WinXP, trojan hidden startup locations???

WinXP, trojan hidden startup locations???

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
WinXP, trojan hidden startup locations??? mfc 04-10-2007
Posted by mfc on April 10, 2007, 8:47 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Please help, I have a trojan and am trying to kill it myself, All the free
Antivirus and Spyware software have failed to kill it so far. Here is what I
have done so far :-

1. I have killed everything in the startup registry keys i cant verify to be
genuine I have just the following left
a. ctfmon.exe - used by ms office
b. avg7_cc - used by avg anti virus
c. zonealarm client
d. nvcpldaemon - used by nvida

2. The trojan was creating exes in the system32 directory so i created text
files of the same name and set them to read only so they cant be override by
the trojan

3. i have checked that i do not have a login script attached to my profile.

I believe the trojan cannot start now, but i still get errors using bootup
:-

"The NTVDM CPU has encounted illegal instructions" and it gives the name of
the exe that was being created by the trojan which cant start now because
its been replaced by my read only text file.


My question is, what causes the NTVDM to try and execute? I cannot see
anything in the start up.





Posted by Nick Domukhovsky on April 10, 2007, 8:13 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Please help, I have a trojan and am trying to kill it myself, All the free
> Antivirus and Spyware software have failed to kill it so far. Here is what I
> have done so far :-
>
> 1. I have killed everything in the startup registry keys i cant verify to be
> genuine I have just the following left
> a. ctfmon.exe - used by ms office
> b. avg7_cc - used by avg anti virus
> c. zonealarm client
> d. nvcpldaemon - used by nvida
>
> 2. The trojan was creating exes in the system32 directory so i created text
> files of the same name and set them to read only so they cant be override by
> the trojan
>
> 3. i have checked that i do not have a login script attached to my profile.
>
> I believe the trojan cannot start now, but i still get errors using bootup
> :-
>
> "The NTVDM CPU has encounted illegal instructions" and it gives the name of
> the exe that was being created by the trojan which cant start now because
> its been replaced by my read only text file.
>
>
> My question is, what causes the NTVDM to try and execute? I cannot see
> anything in the start up.
>
Are you sure that you are remove *all* startup occurrences? To be
completely sure use autoruns.exe utility from sysinternals suite.

--
With best regards
Nickolay Domukhovsky, MCSA

Posted by mfc on April 10, 2007, 3:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks...managed to kill it. It was a really nasty one and managed to hook
itself to the winlogon process via a key in
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlogon\Notify\cmdmant

So thats one more start up place to look.

>> Please help, I have a trojan and am trying to kill it myself, All the
>> free
>> Antivirus and Spyware software have failed to kill it so far. Here is
>> what I
>> have done so far :-
>>
>> 1. I have killed everything in the startup registry keys i cant verify to
>> be
>> genuine I have just the following left
>> a. ctfmon.exe - used by ms office
>> b. avg7_cc - used by avg anti virus
>> c. zonealarm client
>> d. nvcpldaemon - used by nvida
>>
>> 2. The trojan was creating exes in the system32 directory so i created
>> text
>> files of the same name and set them to read only so they cant be override
>> by
>> the trojan
>>
>> 3. i have checked that i do not have a login script attached to my
>> profile.
>>
>> I believe the trojan cannot start now, but i still get errors using
>> bootup
>> :-
>>
>> "The NTVDM CPU has encounted illegal instructions" and it gives the name
>> of
>> the exe that was being created by the trojan which cant start now because
>> its been replaced by my read only text file.
>>
>>
>> My question is, what causes the NTVDM to try and execute? I cannot see
>> anything in the start up.
>>
> Are you sure that you are remove *all* startup occurrences? To be
> completely sure use autoruns.exe utility from sysinternals suite.
>
> --
> With best regards
> Nickolay Domukhovsky, MCSA



Posted by Malke on April 10, 2007, 9:05 am
If you were  Registered and logged in, you could reply and use other advanced thread options
mfc wrote:
> Please help, I have a trojan and am trying to kill it myself, All the free
> Antivirus and Spyware software have failed to kill it so far. Here is what I
> have done so far :-
>
> 1. I have killed everything in the startup registry keys i cant verify to be
> genuine I have just the following left
> a. ctfmon.exe - used by ms office
> b. avg7_cc - used by avg anti virus
> c. zonealarm client
> d. nvcpldaemon - used by nvida
>
> 2. The trojan was creating exes in the system32 directory so i created text
> files of the same name and set them to read only so they cant be override by
> the trojan
>
> 3. i have checked that i do not have a login script attached to my profile.
>
> I believe the trojan cannot start now, but i still get errors using bootup
> :-
>
> "The NTVDM CPU has encounted illegal instructions" and it gives the name of
> the exe that was being created by the trojan which cant start now because
> its been replaced by my read only text file.
>
>
> My question is, what causes the NTVDM to try and execute? I cannot see
> anything in the start up.

Obviously your computer is not clean and whatever you've done hasn't
been adequate to remove it. Since you weren't specific about what you've
done or what trojan you have, I can't guess. Please refer to the malware
removal steps at this link:

http://www.elephantboycomputers.com/page2.html#Removing_Malware

If you have already followed all the preparatory steps, scanning with
Sysclean or Multi-AV, etc., and done all the work in Safe Mode and still
can't remove whatever you have then run HijackThis and post your log in
one of the specialty forums listed at the link above (not here, please).


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Similar ThreadsPosted
*sobbing quetly* trojan in my winxp pro service pro serv. pack 1 December 10, 2007, 10:32 pm
trojan.startup.nameshifter.EW/wingu/EZ August 16, 2005, 6:11 pm
wvurs.dll Trojan.Startup.NameShifter.HN January 6, 2006, 1:19 am
Hidden folders, files April 5, 2007, 11:19 am
Avira finds 3 hidden objects... June 16, 2008, 10:54 pm
Why doesn't Avira find hidden files anymore? July 7, 2008, 3:24 am
HELP BACKLIGHT DETECT STRANGE HIDDEN FILE(SEVERE WINDOWS 2000 INFECTION) February 2, 2007, 3:17 am
Anyone interested in LUA on WinXP? February 7, 2006, 6:35 pm
New WinXP PRO Install - Have I got everything? June 19, 2008, 2:58 am
12-16-06 Computer, WinXP, keeps shutting down December 15, 2006, 8:48 pm

The site map in XML format XML site map

Contact Us | Privacy Policy