Results 1 to 13 of 13

Thread: Very quick question on Trojan

  1. #1
    Formerly known as Andehh Andeh13's Avatar
    Join Date
    Oct 2005
    Location
    Northampton
    Posts
    3,354
    Thanks
    855
    Thanked
    258 times in 153 posts
    • Andeh13's system
      • Motherboard:
      • Gigabyte GA-P35
      • CPU:
      • Intel Q6600
      • Memory:
      • 4gb Corsair XMS2 800mhz
      • Storage:
      • 1 x 250gb Western Digital AAKS, 2 x 500gb Western Digital AAKS, 1TB WD Caviar Green
      • Graphics card(s):
      • BFG Geforce 8800GTS 512mb
      • PSU:
      • Corsair HX520
      • Case:
      • Antec 900
      • Operating System:
      • Windows 7 64bit
      • Monitor(s):
      • Samsung 24" & Sony 17"
      • Internet:
      • Virgin 10mb... hate them!

    Very quick question on Trojan

    A mate of mine has got a nasty Trojan on his computer(he knows what folder it is in and how it got there) that causes it to BSOD every time he turns it on. Even starting up in safe mode causes it to BSOD. He has some work on there he needs to get off.

    If I plug his HDD into my computer, and copy & paste the work file off before formatting the HDD (so he can reinstall windows xp), will i risk infecting my computer?


    Thanks guys, and sorry its in the wrong forum, just want to get a response ASAP before i do it.

  2. #2
    DILLIGAF GoNz0's Avatar
    Join Date
    Jun 2006
    Location
    Derby
    Posts
    10,872
    Thanks
    632
    Thanked
    1,192 times in 945 posts
    • GoNz0's system
      • Motherboard:
      • Asus Rampage V Extreme
      • CPU:
      • i7 something X99 based
      • Memory:
      • 16gb GSkill
      • Storage:
      • 4 SSD's + WD Red
      • Graphics card(s):
      • GTX980 Strix WC
      • PSU:
      • Enermax Galaxy 1250 (9 years and counting)
      • Case:
      • Corsair 900D
      • Operating System:
      • win10 64bit
      • Monitor(s):
      • Dell 24"
      • Internet:
      • 220mb Cable

    Re: Very quick question on Trojan

    plug it in and scan it 1st, see if it will boot afterward

  3. #3
    Pseudo-Mad Scientist Whiternoise's Avatar
    Join Date
    Apr 2006
    Location
    Surrey
    Posts
    4,274
    Thanks
    166
    Thanked
    386 times in 233 posts
    • Whiternoise's system
      • Motherboard:
      • DFI LANPARTY JR P45-T2RS
      • CPU:
      • Q6600
      • Memory:
      • 8GB DDR2
      • Storage:
      • 5.6TB Total
      • Graphics card(s):
      • HD4780
      • PSU:
      • 425W Modu82+ Enermax
      • Case:
      • Silverstone TJ08b
      • Operating System:
      • Win7 64
      • Monitor(s):
      • Dell 23" IPS
      • Internet:
      • 1Gbps Fibre Line

    Re: Very quick question on Trojan

    Why not just get a Linux live disk (Ubuntu should do) and then go and nuke the folder? Or use a windows live disk that has AV software installed on it..?

    After you've done that just boot from a normal windows install cd and perform a repair if you need to (shouldn't do anything to your files).

    I suspect it's done something else if it's blue screening on boot - like it's hijacked some registry settings, so running a scan from your computer should do the job. Something Spybot S/D will sort out any registry problems that a straight antivirus program won't.

    I've just finished getting rid of Win32.Sality/NAR from my boot camp partition. Absolute nightmare. It blocked all the major AV websites, killed all running AV services and stopped task manager. I finally got rid of it by installing Nod32 (install file passed through from OS X) and immediately doing a scan. I tried that before and it would only open (while the virus was still rampant) once after the install. But yeah, infects just about EVERY .exe file on the hard drive, spreads to USB sticks, etc. etc. The infect count was about 500 from one virus!

    I say this because you should be aware (and probably are) that some viruses infect a lot more than just one folder so if it's a similar trojan, it's possible. If you've got up to date antivirus/antispyware on your PC you should be fine, but it's always worth taking precautions.
    Last edited by Whiternoise; 12-01-2010 at 04:01 PM.

