Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Possible Trojan? Unable to find.

Posted on 2004-04-02
10
Medium Priority
?
404 Views
Last Modified: 2010-04-13
When I try and access "MY Computer", try and open up "my documents", or even try and open "My Network Places. The computer system will not allow me to open these items and the screen will refresh and "kick me" off the internet (if connected). Also I am not able to open up the "control panel". It acts as though there is a trojan or worm but when I do a virus scan and use "The Cleaner) the system is unable to find any trojan horses or viruses. ANy ideas?
0
Comment
Question by:manch03
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
  • 2
  • +2
10 Comments
 
LVL 44

Expert Comment

by:CrazyOne
ID: 10745519
Boot to safe mode and use this

Stinger
BackDoor-AQJ, Bat/Mumu.worm, Exploit-DcomRpc, IPCScan, IRC/Flood.ap, IRC/Flood.bi, IRC/Flood.cd, NTServiceLoader, PWS-Sincom, W32/Bugbear@MM, W32/Deborm.worm.gen, W32/Dumaru@MM, W32/Elkern.cav, W32/Fizzer.gen@MM, W32/FunLove, W32/Klez, W32/Lirva, W32/Lovgate, W32/Lovsan.worm, W32/Mimail@MM, W32/MoFei.worm, W32/Mumu.b.worm, W32/Nachi.worm, W32/Nimda, W32/Sdbot.worm.gen, W32/SirCam@MM, W32/Sobig, W32/SQLSlammer.worm, W32/Yaha@MM
http://vil.nai.com/vil/stinger/
0
 
LVL 7

Expert Comment

by:Worked4me
ID: 10745533

Hey Manch03,

  I had some of the same symptoms on a pc try this link and see if it helps.
Also does it allow you to access the regedit and taskmanager?

http://www.experts-exchange.com/Operating_Systems/Win2000/Q_20940675.html
0
Use Case: Protecting a Hybrid Cloud Infrastructure

Microsoft Azure is rapidly becoming the norm in dynamic IT environments. This document describes the challenges that organizations face when protecting data in a hybrid cloud IT environment and presents a use case to demonstrate how Acronis Backup protects all data.

 

Author Comment

by:manch03
ID: 10745543
I currently have Spybot-S &D no luck finding anything. The first web site is unavailable. Is there a certain program you would like me to try?
0
 
LVL 44

Expert Comment

by:CrazyOne
ID: 10745552
Run the program I posted "Stinger"
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745799
And another Trojan removal tool, to add to CO's comment..

Trojan Remover :http://www.simplysup.com/
0
 
LVL 7

Expert Comment

by:Worked4me
ID: 10747392

Hey Manch03,

  This question was answered on 4/1/2004 I can' t figure why the link is unavailable now.

The site for the WORM_AGOBOT is
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.DU
or
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.JP

There are many variants for these and the names for the process may differ from
what is listed since mine was MSclock.exe.  As for Spybot, I tried Norton Antivirus, Mcaffre Virus
Scanner, Stinger, Ad-aware 6, spybot, all updated and with update definitions and none of them detected this worm.
0
 

Author Comment

by:manch03
ID: 10748480
At this point I have tried just about everything. The Stinger could not find any viruses or trojans. Ad-Ware found 16 objects and deleted them. Most of the on-line virus scanners were not available because I do not have access to Internet Explorer (will not open) so I have to use Netscape. Most sites (Anti-Virus) are prompting me to use Internet Explorer. I will proceed with the next two suggustions from "fatel Exception" and "Worked4me". NO solution yet. Any more suggustions?
0
 
LVL 6

Accepted Solution

by:
akboss earned 2000 total points
ID: 10749175
HijackThis  
http://209.133.47.200/~merijn/files/HijackThis.exe

see if you can download and run this.

Post the log so we can take a look see.
0
 

Author Comment

by:manch03
ID: 10750413
I am still not sure which Virus or Trojan that was in the computer but the program HijackThis worked and everything is working fine. Thanks
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
On September 18, Experts Exchange launched the first installment of the Help Bell, a new feature for Premium Members, Team Accounts, and Qualified Experts. The Help Bell will serve as an additional tool to help teams increase question visibility.
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…
In this video, Percona Director of Solution Engineering Jon Tobin discusses the function and features of Percona Server for MongoDB. How Percona can help Percona can help you determine if Percona Server for MongoDB is the right solution for …
Suggested Courses

721 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question