NOD32 acting really weird...

Discussion in 'NOD32 version 2 Forum' started by Azn_Tweaker, Jul 1, 2004.

Thread Status:
Not open for further replies.
  1. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    i just got an virus yesterday and now it seems that NOD32 doesnt even open. but the control Center is working normal. the virus got detect from AMON. the virus is called " Win32/prorat.12.trojan" and "win32/prorat.17.trojan"

    Please help me.
     
  2. kjempen

    kjempen Registered Member

    Joined:
    May 6, 2004
    Posts:
    379
    This is a bit of a nasty trojan. If I remember correctly, it also has a firewall/antivirus killer feature. The best way to really clean up after this trojan is probably to use an anti-trojan dedicated program, such as Trojan Defence Suite (should clean up all the registry entries from this trojan). Download a trial from the TDS web page , restart your computer in safe mode and run a complete scan (although most of the trojan components should be located in C:\WINDOWS , C:\WINDOWS\system and C:\WINDOWS\system32). If TDS should happen to fail to start (because of the antivirus killer), rename the tds-3.exe file into notepad.exe for example, and then run it.
     
  3. Marcos

    Marcos Eset Staff Account

    Joined:
    Nov 22, 2002
    Posts:
    14,374
    Maybe you could try running nod32.exe with the /ah parameter in safe mode or using NOD32 for DOS. If NOD32 detects a probable unknown NewHeur_PE virus, please rename the file and send it to samples@nod32.com for analysis.
     
  4. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    Hi :D

    thanks for the replies. i got it fixed now. :D
     
  5. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    57,722
    Location:
    Texas

    How did you fix it?
     
  6. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    my last resort. the old Reformat Way..
    i think that trojan disable NOD32?
     
  7. pepito

    pepito Registered Member

    Joined:
    May 2, 2004
    Posts:
    57
    Location:
    Australia

    You had to re-format your HDD to get rid of it?

    That's a bit of a worry. Due to large number of installed apps, re-formats are a huge task for me.
     
  8. kjempen

    kjempen Registered Member

    Joined:
    May 6, 2004
    Posts:
    379
    A bit drastic measure, yes. I've been infected with one of those ProRat trojans. It did disable my NOD32 yes, and I basically got rid of the trojan using TDS 3 (in the method I described in my previous post in this thread). Once TDS 3 had identified all the "infected" files, I just renamed them adding the ".txt" extension at the end. Then I could reboot and everything was back to normal (including NOD32).
     
  9. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    only took 2 hrs to reformat and get all my stuff back :D
     
  10. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    Hi :)
    maybe i should try out "TDS 3". is it really good?
     
  11. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    It is ;) Hop over to the TDS support forum, have a glance at the sticky posts and start a thread on TDS over there in case you want to ;).

    regards.

    paul
     
  12. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    thanks Paul :D
     
  13. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    My pleasure ;)

    regards.

    paul
     
  14. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    Paul, i have one more question, whats the latest version for TDS3?
    sorry if this is off topic...
     
  15. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    The one as available over on their site ;).

    Let's hop over to the TDS support forum from now on (as for TDS of course), OK ;)

    regards,

    paul
     
  16. Azn_Tweaker

    Azn_Tweaker Registered Member

    Joined:
    Jun 26, 2004
    Posts:
    120
    Location:
    Canada, Toronto
    of Course Paul
     
  17. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    ;)

    regards.

    paul
     
  18. larstri

    larstri Guest



    Hey got the same problem as you here in Norway...pleace help
     
  19. Paul Wilders

    Paul Wilders Administrator

    Joined:
    Jul 1, 2001
    Posts:
    12,472
    Location:
    The Netherlands
    Follow the advice as posted above ;)

    regards,

    paul
     
  20. naft

    naft Guest

    awesome help, i was just having this same exact problem.
    thanks to search engines and knowledgeable people, im good to go.
     
Thread Status:
Not open for further replies.