Computer Forums

Go Back   Computer Forums > Software > Security Software

Security Software Protect your computer from internet nasties... firewalls, antivirus, and everything computer security related belongs here.

Register Now for FREE!
Computer Forums

Username: Password: Confirm Password: E-Mail: Confirm E-Mail:
Agree to forum rules 


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-01-2007, 12:04 AM
Kilobyte
 
Join Date: 24 Jan 2007
Posts: 96
comedyink is on a distinguished road
Default Need help removing a Trojan

I have the "SVCHOSTS.EXE-06B6C8D2.pf" trojan on my computer.
How exalty do I remove it. I did have "svchosts.exe" trojan which i removed using AEVITA Wipe and Delete.
Im running Avast! as my AntiVi and Zone Alaram Pro as my firewall
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 02-01-2007, 12:12 AM
Ultra_Man's Avatar
CompuForums Moderator
 
Join Date: 29 Aug 2006
Location: Missouri
Posts: 578
Ultra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud ofUltra_Man has much to be proud of
Default

Have you tryed running Avast to remove the trogan...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 02-01-2007, 01:31 AM
SeanFlaherty's Avatar
Prepare to be moderated
 
Join Date: 02 Jan 2007
Location: TX
Posts: 322
SeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond reputeSeanFlaherty has a reputation beyond repute
Default

Hello comedyink,
I would recommend using Twister Anti-Trojan Virus from Filseclab to get rid of this trojan.

~Sean
__________________
http://www.compuforums.org/image.php?type=sigpic&userid=884&dateline=12149234  87
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 02-01-2007, 07:29 PM
Kilobyte
 
Join Date: 24 Jan 2007
Posts: 96
comedyink is on a distinguished road
Default

-Yes, I did try running avast to find and delete, but nothing came up.
-Ill try using twister anti-trojan to see if i can get rid of this.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 02-02-2007, 04:44 AM
Valandil's Avatar
New Member
 
Join Date: 06 Dec 2006
Location: Texas
Posts: 21
Valandil is on a distinguished road
Default

Why don`t you go ahead and press ctrl, alt, delete and pull up your task manager and go to the "Processes" and try seeing if perhaps the trojan is in there. If it is, end the task and run any anti-virus software and it should take care of it.

You mentioned Avast didn`t pick the virus up... Is it the latest version with current updates?
__________________
http://i116.photobucket.com/albums/o...ch/2710341.gif
Shamelessly ripped off of b3ta? How very dare you?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 02-02-2007, 05:58 AM
Terabyte
 
Join Date: 15 Dec 2006
Location: Sacramento, CA, United States
Posts: 573
guyladouche is a jewel in the roughguyladouche is a jewel in the roughguyladouche is a jewel in the rough
Default

Terminating viruses/malware doesn't typically work in taskmanager because they auto restart.

I'd start up in Safe Mode and then run antivirus from safe mode. There are some web-based virus scanners (pandasoft) that don't require you to install the program or updates, and just scans your computer from the net--viruses/malware are famous for fooling/preventing antivirus software from working properly (in some cases). Try a few different free antivirus programs to see if that helps.
__________________
AMD Athlon 64 X2 4400+ (@2.6 GHz)
2x1GB OCZ Spec. Ops. PC3200
ASRock Dual939-SATA2
Antec TruePower 550 watt PSU
80 GB Seagate Barracuda SATA 7200 rpm
300 GB Seagate Barracuda SATA 7200 rpm
120 GB Maxtor ATA/133 7200 rpm
ATI Radeon x1950 Pro
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 02-02-2007, 11:01 PM
Valandil's Avatar
New Member
 
Join Date: 06 Dec 2006
Location: Texas
Posts: 21
Valandil is on a distinguished road
Default

Quote:
Originally Posted by guyladouche View Post
Terminating viruses/malware doesn't typically work in taskmanager because they auto restart.

I'd start up in Safe Mode and then run antivirus from safe mode. There are some web-based virus scanners (pandasoft) that don't require you to install the program or updates, and just scans your computer from the net--viruses/malware are famous for fooling/preventing antivirus software from working properly (in some cases). Try a few different free antivirus programs to see if that helps.
Yeah, but there`s actually a way to end it in task manager without it restarting while you delete it. This was actually how I managed to fix a computer that came into the shop I used to work at.
__________________
http://i116.photobucket.com/albums/o...ch/2710341.gif
Shamelessly ripped off of b3ta? How very dare you?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 02-05-2007, 03:10 AM
Terabyte
 
Join Date: 15 Dec 2006
Location: Sacramento, CA, United States
Posts: 573
guyladouche is a jewel in the roughguyladouche is a jewel in the roughguyladouche is a jewel in the rough
Default

Sure, in safe mode while you're running an antivirus program, but there's no practical way to manually kill a virus/malware trojan in task manager and then remove all instances of the program(s) from your computer before it restarts.

