Windows 7 Forums


Windows 7: Help with removing new Trojan

01 Feb 2010   #1

Windows 7 Pro 64bit SP1 / XP Pro 32bit
Phoenix
 
 
Help with removing new Trojan

Well didn't take long...my girlfriend's computer with a brand new Win 7 Pro installation has a Trojan...Bit Defender stops it from accessing the Internet and Quarantines it...but it keeps reappearing as a new name. The location is always the same though as shown in the attached JPG. The Folders (source) always stay the same...but Bit Defender just Quarantines it...can't seem to find the source and remove it tho ?



The C:\Windows\ServiceProfiles\NetworkService\AppData\Temp\ is always the same...the wbwb.tmp changes...the svchost.exe is always the same.

When I first opened the W\SP\NS directory...there was no "APPDATA" folder...and some how I managed to get the "\SERVICEPROFILE\NETWORKSERVICE\" to become hidden...while trying to show the APPDATA folder ?

Any help on how to both get the SERVICEPROFILE\NETWORKSERVICE folders to reappear, and, isolate this Trojan and remove it will be greatly appreciated.

Thanks, Tim
My System SpecsSystem Spec

01 Feb 2010   #2

Windows 7 Ult, Windows 8 Pro,
San Diego
 
 

You can enable "show hidden files and folders" by going to device manager then choose folder options and click to show files and folder then hit apply. You might try either MalWarebytes or spybot S&D to get that trojen.
Attached Thumbnails
Help with removing new Trojan-folder-options.jpg  
My System SpecsSystem Spec
01 Feb 2010   #3

win7 ultimate / virtual box
weston super mare, UK
 
 

Quote   Quote: Originally Posted by chev65 View Post
You can enable "show hidden files and folders" by going to device manager then choose folder options and click to show files and folder then hit apply. You might try either MalWarebytes or spybot S&D to get that trojen.
I agree with chev65 and suggest you run malwarebytes in safe mode twice
My System SpecsSystem Spec
.


01 Feb 2010   #4

Windows 7 Pro 64bit SP1 / XP Pro 32bit
Phoenix
 
 

Thanks guys...downloading malwarebytes now (free version I'm assuming ). Do I install this normally before rebooting to safe mode...or install it after rebooting to safe mode ?

Tim
My System SpecsSystem Spec
01 Feb 2010   #5

Win 7 Ultimate SP1 x64
SG
 
 

Quote   Quote: Originally Posted by trinaz View Post
Thanks guys...downloading malwarebytes now (free version I'm assuming ). Do I install this normally before rebooting to safe mode...or install it after rebooting to safe mode ?

Tim
You should install the program normally then reboot to safe mode and run malwarebytes scan.
My System SpecsSystem Spec
01 Feb 2010   #6

 
 

First thing after install is to check for updates.
My System SpecsSystem Spec
01 Feb 2010   #7

Windows® 8 Pro (64-bit)
Mumbai, India
 
 

Hi there, scan with Hitman Pro.
Downloads - SurfRight
My System SpecsSystem Spec
02 Feb 2010   #8
jav

Windows 7 Ultimate x86 SP1
 
 

Quote   Quote: Originally Posted by trinaz View Post
Thanks guys...downloading malwarebytes now (free version I'm assuming ). Do I install this normally before rebooting to safe mode...or install it after rebooting to safe mode ?

Tim
Hello Tim
1. Install it on normal mode.
Update it.
Run Quick scan with it on Normal mode
Tick all detection except those on C:\System Voulme Information folders
Click remove selected.
It will open up lof file.
Post it here.

2. Now run Full scan and tick all drives.
same instructions as above.
Post back log.


For other guys who recommended safe mode. Sorry for hijacking your posts, but: Malwarebytes and Safe mode
Hope you guys will understand me.


Quote   Quote: Originally Posted by Dinesh View Post
Hi there, scan with Hitman Pro.
Downloads - SurfRight

+1
Do this one aswell.
Don't worry it's really fast.
My System SpecsSystem Spec
Reply

 Help with removing new Trojan problems?



Thread Tools



Similar help and support threads for: Help with removing new Trojan
Thread Forum
Trojan.Sirefef virus, problems removing it System Security
Removing Win32/Malagent Trojan - The Easiest Way System Security
System infected after removing trojan. System changes on its own. System Security
Trojan:Win32/FakeSpypro & Trojan:JS/FakeSpypro System Security
Trojan.VB.VZO System Security


All times are GMT -5. The time now is 09:00 PM.


Seven Forums Android App Seven Forums IOS App Follow us on Facebook

Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32