trojan horse cant be removed

previously my system has been detected by avast tht it got infected by a trojan horse, n i keep deleting it, removing it but still not successful at all. So i sent it to a technician. Right now, my 2nd pc has been infected, few hours ago.

when i was notified about the trojan, i clicked on the delete, a message pop up saying tht “The processs cannot access the file because it is being used by another process”. Neither can i move it to chest. I believed tht it has affected my OS too, how do i get rid of it?

i did all tht i can even by scanning it thoroughly in reboot. During tht process, those infected files seems to be cleared off, but once the window restarts, the trojan is still there, but perhaps in a different folder. Even now, the avast seems to stop running itself, it shuts off itself. :-[

Malware : Win32:Pepatch-Q [Trj]

Hi ajoebonnie,

What is your OS?

What is the location(s) of the file detected?

Please download any of the following you don’t already have, install, update and run a scan:

AVG Anti-Spyware: (Requires Win2000/XP)

http://www.ewido.net/en/

Spybot Search & Destroy:

http://www.safer-networking.org/

a-Squared:

http://www.emsisoft.com/en/software/free/

Ad-Aware:

http://www.download.com/3000-2144-10045910.html

Please post a HijackThis! log if none of these works:

http://www.bleepingcomputer.com/tutorials/tutorial42.html

Good luck!

have u tried the avast virus cleaner tool?it may can remove it…and try to do a scan with avg antispyware or spybot search & destroy(i use spybot but avg antispyware is very effective as well…)if nothing of these helps…i don’t know…then give a shot by running windows in safe mode and deleting the file that contains the trojan…but i think that ur trojan has a pretty gd spread rate…oh…also try to do an online scan in www.bitdefender.com or in www.trendmicro.com (i don’t know the exact link for the trendmicro online scan)…gd luck man :slight_smile:

my OS is Windows Xp Pro.

if i download these would it affect my avast from running properly? I just downloaded and installed a programme named Trojan Remover, but anyway, it doesn’t seem to work too.

i have notified tht the trojan is in C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5

All the programs I mentioned work well with avast!

You should also try running a program to clean out your temp files like CleanUp!:

http://www.stevengould.org/software/cleanup/

I have never heard of Trojan Remover; I doubt its effectiveness. Stick with the tried-and-trusted programs I mentioned.

alright, thanks!

will try them out now :slight_smile:

The programs suggested by Frank for the most part are on-demand programs (except AVG Anti-Spyware) none of which have any problem with avast or vice versa. However, when running other security program scans, it is best to pause the Standard Shield provider. This will speed the overall scan and avoid any possible conflict.

Before running any programs, it is best to clear the Temporary Internet Files and temp file locations, since they are temporary there is no point in scanning them if you can delete them.

Before running any programs, it is best to clear the Temporary Internet Files and temp file locations, since they are temporary there is no point in scanning them if you can delete them.

Very true. Sometimes an attempt to remove temp files will stall if malware is running from a temp file. CleanUp! is pretty brutal, and will clean files in use on reboot. If however it should fail to delete any temp files, move on to a Trojan scan and try deleting the temps files later.

:slight_smile: Hi “ajoe” :

 I never heard of "Trojan Remover" either; the programs recommended by Frank are those that
antiSPYWARE Expert Eric Howes recommends at : www.spywarewarrior.com/rogue_anti-spyware.htm#trustworthy . However, one of the ones there that Frank does not suggest is probably

the best, the FREE version of “SUPERantispyware” at www.superantispyware.com .
When a security program detects something, should ALWAYS select “quarantine” FIRST, not
“Delete”.
If none of these programs “solves” your problem, you will most likely need the guidance of
volunteer EXPERIENCED Malware Experts usually found on antiSPYWARE Support Forums, who
analyze “logs” from the “HijackThis” program, best downloaded from www.thespykiller.co.uk/files/HJTsetup.exe .
At the download prompt, choose “Save”.
Navigate to the saved file and double-click the installer, HJTsetup.exe.
HijackThis will be installed on your computer at C:\Program Files\HijackThis, making an entry in the start menu and also providing a desktop shortcut.
When the installation is complete, exit HijackThis.

Since you do not seem to have any antiSPYWARE program on your computer, I recommend
the forums at www.landzdown.com .

Frank : Does not “CleanUp” have “Delete Prefetch files” as one of their “automatic” Options !?
Another thread on this forum recommends NOT deleting Prefetch files" !?

As malware can hide in prefetch, I reckon it’s worth cleaning it out: the prefetch folder is rebuilt automatically and you only loose a few seconds in boot time.

EDIT: For routine temp file cleaning (when malware infection is not suspected) I don’t recommend cleaning the prefetch folder.

i think i had successfully removed those trojans or maybe not, right now, some of my system files had been removed too!

wat do i do?? i mean, most of my programmes cant be open in the sense tht, let say i click on the internet explorer icon, it cant be open, a pop up appear asking me whether to open it with?

wat do i do now? i think the clean up machines have realy cleared up all files tht has been infected by trojan, i guess right now even avast even isn’t working properly… wat should i do? n if all these have been settled, do i need anymore safeguard in order to prevent trojans from accessing my system? as far as i concern, avast isn’t tht efficient in clearing up trojans.

File association seems to be changed by the trojan.

It will be good if you download, install, update and run other trojan remover tools:
a-squared
Free AVG Antispyware
SUPERantispyware
Spyware Terminator

Most of the times you need specific tools to remove and clean a trojan infection. Follow Spiritsongs’ advices… :slight_smile:

so how do i fix the existing problems now? do i re install the window ? n how do i do it?

Use Google 8)
http://www.dougknox.com/xp/file_assoc.htm
Use the .exe association tool :slight_smile:

That was a good find Tech, I have a lot of Doug Knox’s Utilities, but that page is very handy to fix multiple file association problems.

As Tech informed you, the exe file association has been broken by a virus:

When you try to launch an application (.exe files), the following error message appears and the program does not run.

Cause

This problem occurs if the .exe file association in the registry is corrupt. This behavior is generally caused by viruses; one of which is SirCam virus, which modifies the .exe file association in registry.

http://windowsxp.mvps.org/exefile.htm

There’s also a utility to fix the problem on that page; I’m sure one of the solutions you have been offered will fix the problem quite easily.

As to Trojans, you can scan any suspect files with a-Squared and AVG Anti-Spyware along side avast! as a double check.

Remember Trojans are presented as something you would want on your computer- video codecs, cracks, keygens etc., and also that new Trojans emerge hourly so there’s no guarantee any scanner will detect them. The best thing you can do to avoid Trojans is to refrain from pulling large wooden horses mysteriously left outside your doors at night inside you castle: don’t download files from dodgy sources.

thanks!

gosh, it’s juz so scary to connect to the net nowadays… btw, those trojans’ juzt doesn’t seem to leave my laptop anyway…

i sent it to clean up, the technician did not format my laptop but attempted only to clean it up… but now when i on9, seems like there’s stil trojan found in it… can i juz leave it like tht? cos it’s juz so troublesome to get rid of it…

btw, he too installed me another anti-virus, McAfee…

thanks! juz quarantine? not to delete it at all? will it infect other system files in the future?

Well this will be avast forum… can you told your technician to get help at McAfee site?
I mean, if he installed McAfee he must have uninstalled avast, so we can`t help with avast anymore.
Maybe you want to come back later 8)