Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   PeachParts Mercedes-Benz Forum > General Discussions > Off-Topic Discussion

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 03-21-2012, 03:06 PM
whunter's Avatar
Moderator
 
Join Date: Dec 2003
Location: Metro Detroit, Michigan
Posts: 17,416
Help, Daughters Netbook computer has a trojan

TROJAN: svchost.exe(1036)

This is a win32 variant.

The computer is an acer ASPIRE ONE Netbook.

NOD32 anti-virus, and Malwarebytes are installed.

Assistance would be greatly appreciated.

.

Reply With Quote
  #2  
Old 03-21-2012, 03:08 PM
Banned
 
Join Date: Dec 2011
Location: Sharing my mother's basement with several liberals who can't hold a job.
Posts: 33,010
Quote:
Originally Posted by whunter View Post
TROJAN: svchost.exe(1036)

This is a win32 variant.

The computer is an acer ASPIRE ONE Netbook.

NOD32 anti-virus, and Malwarebytes are installed.

Assistance would be greatly appreciated.

.
When was last A/Virus update?
Try going into safe mode and run virus scan or can't you?
Reply With Quote
  #3  
Old 03-21-2012, 03:09 PM
vstech's Avatar
DD MOD, HVAC,MCP,Mac,GMAC
 
Join Date: Mar 2006
Location: Mount Holly, NC
Posts: 26,843
google.com
download rkill, and all it's variants.
pick one, and run it, THEN when it's finished run malware bytes and it should be removed.
__________________
John HAUL AWAY, OR CRUSHED CARS!!! HELP ME keep the cars out of the crusher! A/C Thread
"as I ride with my a/c on... I have fond memories of sweaty oily saturdays and spewing R12 into the air. THANKS for all you do!

My drivers:
1987 190D 2.5Turbo
1987 190D 2.5Turbo
1987 190D 2.5-5SPEED!!!

1987 300TD
1987 300TD
1994GMC 2500 6.5Turbo truck... I had to put the ladder somewhere!
Reply With Quote
  #4  
Old 03-21-2012, 03:15 PM
Banned
 
Join Date: Dec 2011
Location: Sharing my mother's basement with several liberals who can't hold a job.
Posts: 33,010
Quote:
Originally Posted by vstech View Post
google.com
download rkill, and all it's variants.
pick one, and run it, THEN when it's finished run malware bytes and it should be removed.
Might not be able to get in.
Reply With Quote
  #5  
Old 03-21-2012, 03:26 PM
tbomachines's Avatar
ಠ_ಠ
 
Join Date: Mar 2009
Location: Philadelphia
Posts: 7,371
Let us know if you can boot into safe mode. Right before the Windows loading screen press F8 and select "Safe mode without networking". Then run the A/V software. Safe mode will only load the most essential drivers to run. Svchost is network-related so you should select without networking...I am not positive if it loads or not anyways but that's your best first move.
__________________
TC
Current stable:
- 2004 Mazda RALLYWANKEL
- 2007 Saturn sky redline
- 2004 Explorer...under surgery.

Past: 135i, GTI, 300E, 300SD, 300SD, Stealth
Reply With Quote
  #6  
Old 03-21-2012, 03:28 PM
whunter's Avatar
Moderator
 
Join Date: Dec 2003
Location: Metro Detroit, Michigan
Posts: 17,416
Answer

Quote:
Originally Posted by Dudesky View Post
When was last A/Virus update?
Try going into safe mode and run virus scan or can't you?
Virus signatures update every hour.

Tried safe mode, wasted many hours, the Trojan is found but can not remove it.

.
Reply With Quote
  #7  
Old 03-21-2012, 03:29 PM
compu_85's Avatar
Cruisin on Electric Ave.
 
Join Date: May 2008
Location: La Conner, WA
Posts: 5,234
What OS? Any files on the machine she needs?

-J
__________________
1991 350SDL. 230,000 miles (new motor @ 150,000). Blown head gasket

Tesla Model 3. 205,000 miles. Been to 48 states!
Past: A fleet of VW TDIs.... including a V10,a Dieselgate Passat, and 2 ECOdiesels.
2014 Cadillac ELR
2013 Fiat 500E.
Reply With Quote
  #8  
Old 03-21-2012, 03:30 PM
whunter's Avatar
Moderator
 
Join Date: Dec 2003
Location: Metro Detroit, Michigan
Posts: 17,416
Thanks

Quote:
Originally Posted by vstech View Post
google.com
download rkill, and all it's variants.
pick one, and run it, THEN when it's finished run malware bytes and it should be removed.
Just finished loading them on a thumb drive.
Loading into her machine now.

.
Reply With Quote
  #9  
Old 03-21-2012, 04:07 PM
whunter's Avatar
Moderator
 
Join Date: Dec 2003
Location: Metro Detroit, Michigan
Posts: 17,416
Answer

Quote:
Originally Posted by compu_85 View Post
What OS? Any files on the machine she needs?

-J
windows xp home sp3
unknown school stuff.


.
Reply With Quote
  #10  
Old 03-21-2012, 04:25 PM
whunter's Avatar
Moderator
 
Join Date: Dec 2003
Location: Metro Detroit, Michigan
Posts: 17,416
Update

Quote:
Originally Posted by whunter View Post
Just finished loading them on a thumb drive.
Loading into her machine now.

.
NOD32 still finds but will not touch it.

Malwarebytes is running now.

The Trojan is taking huge resources = slow...
Reply With Quote
  #11  
Old 03-21-2012, 04:55 PM
engatwork's Avatar
Registered User
 
Join Date: May 2000
Location: Soperton, Ga. USA
Posts: 13,667
I recently had an issue where I was able to go back and have the computer reset a day or so earlier. I don't remember how I went about it. If I remember I'll let you know.

Can you go back to set it some time in the past?
__________________
Jim
Reply With Quote
  #12  
Old 03-21-2012, 05:03 PM
Fold on dotted line
 
Join Date: Aug 2007
Location: SE Mich
Posts: 3,284
Quote:
Originally Posted by engatwork View Post
I recently had an issue where I was able to go back and have the computer reset a day or so earlier. I don't remember how I went about it. If I remember I'll let you know.

Can you go back to set it some time in the past?
If you reset more than a week to a previous set point, Malwarebytes will work in non-safe (normal)mode,or always has for me.
__________________
Strelnik
Invest in America: Buy a Congressman!

1950 170SD
1951 Citroen 11BN
1953 Citroen 11BNF limo
1953 220a project
1959 180D
1960 190D
1960 Borgward Isabella TS 2dr
1983 240D daily driver
1983 380SL
1990 350SDL daily driver alt
3 x Citroen DS21M, down from 5
3 x Citroen 2CV, down from 6
Reply With Quote
  #13  
Old 03-21-2012, 05:04 PM
Banned
 
Join Date: Feb 2012
Location: In God's Arms
Posts: 134
Quote:
Originally Posted by engatwork View Post
I recently had an issue where I was able to go back and have the computer reset a day or so earlier. I don't remember how I went about it. If I remember I'll let you know.

Can you go back to set it some time in the past?

It is called system restore, and I have had to do it a few times before too! If it has Windows Vista or Windows 7 you can search at the bottom of the Start Menu. Just search System Restore. They you can go back a few days, and you shouldn't have the Trojan anymore, unless it was acquired before the reset.
Reply With Quote
  #14  
Old 03-21-2012, 05:32 PM
tyl604's Avatar
Registered User
 
Join Date: Feb 2008
Location: Atlanta, GA
Posts: 3,641
If you still have the problem, go to www.bleepingcomputers.com and find the virus section. Post a good description of your computer, operating system, and what's happening. They will have you download several programs which list the files on your computer. You will post the results for them to inspect. They will get back to you in about two days with a recommendation of how to fix it along with links so you can download the appropriate virus programs.

It is a computer geek forum and they can basically fix anything. Pretty much.
Reply With Quote
  #15  
Old 03-21-2012, 05:48 PM
whunter's Avatar
Moderator
 
Join Date: Dec 2003
Location: Metro Detroit, Michigan
Posts: 17,416
Daughter here--
I was helped by an awesome guy on NOD32's tech support. He used remote access to get the nasty thing taken care of. Thanks for the help, everyone!


.


Last edited by whunter; 03-21-2012 at 09:10 PM.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT -4. The time now is 07:50 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2024 Pelican Parts, LLC - Posts may be archived for display on the Peach Parts or Pelican Parts Website -    DMCA Registered Agent Contact Page