  4. #4
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,038
    Thanks
    1,878
    Thanked
    3,378 times in 2,715 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Very quick question on Trojan

    Quote Originally Posted by Andehh View Post
    A mate of mine has got a nasty Trojan on his computer(he knows what folder it is in and how it got there) that causes it to BSOD every time he turns it on. Even starting up in safe mode causes it to BSOD. He has some work on there he needs to get off.

    If I plug his HDD into my computer, and copy & paste the work file off before formatting the HDD (so he can reinstall windows xp), will i risk infecting my computer?
    Yes, if by doing so you touch the infected file at all (eg caching etc.) chances are quite low though.

    But better would be to boot off the XP disc into the repair console and manually delete the folder.

  5. #5
    Senior Member
    Join Date
    Feb 2008
    Posts
    925
    Thanks
    4
    Thanked
    161 times in 148 posts
    • smargh's system
      • Motherboard:
      • Gigabyte GA-EP45-UD3P
      • CPU:
      • Xeon E5450 with 775-to-771 Mod
      • Memory:
      • 16GB Crucial
      • Storage:
      • Intel X25-M G2 80GB/Adaptec 3405 4x 2TB Ultrastar RAID1 / 1x 6TB Hitachi He6 / Dying 2TB Samsung
      • Graphics card(s):
      • GTX 750 Ti
      • PSU:
      • Seasonic X-560
      • Case:
      • Lian-Li PC-A71
      • Operating System:
      • Windows 7 Ultimate 64bit
      • Monitor(s):
      • BenQ G2400WD
      • Internet:
      • Really Crap ADSL2 <3Mbit

    Re: Very quick question on Trojan

    It's fine to plug in another drive as long as you have autorun/autoplay disabled completely, and if you do get any "do you want to play/explore/run...?" prompts be sure to just cancel the window, as they are often easily faked with XP.

    Whether the BSOD is caused by the malware depends on what the BSOD text actually says.

    To avoid potential re-infection, be wary of the content of his & your USB sticks if they have been plugged in to his PC.

  6. #6
    Admin (Ret'd)
    Join Date
    Jul 2003
    Posts
    18,481
    Thanks
    1,016
    Thanked
    3,208 times in 2,281 posts

    Re: Very quick question on Trojan

    Personally, I'm a fan of the scorched earth approach to removing nasty virii and trojii.

    So, worst case, I end up doing a format, including MBR etc, and then re-installing apps etc, from a known uninfected disc image, manually patching an updating, and then reloading data files. It tkaes a couple of hours and is a pain, but I get peace of mind from knowing the infectious little beggars aren't still lurking anywhere.

    Of course, it's easier to do that without losing a truckload of stuff if you take regular backups, especially of essential data, etc, and if you take the precaution of doing regular Ghost/TrueImage type backups.

    As such, it might not help your mate now, buy does perhaps hint at the road to take in the future.

  7. #7
    Anthropomorphic Personification shaithis's Avatar
    Join Date
    Apr 2004
    Location
    The Last Aerie
    Posts
    10,857
    Thanks
    645
    Thanked
    872 times in 736 posts
    • shaithis's system
      • Motherboard:
      • Asus P8Z77 WS
      • CPU:
      • i7 3770k @ 4.5GHz
      • Memory:
      • 32GB HyperX 1866
      • Storage:
      • Lots!
      • Graphics card(s):
      • Sapphire Fury X
      • PSU:
      • Corsair HX850
      • Case:
      • Corsair 600T (White)
      • Operating System:
      • Windows 10 x64
      • Monitor(s):
      • 2 x Dell 3007
      • Internet:
      • Zen 80Mb Fibre

    Re: Very quick question on Trojan

    Quote Originally Posted by Saracen View Post
    Personally, I'm a fan of the scorched earth approach to removing nasty virii and trojii.
    like this ?
    Main PC: Asus Rampage IV Extreme / 3960X@4.5GHz / Antec H1200 Pro / 32GB DDR3-1866 Quad Channel / Sapphire Fury X / Areca 1680 / 850W EVGA SuperNOVA Gold 2 / Corsair 600T / 2x Dell 3007 / 4 x 250GB SSD + 2 x 80GB SSD / 4 x 1TB HDD (RAID 10) / Windows 10 Pro, Yosemite & Ubuntu
    HTPC: AsRock Z77 Pro 4 / 3770K@4.2GHz / 24GB / GTX 1080 / SST-LC20 / Antec TP-550 / Hisense 65k5510 4K TV / HTC Vive / 2 x 240GB SSD + 12TB HDD Space / Race Seat / Logitech G29 / Win 10 Pro
    HTPC2: Asus AM1I-A / 5150 / 4GB / Corsair Force 3 240GB / Silverstone SST-ML05B + ST30SF / Samsung UE60H6200 TV / Windows 10 Pro
    Spare/Loaner: Gigabyte EX58-UD5 / i950 / 12GB / HD7870 / Corsair 300R / Silverpower 700W modular
    NAS 1: HP N40L / 12GB ECC RAM / 2 x 3TB Arrays || NAS 2: Dell PowerEdge T110 II / 24GB ECC RAM / 2 x 3TB Hybrid arrays || Network:Buffalo WZR-1166DHP w/DD-WRT + HP ProCurve 1800-24G
    Laptop: Dell Precision 5510 Printer: HP CP1515n || Phone: Huawei P30 || Other: Samsung Galaxy Tab 4 Pro 10.1 CM14 / Playstation 4 + G29 + 2TB Hybrid drive

  8. #8
    Formerly known as Andehh Andeh13's Avatar
    Join Date
    Oct 2005
    Location
    Northampton
    Posts
    3,354
    Thanks
    855
    Thanked
    258 times in 153 posts
    • Andeh13's system
      • Motherboard:
      • Gigabyte GA-P35
      • CPU:
      • Intel Q6600
      • Memory:
      • 4gb Corsair XMS2 800mhz
      • Storage:
      • 1 x 250gb Western Digital AAKS, 2 x 500gb Western Digital AAKS, 1TB WD Caviar Green
      • Graphics card(s):
      • BFG Geforce 8800GTS 512mb
      • PSU:
      • Corsair HX520
      • Case:
      • Antec 900
      • Operating System:
      • Windows 7 64bit
      • Monitor(s):
      • Samsung 24" & Sony 17"
      • Internet:
      • Virgin 10mb... hate them!

    Re: Very quick question on Trojan

    Many thanks for the response guys. We decided it was safer just to format it and start again, he found a copy of the work he'd done on a memory stick!


    Ironically enough, now my PC wont start up (his HDD was only plugged in once it was formatted). It freezes during the 'welcome' screen of Windows 7. Time to download a repair disc

  9. #9
    Late Night Ninja! CrazyMonkey's Avatar
    Join Date
    Oct 2006
    Location
    Bristol
    Posts
    1,510
    Thanks
    29
    Thanked
    44 times in 43 posts
    • CrazyMonkey's system
      • Motherboard:
      • Asus M4N98TD Evo
      • CPU:
      • Phenom II X6 1055T @ 4.1ghz
      • Memory:
      • 8GB DDR3 Dominator @ 1700mhz
      • Storage:
      • 120GB OCZ Vertex 2E - 1TB Hitatchi
      • Graphics card(s):
      • 2x 460 1GB
      • PSU:
      • 850W
      • Case:
      • Silverstone Fortress FT02R-WRI Ltd.Edition
      • Operating System:
      • Win 7, XP, Server2008 RC1, Gentoo
      • Monitor(s):
      • 24" Acer LED - 22" Belinea - 19" Samsung - 19" IIyama
      • Internet:
      • 50 MB Virgin Media Cable

    Re: Very quick question on Trojan

    Why dont you just delete the infected files outside of windows? Regain access and then scan? or run further scans from outside windows too..

  10. #10
    Not a good person scaryjim's Avatar
    Join Date
    Jan 2009
    Location
    Gateshead
    Posts
    15,196
    Thanks
    1,232
    Thanked
    2,290 times in 1,873 posts
    • scaryjim's system
      • Motherboard:
      • Dell Inspiron
      • CPU:
      • Core i5 8250U
      • Memory:
      • 2x 4GB DDR4 2666
      • Storage:
      • 128GB M.2 SSD + 1TB HDD
      • Graphics card(s):
      • Radeon R5 230
      • PSU:
      • Battery/Dell brick
      • Case:
      • Dell Inspiron 5570
      • Operating System:
      • Windows 10
      • Monitor(s):
      • 15" 1080p laptop panel

    Re: Very quick question on Trojan

    Quote Originally Posted by Andehh View Post
    Many thanks for the response guys. We decided it was safer just to format it and start again, he found a copy of the work he'd done on a memory stick!
    I take it you made sure the memory stick was scanned prior to being used?

