Downloaded Trojan Horse!! GAH!

Noobtastic

Banned
Jul 9, 2005
3,721
0
0
I tried deleting it but it said "access denied". Reformatting is out of the question. Please, I need a quick fix.


Suggestions??!!!
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Do you have an antivirus program at the moment? Also, can you give the name of the site that the codec came from?
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
In the event that System Restore or your present antivirus software aren't getting the job done,

1) download a free 30-day trial of Kaspersky Antivirus Personal 6 from here: http://www.kaspersky.com/trials?chapter=186685140

2) install it with the default settings, right-click the red K icon in the System Tray, and Update it, then reboot as necessary

3) download this file: http://www.mechbgon.com/maxed-out.cfg

4) right-click the K icon and choose Settings, then click the Load button and aim it at the maxed-out.cfg file from step 3

5) now right-click the K icon and do a Scan My Computer

6) take a snack break :D while it plows through your system

7) also try this: http://siri.geekstogo.com/SmitfraudFix.php



After the 30-day trial period of Kaspersky ends, you can get most of its functionality from the free AOL Kaspersky: http://www.activevirusshield.com
 

JPB

Diamond Member
Jul 4, 2005
4,064
89
91
What is the trojan called ? It may be the one I had, if it is...I know how to remove it.
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Those PITA codec files are part of smitfraud. To date, they are:

eMedia Codec, HQ Codec, iCodecPack, iMediaCodec, IntCodec, iVideoCodec, Media-Codec, MediaCodec, MMediaCodec, MPCODEC, PCODEC, PowerCodec, SoftCodec, strCodec, TrueCodec, VidCodecs, VideoCompressionCodec, VideoKeyCodec, VideosCodec, WinMediaCodec, ZipCodec...

You may have gotten rid of it, but it wouldn't hurt to run SmitFraudFix because that will also fix the bad registry keys smitfraud causes

D/L it from: http://siri.urz.free.fr/Fix/SmitfraudFix.zip

After you've unzipped it, reboot into Safe Mode - important because tool will not work in Normal Mode!

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If it is infected and a clean version is found, you will be prompted to replace the infected wininet.dll with the clean file. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

Run your anti-spyware app to get rid of malware files that smitfraud may have installed.