Author Topic: [Strange situation] I can't get rid of "Win32:Trojan-gen. {Delphi}"  (Read 14868 times)

0 Members and 1 Guest are viewing this topic.

MarduK

  • Guest
Re: [Strange situation] I can't get rid of "Win32:Trojan-gen. {Delphi}"
« Reply #15 on: March 11, 2006, 08:32:56 PM »
Well FreewheelinFrank I haven't been able to get rid of it after following your suggestion.  And I haven't been able to find the "Free Sophos Command Line Scanner" in the site you provided..?

Spiritsongs thanks a lot for your suggestion to check onthe AumHa forums. I can't even remember when I last visited those forums so it's existance was completely off my mind.. Anyway I've posted all the same stuff there too, let's see what kind of results am I going to get from there..
And thanks for commenting on the Services.. I didn't even notice the changes, I use my own setting for the Services, thanks again for pointing that out too..

I hope I won't have to format the system drive and re-install everything in the end  ???
Thanks a lot again for all your help

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: [Strange situation] I can't get rid of "Win32:Trojan-gen. {Delphi}"
« Reply #16 on: March 12, 2006, 09:49:32 AM »
The Sophos scanner is here:

http://www.sophos.com/tools/sav32sfx.exe

The latest updates are here:

http://www.sophos.com/downloads/ide/403_ides.zip

The Sophos page recommends running the scanner from a CD, but it will run from the hard disk assuming the Trojan is not preventing this.

Run SAV32sfx.exe and move the folder produced to the root directory. (C:/)

[EDIT: just checked and C:/SAV32CLI is the default location when unzipping, so there is no need to move the folder.]

Unzip the updates file and move the contents to the same folder.

Reboot into safe mode with command prompt. Navigate to the folder you created:

[Edit: Navigate to the root directory using cd.. ]

CD SAV32CLI, I think it should be. [Edit: it is]

Type in this command and hit enter:

SAV32CLI -REMOVE -P=C:\LOGFILE.TXT

Another possibility is TrojanHunter, which will remove process injecting Trojans. (It has a free working trial.)

http://www.misec.net/

To attempt manual removal, delete or edit these registry values and reboot:

Quote
The following registry entries are created to run emgfx.exe, nwisse.exe, winspols.scr and svch0st.com on startup:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(tt9381D8F2-0288-11D0-9501-00AA00B911A5)
StubPath
<System>\emgfx.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
nwisse
<Windows>\nwisse.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe winspols.scr

[Delete winspols.scr NOT the whole key]

(the default value for this registry entry is "Explorer.exe" which causes the Microsoft file <Windows>\Explorer.exe

to be run on startup).

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
System
<System>\SVCH0ST.com

[Edit: regedit will run from the command prompt in safe mode. Explorer.exe is not running in safe mode with command prompt so you should be able to delete the winspols.scr entry from the explorer.exe key without any problem.]

Good luck!
« Last Edit: March 12, 2006, 12:20:51 PM by FreewheelinFrank »
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog