Solved

Trojan Horse?

Posted on 2000-03-09
8
192 Views
Last Modified: 2013-12-28
I think I have a Trojan Horse in my boot sector.I'm Running win98se and it became slow & jerky so I went to run scan disk in Norton first & was told I had an unknown program locking my C drive. I looked at what was running & saw a program called Image-C running in the background. Its not in the start menu that I can find. I closed it & ran NAV scan & was told it was unable to read my Boot record. I ran scan disk in windows & was told. "Scan disk cannot check drive because the disk is not properly formatted or a program such as a disk utitity has locked it" I looked in the boot file & everything looks ok but this file its called 386grabber= vgafull.3gr. I don't know how to find this thing if thats not it because I don't really know where to look & what it is. I need help bad and I always get it here. Thanks Bill
0
Comment
Question by:W1Cheney
8 Comments
 
LVL 6

Expert Comment

by:sgenther
ID: 2602166
You may have to boot 98 with a virus free 98 boot disk. Then run norton anti-virus to clean the virus.
If that doesn't work you can always try booting from the clean boot disk and try running "fdisk /mbr" to restore the boot record.
0
 
LVL 15

Expert Comment

by:hewittg
ID: 2602310
W1,
If the Trojan is your problem, go to this page.  It will help.

Glenn

http://www.iinet.net.au/help/trojanhelp.html

0
 
LVL 2

Expert Comment

by:msledd
ID: 2602425
Hi!

That doesn't sound like a virus, but more like a program (a system utility like... Norton for instance) do you have any drive imaging/backup protection programs?

What I suggest is that you:

1. search for the Image-C program on your hard drive using FIND>Files or Folders (its location may very well tell you exactly what it is virus or otherwise).

2. Disable all startup programs to try and locate the culprit, adding them back one by one till the errors re-appear (assuming they disappear when you disable the startups) Go to START>RUN and type MSCONFIG. Under the General tab, select "selective startup". Then go to the Startup tab and uncheck everything. Click OK and re-boot.

Although you very well may need to also fdisk your Master boot record as sgenther said (it won't hurt)

Keep us posted :o)
~Ms
0
Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

 
LVL 1

Expert Comment

by:jbeaman
ID: 2602428
The program called Image-C that you are refering to is Norton Image.  It takes a snapshot (image) of each of your drives.  My hunch is you have Norton System Works 2000 or Norton Utilites 2000 installed on your PC.  I would recommend pressing CTRL-ALT-DEL and  then "end task" on everything in the close program list except EXPLORER.  Then try running scan disk again.  If all else fails, boot into win95 in safe mode.

The fill VGAFULL.3GR is a win95 and win98 installed file, so I would recommend leaving that alone.

HTH,
John
0
 

Author Comment

by:W1Cheney
ID: 2602635
You are right about image-c It had nothing to do with the problem. I had just done a virus update from norton and It had looked at my files to see what I needed. I think that was it. I still have the problem though. I will try the other things that have been suggested & will post back. Thanks to all.
0
 

Expert Comment

by:asnack
ID: 2602869
This sounds more like a video problem. The 386grabber=vgafull.3gr is a windows 3.1 display reference. You might be having a problem with using old Direct X drivers. So I recommed that you use the latest version of direct X. Reinstall your video card drivers and check for the updates. Also download the correct MDF(monitor definition file) for your display. Defrag your hard drive and enjoy.
0
 
LVL 2

Accepted Solution

by:
craig_capel earned 200 total points
ID: 2605149
yeah, a Trojan is far to big to get into the bootsector....

Yeah, your looking for something thats not there..... I have seen this problem before, look in your startup dirs including, Startup folder... and in the Registry: try here

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Runservices

or you may want to check your c:\autoexec.bat or win.ini for something thats causing this, did i hear Norton? :) Remove it, see if it does the trick
0
 

Author Comment

by:W1Cheney
ID: 2634746
I removed Norton & reinstalled it & things were ok. Now why I can't tell you? It just cleared up. "Strange" Thanks for all the good help Bill
0

Featured Post

Secure Your Active Directory - April 20, 2017

Active Directory plays a critical role in your company’s IT infrastructure and keeping it secure in today’s hacker-infested world is a must.
Microsoft published 300+ pages of guidance, but who has the time, money, and resources to implement? Register now to find an easier way.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Today, still in the boom of Apple, PC's and products, nearly 50% of the computer users use Windows as graphical operating systems. If you are among those users who love windows, but are grappling to keep the system's hard drive optimized, then you s…
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
The viewer will learn how to successfully create a multiboot device using the SARDU utility on Windows 7. Start the SARDU utility: Change the image directory to wherever you store your ISOs, this will prevent you from having 2 copies of an ISO wit…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question