  11. #11
    Formerly known as Andehh Andeh13's Avatar
    Join Date
    Oct 2005
    Location
    Northampton
    Posts
    3,354
    Thanks
    855
    Thanked
    258 times in 153 posts
    • Andeh13's system
      • Motherboard:
      • Gigabyte GA-P35
      • CPU:
      • Intel Q6600
      • Memory:
      • 4gb Corsair XMS2 800mhz
      • Storage:
      • 1 x 250gb Western Digital AAKS, 2 x 500gb Western Digital AAKS, 1TB WD Caviar Green
      • Graphics card(s):
      • BFG Geforce 8800GTS 512mb
      • PSU:
      • Corsair HX520
      • Case:
      • Antec 900
      • Operating System:
      • Windows 7 64bit
      • Monitor(s):
      • Samsung 24" & Sony 17"
      • Internet:
      • Virgin 10mb... hate them!

    Re: Very quick question on Trojan

    Quote Originally Posted by scaryjim View Post
    I take it you made sure the memory stick was scanned prior to being used?
    Yeh, double checked that. Fixed my computer, dodgy DVD was in the drive which wasn't letting the PC start for some reason!

  12. #12
    Registered User
    Join Date
    Jul 2003
    Location
    Cornwall/Weston-Super-Mare
    Posts
    5,337
    Thanks
    438
    Thanked
    308 times in 261 posts
    • Behemoth's system
      • Motherboard:
      • Gigabyte mATX
      • CPU:
      • Phenom 2 X2 555 BE
      • Memory:
      • 8 Gig DDR3 Corsair XMS 3 1600 MHz
      • Storage:
      • 4 TB's Storage
      • Graphics card(s):
      • Gigabyte GTX 460 OC2
      • PSU:
      • OCZ StealthStream 2 600 Watt
      • Case:
      • Silverstone TJ08-E
      • Operating System:
      • Windows 7 64 Bit
      • Monitor(s):
      • HP x23LED
      • Internet:
      • BT Broadband

    Re: Very quick question on Trojan

    Quote Originally Posted by Saracen View Post
    Personally, I'm a fan of the scorched earth approach to removing nasty virii and trojii.

    So, worst case, I end up doing a format, including MBR etc, and then re-installing apps etc, from a known uninfected disc image, manually patching an updating, and then reloading data files. It tkaes a couple of hours and is a pain, but I get peace of mind from knowing the infectious little beggars aren't still lurking anywhere.

    Of course, it's easier to do that without losing a truckload of stuff if you take regular backups, especially of essential data, etc, and if you take the precaution of doing regular Ghost/TrueImage type backups.

    As such, it might not help your mate now, buy does perhaps hint at the road to take in the future.
    Thats exactly what I do. After you've had a virus and you have been lucky enough to have been able to disinfect your system I always find things don't work properly after, or it comes back again. That said it would help if the people I help out used a decent security package like Kaspersky in the first place.

    I know re-installing everythng from scratch can be a right pain in the gentlemen veg but I'd rather sepnd hours doing it right the first time, than spending hours doing yet another disinfection of the problem which you thought you cured only some days before.

  13. #13
    Banned
    Join Date
    Jan 2010
    Posts
    199
    Thanks
    0
    Thanked
    3 times in 3 posts

    Re: Very quick question on Trojan

    Full format etc seems the safest bet.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Just a quick question re DFI LP DK X48 T2R
    By spiderdany in forum SCAN.care@HEXUS
    Replies: 0
    Last Post: 19-08-2008, 06:37 PM
  2. Quick Question - Just placed an order...
    By fonz_valo in forum SCAN.care@HEXUS
    Replies: 3
    Last Post: 01-08-2008, 10:05 AM
  3. Just a quick question - Hard Drive
    By Crazy Fool in forum PC Hardware and Components
    Replies: 2
    Last Post: 13-09-2005, 03:20 PM
  4. Quick Question: PSU's with 1x120mm fan question
    By philyau in forum PC Hardware and Components
    Replies: 10
    Last Post: 05-09-2005, 02:30 PM
  5. Quick Linux question from a newbie...
    By madmonkey in forum Software
    Replies: 19
    Last Post: 26-08-2005, 09:07 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •