windows partition or not.

If you can, do one of the following:

1)Download CyberScrub Privacy Suite 15 Day Trial and use it to delete the trojan.

 

http://www.cyberscrub.com/download/

 

2)Start Windows in safe mode. That should also allow you to delete the trojan.

 

And BTW, you can also use a Linux LiveCD to do all sort of things, including back up your data and possibly remove the trojan if you use a distro with NTFS-3G support, like this:

 

http://distrowatch.com/?newsid=04688

Link to comment
Share on other sites

Also, look if your computer has a recovery partition, those things usually include an AV. If not, a recovered computer runs like {censored} in the end. Just backup and reinstall!

Link to comment
Share on other sites

If you got it recently, just use System Restore to go back before you got it. This will remove all traces of the virus in your registry and startup items. Once you've done that and the file is released, scan with your AV program and it should be able to delete it.

 

That's the method I used back in my Windows XP days and it has a 100% success rate. I don't get trojans now that I'm running Windows Vista and Mac OS X. :(

Link to comment
Share on other sites

The reason that your AV program can't delete the files is that they are probably in use. If you can find the process(es) being used by the Trojan (sometimes it's painfully obvious, sometimes not) in Task Manager, stop them and then try to delete using you AV or by manually deleting infected files.

 

Most of the time though the Trojan will start right back up again, so restarting in safe mode should prevent the Trojan from running in the first place and give you the ability to delete it. If you also have a list of registry entries made by the Trojan, you'll want to get rid of those too.

 

If safe mode doesn't work, you can also boot the Windows drive from either another OS (follow Alessandro's advice).

 

You can try using System Restore; the problem with that is sometimes you don't know when you were first infected (wouldn't want to revert to a still infected-state, only to find out later you didn't fix your problem).

 

Finally, the most effective (though usually not desirable) way of ridding of your infection is to do a complete reinstall of Windows. It's effective, but unless you have a good, recent backup of your system it can be a pain.

Link to comment
Share on other sites

Nicely said rollcage <_>

 

Try to clean out as much of it as possible, stop any viral processes that are running, then run these 2 online virus cleaners:

TrendMicro HouseCall

http://housecall.trendmicro.com/

 

X-Cleaner Micro Edition

http://www.spywareguide.com/onlinescan.php

 

The first one is the biggie, it scans and destroys all viral files and every trace of a virus it can, with up to date definitions. The second one is mainly for removing viral registry entries and entries left over by viruses that were deleted before.

Link to comment
Share on other sites

That's what I like seeing. 10 people helping out one guy who was silly enough to by a PC in the first place :P

 

But honestly it's really nice seeing people come together helping one another. We don't see as much of this in this forum any more I'm sad to say.

Link to comment
Share on other sites

Yeah I forgot HijackThis.

 

After you've run the cleaners, run HijackThis and submit the log in a forum, or paste the log into an automatic analyzer like these ones:

 

http://www.hijackthis.de/

http://hjt.networktechs.com/

http://www.prevx.com/hijackthis.asp

http://www.spyandseek.com/

 

Paste the log into all of them because sometimes they show up a slightly different result in each analyzer.

Link to comment
Share on other sites

Yeah you can get a mac but do not act like a douche, give this guy some help on what he needs.

Haha, come on dude, this forum is called InsanelyMac, we can't have a PC help thread without at least one "get a Mac" reference. :( :censored2: And I did give him some help - System Restore would free up the file by rolling back to the list of startup items before he got infected, releasing the file permissions and allowing him to delete it (provided he didn't turn it off at the suggestion of those moronic "tweaking Windows" websites that do more harm than good).

 

Oh yeah, and make sure you run AV software from now on! AVG is a great free solution - run it in full-protected mode, perform daily scans, run automatic updates, and always scan anything you torrented before opening it!!

Link to comment
Share on other sites

That's the method I used back in my Windows XP days and it has a 100% success rate. I don't get trojans now that I'm running Windows Vista and Mac OS X. :wub:
Only surf the internet with linux or mac os x. End of problem.

Honestly, if your computer can handle it, look at Vista. It's been very good to the work computers with Viruses... not one yet, and this is in a work environment where emails contain viruses [virii?] all the time... and most if not all of them are trojans!

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...