|
Posted by Nick Skrepetos on October 6, 2006, 1:30 pm
If you were Registered and logged in, you could reply and use other advanced thread options
Panya wrote:
> Hi,
>
> Recently, my computer is infected by some trojans.
> And I try to manually fix it (as before).
> Here is my usual pratice to remove trojan.
> -Boot in Safe mode.
> -Locate suspicious files in
> HKLM\Software\Microsoft\Windows\CurrentVersion\Run***
> -Remove those files then remove registry key
> -Reboot
> But this cant help me this time.
>
> I noticed the FAKE svchost.exe even I boot in Safe mode!
> I know that it is fake because I use ProcessExplorer
> and found that that svchost.exe process has no
> process description or image file path as the real ones.
> Its process icon is also a bit different.
> When I try to kill it. Is said that "Access is denied"
> I also cannot find any fake svchost.exe on my harddrives.
>
> What is this? On-memory process that has no physical file?
> Or there must be a trojan file out there
> but it can disguise its process name?
> Anybody knows how to deal with it?
> Thanks,
>
> Panya
Try scanning with SUPERAntiSpyware Free Edition here:
http://www.superantispyware.com
Nick Skrepetos
SUPERAntiSpyware.com
http://www.superantispyware.com
|