Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 24th, 2004, 09:36 PM
dostival dostival is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 3
Default Troj/Winflux-B

Helo all
I am having trouble removing this trojan.
I'm following sophos instruction to remove it, but it not work!!
The startup in registry keep coming back!
If i delete file it also comes back! why?
am i doing wrong?
I open regedit and find the keys sophos say, then i delete them.
They disapear but if I press F5 (update) they are back again.
Same with file.
I go to explorer and delete file c:\windows\backvol.exe.
But after i update the file is back!
How can i remove it?
Can tds help me?
Why can I not remove it?

This happens if i boot computer in safe mode too!

info:
http://www.sophos.com/virusinfo/anal...jwinfluxb.html
  #2  
Old August 24th, 2004, 09:39 PM
Blackspear's Avatar
Blackspear Blackspear is offline
Global Moderator
 
Join Date: Dec 2002
Location: Gold Coast, Queensland, Australia
Posts: 15,114
Default Re: Troj/Winflux-B

Do you have System Restore turn off ?

Have you edited the registry as they advise?

You will also need to edit the following registry entries, if present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\
and remove any reference to any file you deleted.

Locate the HKEY_LOCAL_MACHINE entries:
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(CLASS ID)\
delete only the entry with the path of the Trojan, nothing else.

Each user has a registry area named HKEY_USERS\[code number indicating user]\.

For each user locate the entry:
HKCU\[code number]\Software\Microsoft\Windows\CurrentVersion\Run\
HKCU\[code number]\Software\Microsoft\Windows\CurrentVersion\RunOnce\
and remove any reference to any file you deleted.

Close the registry editor.

Hope this helps...

Cheers
__________________
"Illegitimis non carborundum"
translation:
"Don't let the bastards grind you down"
U.S. General Joseph W. "Vinegar Joe" Stilwell (1883-1946)
Two Photographers
  #3  
Old August 24th, 2004, 10:00 PM
dostival dostival is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 3
Default Re: Troj/Winflux-B

Yes I have.

I have (tried) removed all of them.

This is also what sophos say:
"The Trojan has the ability to monitor these autostart entries and may restore them if they are deleted."

I think that is why my registry can not be deleted.
Sure I can delete them, but they keep coming back.
  #4  
Old August 25th, 2004, 02:14 AM
illukka's Avatar
illukka illukka is offline
Spyware Fighter
 
Join Date: Jun 2003
Location: S.A.V.O
Posts: 632
Default Re: Troj/Winflux-B

Quote:
Originally Posted by dostival
Can tds help me?


yes tds can help you. download and install it and do a full system scan(update before scanning)..

download here
http://tds.diamondcs.com.au/
update here
http://tds.diamondcs.com.au/index.php?page=update
basic configuration and info here
http://www.wilderssecurity.com/showthread.php?t=24666

this one drops several files, av sites write ups are not that helpful, because filenames are customisable.

flux also has a hidden startup .. making it difficult to remove completely.
so a dedicated anti trojan really is your best bet!

edit: you might want to post tds's scan report here
__________________
a proud supporter of THE GLORIOUS REDS

To Ride, Shoot Straight And Speak TheTruth
  #5  
Old August 26th, 2004, 01:55 AM
dostival dostival is offline
Infrequent Poster
 
Join Date: Aug 2004
Posts: 3
Default Re: Troj/Winflux-B

Ok, I tried it.
TDS finds it as RAT.Flux 1.0b.
I can right click and select "delete file" but it still comes back right after i delete it!
Same with registry.

So how do i else get rid of it??
  #6  
Old August 27th, 2004, 07:08 AM
illukka's Avatar
illukka illukka is offline
Spyware Fighter
 
Join Date: Jun 2003
Location: S.A.V.O
Posts: 632
Default Re: Troj/Winflux-B

can you boot into safe mode( tap f8 button while booting)

and scan with tds again?
__________________
a proud supporter of THE GLORIOUS REDS

To Ride, Shoot Straight And Speak TheTruth
  #7  
Old August 27th, 2004, 12:02 PM
Gavin - DiamondCS's Avatar
Gavin - DiamondCS Gavin - DiamondCS is offline
Former DCS Moderator
 
Join Date: Feb 2002
Location: Perth, Western Australia
Posts: 2,080
Default Re: Troj/Winflux-B

Fixed over at our forum, refer to this manual removal instructions for Flux any time
http://www.diamondcs.com.au/forum/sh...3562#post23562
Actually quite easy to remove like this, should only need the first 5 steps
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:29 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums