Trojan problem resolved.

MojoKrunch

Member
Nov 29, 2000
99
0
0
Downloaded a ?no cd? patch from KazaaLite and ran it.
Apparently it was a Trojan of some kind.
My virus scanner caught and disabled it.
But not before it made changes to my system, apparently.
It installed something called ?rohfemmoc.exe?.
I restarted the machine thinking the virus scanner had done its job and Windows took a bit longer than normal to boot.
A window pops up saying that ?rohfemmoc.exe? can?t be found.
Then I discover that I can?t launch any programs.
?Windows cannot find XXX?? dialogue box pops up when I try.
Not from the shortcuts on the desktop or from the Program Files folder.

So, I do some looking and find a prefetch file with the ?rohfemmoc.exe? and delete that.
Then I do a manual search of the registry and delete any entries with that name.
One entry was listed under a string with ?Shell? in the line and had ?explorer? & ?rohfemmoc.exe? in it, so I deleted the ?rohfemmoc.exe? portion.
Also located ?rohfemmoc.exe? in the startup/boot file and disabled it there.

Reboot and no more ?rohfemmoc.exe? but I still can?t launch programs without the ?Windows cannot find XXX?? dialogue box.

So I dig around a bit more and discover that I *can* launch programs if I right click, go to ?run as? and uncheck the ?Protect computer?? box.
Most everything runs fine.
But this doesn?t bode well.

I say most because after I get the Help program running I discover that some links in it to OS files don?t work.
It can?t find the MSINFO32 file. An ?error 2? window pops up.
And it won?t launch some of the other help tools like Disk Cleanup and Backup.
I get a ?This program will not start?? window.

The upside is my computer is still running and I haven?t had to reinstall the OS.
The downside is that I don?t have any restore points to go back to.

One odd thing.
When I was in the Help program and clicked on the Disk Cleanup link, the first thing under notes is a line that says ?XOXOX??
Hugs and kisses from Microsoft?
Hmmmm? lol

Any help would be greatly appreciated.
brett
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If I were you, I'd reformat the hard drive and reinstall Windows.
 

MojoKrunch

Member
Nov 29, 2000
99
0
0
//If I were you, I'd reformat the hard drive and reinstall Windows.//
That will be the last resort.
I'm thinking that unless I get some other ideas I'll try a dirty reinstall first.

Thanks
brett
 

viivo

Diamond Member
May 4, 2002
3,345
32
91
"rohfemmoc.exe"

Is that spelled correctly? I can't find anything on it anywhere.
 

MojoKrunch

Member
Nov 29, 2000
99
0
0
//"rohfemmoc.exe"
Is that spelled correctly? I can't find anything on it anywhere. //
Yep and neither could I.

According to my AV log the name of the trojan was "gkrfc.exe".

In retrospect I regret deleting the damn files now.

Thanks
brett
 

VicodiN

Senior member
May 6, 2002
576
0
0
Originally posted by: MojoKrunch
//"rohfemmoc.exe"
Is that spelled correctly? I can't find anything on it anywhere. //
Yep and neither could I.

According to my AV log the name of the trojan was "gkrfc.exe".

In retrospect I regret deleting the damn files now.

Thanks
brett

Dude, save yourself the headache, and do a fresh reinstall...
Also, by any chance did your AV log say what string of virus it is? The Type? That would help in telling you exactly what it did to your system, and perhaps allow people like me to further help ;)
 

MojoKrunch

Member
Nov 29, 2000
99
0
0
//Dude, save yourself the headache, and do a fresh reinstall...//
With all the software I have installed, its a headache either way... path of least resistance. lol

//Also, by any chance did your AV log say what string of virus it is? The Type? That would help in telling you exactly what it did to your system, and perhaps allow people like me to further help //
Nope. Not that I can tell.
I use Grisoft AVG 6, the free version so theres not a whole lot more info than what I posted.
AVG did id it as a trojan and the name of the file was GKRFC.exe.

Thanks
brett
 

MojoKrunch

Member
Nov 29, 2000
99
0
0
// Have you tryed a system restore from XP install disk?//
That was going to be my last resort.
Thankfully, I won't have to.
The virus/trojan had written to my registry in the key that controlled how explorer looks at EXE files.
It wrote "gkrfc.exe" into the line.
Deleted and everything works.

Thanks for the input guys. I appreciate it.

brett