If you have found a way please share it for the person having this problem.
__________________
AMD Athlon 64 X2 4400+ (@2.6 GHz)
2x1GB OCZ Spec. Ops. PC3200
ASRock Dual939-SATA2
Antec TruePower 550 watt PSU
80 GB Seagate Barracuda SATA 7200 rpm
300 GB Seagate Barracuda SATA 7200 rpm
120 GB Maxtor ATA/133 7200 rpm
ATI Radeon x1950 Pro
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 02-06-2007, 10:36 AM
Sigh-clone's Avatar
Premium Member
 
Join Date: 02 Nov 2006
Location: Noo Zeelund
Posts: 313
Sigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond repute
Default

Hi comedyink... You said you had an Svchosts.exe trojan and then said you removed it using Aevita Wipe and Delete which is basically a file shredder. What exactly did you delete? Guy is right - stopping or deleting the process will not remove the trojan. Several malwares have been associated with using svchosts.exe - do you know which trojan you have?
I would start the computer in safe mode. Download the latest virus definitions for Avast. Run a full system scan and delete all the files detected. Hopefully this will also get rid of the registry entries or you will have to do this manually. When you are sure the trojan is gone set a new system restore point as the previous ones will probably contain the trojan. If Avast doesn't pick anything up then I would try an online detector like Housecall.
__________________

The original point and click interface was a Smith and Wesson.
Never underestimate the power of PINK
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 02-07-2007, 05:23 AM
Kilobyte
 
Join Date: 24 Jan 2007
Posts: 96
comedyink is on a distinguished road
Default

It still didnt work with anyother AntiVi.
I deleted svchosts.exe in my system32 dedicatory.
And my Virus is Trojan.W32.MyTob i think
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 02-07-2007, 09:49 AM
Sigh-clone's Avatar
Premium Member
 
Join Date: 02 Nov 2006
Location: Noo Zeelund
Posts: 313
Sigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond repute
Default

Did you run the AV's from safe mode? What makes you think it is W32.MyTob? You should also check in Add/Remove Programs to make sure nothing has installed itself without your knowledge. Some malwares do this such as Adware.TopAV - this also creates an svchosts file as do many other malwares. You really need to know what you are dealing with as removal techniques differ.
__________________

The original point and click interface was a Smith and Wesson.
Never underestimate the power of PINK
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 02-08-2007, 06:02 AM
Speedboxer's Avatar
MattsBlog.Ca
 
Join Date: 31 Jan 2007
Location: Canada
Posts: 62
Speedboxer is on a distinguished road
Default

If the Virus you have is the one you said it is, try this Virus remover for it:

W32.Mytob@mm Removal Tool - Symantec.com

Or maybe this one:

W32.Mytob.AR@mm Removal Tool - Symantec.com

Or, if those don't work, I think that Symantec has an online Virus scanner somewhere, maybe not though.
__________________
[center]
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 02-08-2007, 11:56 PM
Kilobyte
 
Join Date: 24 Jan 2007
Posts: 96
comedyink is on a distinguished road
Default

I think I got all of them on my computer,
I found 2-3 in safe mode,
and 1 when I was in regular mode, just browsing.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14 (permalink)  
Old 02-11-2007, 08:08 AM
Sigh-clone's Avatar
Premium Member
 
Join Date: 02 Nov 2006
Location: Noo Zeelund
Posts: 313
Sigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond reputeSigh-clone has a reputation beyond repute
Default

see the thread in this forum called Hijack This - tacotanker27 may be able to help you with your problem
__________________

The original point and click interface was a Smith and Wesson.
Never underestimate the power of PINK
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15 (permalink)  
Old 03-08-2007, 07:15 PM
Bob The Computer Guy's Avatar
Megabyte
 
Join Date: 08 Mar 2007
Posts: 150
Bob The Computer Guy is on a distinguished road
Default

Spy-Bot Search and Destroy.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 06:34 PM.



Powered by: vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Limited.
Content © Copyright 2005-2008 CompuForums. All Rights Reserved. Some content © Copyright of the respective owners.
Cheap Gas - Loans - Phoenix Landscaping - Loans

Content Relevant URLs by vBSEO 3.2.0 RC5