got rid of a trojan and it came back

To many ads? Support ODJT and see no ads!
I was working on a clients computer, transfered docs over to our external drive. It picked up a trojan. Infected one of my work machines, luckily it didn't get to any of our other machines at the office like the server, laptops, or editing system.

Sality/V was the name. It would rewrite the files. and extract the virus upon opening. Was pretty nasty stuff. Put us behind a day on our projects.
 
I was working on a clients computer, transfered docs over to our external drive. It picked up a trojan. Infected one of my work machines, luckily it didn't get to any of our other machines at the office like the server, laptops, or editing system.

Sality/V was the name. It would rewrite the files. and extract the virus upon opening. Was pretty nasty stuff. Put us behind a day on our projects.

BUMMER!!!

I have to admit that I impressed myself. With the AMAZING help of DjDennis (Who is quite amazing in his own right!) I learned enough to make this all happen.

I wiped Wifey's lappy and reinstalled it all. Got stumped on some of the drivers, but got them to love me after more research.
 
well all you have to do is ask.........

gotta get some more work done - it never ends here

I tell ya computers you either love them or hate them
 
If you are reasonably PC confident and literate you can manually remove just about anything with out a format.

As one poster said, check your Task Manager (CTRL+ATL+DEL) for processes. Most are easy to understand as they will be names of programs running on your PC.

If there is something you don't know about google it.

It is also a good idea to periodically delete your Temp folder.

You can also go to START -->RUN and enter MSCONFIG
This will open up a box.You want to be on the STARTUP tab.

You can select the programs that you don't want to automatically start when you boot up your PC. Programs like your Printer, Office, Adobe and Winamp you can uncheck; as they really slow down you PC unless you use any of them frequently.

Sometimes you will spot items listed that you have no idea about. Google those, you can also look at the details to find where the program is residing on the Hard drive. You will also want to copy the name and the folder it is in (if the program is in it's own directory). If it is a virus/trojan/malware you will need that info to remove them from your registry.

After you have selected/unselected your start up options (you can disable all and the ones that are necessary for your PC to run will auto run anyway so no real danger of messing anything up, at the worst you can go to safe mode and turn them back on.)

If you do have malicious software you will want to go into safe mode, then back to the RUN and enter REGEDIT. Another box will open. I do not suggest you do anything in here unless you are 100% certain you have malicious software on your PC.

Goto Edit and to Find. (CTRL+F) then enter in the file name with out the .exe extension. Then hit enter and F3 to search for more entries. When you find an entry with the same file name (and sometimes it will show the location of the file) just delete it. Do this for every entry. When done, do the same for the folder name you found the program in. Sometimes there will be an entry that hides in the registry that re-downloads the program again when you open a web browser. If you are not sure if you should delete something... don't.

Once that is done, delete the Temp Folder. For Win XP: Open your C drive (or master drive) then go to Tools ---> Folder Options --->View.
Find the radio button for Hidden Files and Folders and click on SHOW Hidden Files and Folders. It is also a good idea to Click the radio button
For Hide Extensions for Known file types.

(this lets you see what type of files you have by looking at the end of their names. It unhides .jpg, .exe, .mp3 from the file name. Some malware and viruses will pick an icon of a file type you recognize like an MP3, and the files title might look like "Prince - 1999.mp3" but in reality because the extension is hidden it is "Prince - 1999.mp3.exe" so when you click to listen to it, you have just installed/ran a virus. You have been tricked.)

In XP your Temp Folder can be found at:
C:\Documents and Settings\**User Account Name**\Local Settings\Temp

Local settings will be opaque compared to the normal yellow folders, this just means it is a normally hidden file.

You can delete this file with no harm to your computer. Windows will create a new folder when it needs to store temp files. Most of the files in this folder were used to help install programs or store data when accessing certain programs. Nothing is need to operate any of your programs.

Sometimes not all the files will let you delete them. A reboot to safe mode should let you remove them.

Always do a defrag after you remove the temp folder. It is a good idea to do it once a month on average anyway. It can sometimes free up hard drive space and speed up your PC.

Even if you don't get all the registry entries Windows does an ok job at purging unused registry entries. But it is not guaranteed. This is the basic way to avoid a format, but it is not guaranteed.

Also, the first places viruses like to hide is in your restore files. (right click My Computer then go to Properties. You will see a System Restore Tab) You can turn this off, it will speed up your PC a bit, free up a bit of file space and of course viruses will not be able to hide there. You wont be able to use the restore if you turn it off.

Not sure if any of this is useful in your case. Sorry if it isn't. I am not sure if this works with vista. I stopped doing tech work before vista came out and I don't use it myself.
 
TJ the problem for me with viruses and trojans is you can never be sure that they didn't hide themselves somewhere else in the system or attach themselves to some system file hiding out some where deep in C:\Windows. :eek:

For my peace of mind and the peace of mind of people's personal information that I store on my computer I'd much rather wipe the HD and start over again.

Now a great thing would if MS published checksums/hashes of their files, I wouldn't mind spending a couple of hours computing and comparing my file hashes to known hashes to be sure I was virus free.

All in all I'm pretty lucky, I haven't been hit in a bad way but I'm proactive and never go online with out protection. But any sign of something fishy and I'm wiping the HD to start over again.
 
lol no protection hey Dan (sure that wasnt a reference to using a condom) ! :)

anyway I always keep a ghost image of my system and since 80% are portable software I can just ghost the image over and away I go

love working with portables its great

www.portableapps.com

The PortableApps.com Suite and Platform is free. It contains no spyware. There are no advertisements. It isn't a limited or trial version. There is no additional hardware or software to buy. You don't even have to give out your email address. It's 100% free to use, free to copy and free to share.

have fun all