# Need help eradicating a Trojan Horse

**URL:** <https://boards.straightdope.com/t/need-help-eradicating-a-trojan-horse/282553>\
**Category:** Factual Questions\
**Created:** [January 1, 2005, 1:41pm UTC](https://boards.straightdope.com/t/need-help-eradicating-a-trojan-horse/282553 "2005-01-01T13:41:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![VunderBob](https://avatars.discourse-cdn.com/v4/letter/v/839c29/32.png) [@VunderBob](https://boards.straightdope.com/u/VunderBob)\
**Post date:** [January 1, 2005, 1:41pm UTC](https://boards.straightdope.com/t/need-help-eradicating-a-trojan-horse/282553/1 "2005-01-01T13:41:00Z")

</div>

I managed to wind up with a Trojan Horse on my computer, despite all my antivirus, spyware, and firewall software set to kill. I have the Backdoor.Prorat.2xxx trojan, and despite what Symantec says about manually swatting the beast, I can’t get the job done.

**SOMETHING** is buried deep within my PC to bring the beastie back to life each time I try to kill it. The general, exec summary of Symantec’s procedure is:  
[ol]  
[li]Shut off system restore (done that)[/li][li]Use regedit to reverse registry changes (done that)[/li][li]Reboot in safe mode, and delete all the program files (done that)[/li][/ol]  
Yet, when I restart, there it is in all it’s fecking glory.

For the moment, I have my firewall set to disallow any net traffic by the TH components, just so I don’t become a spambot.

Anyone out there have advice/experience with this one?

---

<div class="post-metadata">

**Author:** ![ParentalAdvisory](https://avatars.discourse-cdn.com/v4/letter/p/53a042/32.png) [@ParentalAdvisory](https://boards.straightdope.com/u/ParentalAdvisory)\
**Post date:** [January 1, 2005, 1:56pm UTC](https://boards.straightdope.com/t/need-help-eradicating-a-trojan-horse/282553/2 "2005-01-01T13:56:42Z")

</div>

> [@VunderBob](#):
>
> [ul]  
> [li]Reboot in safe mode, and delete all the program files (done that)[/li][/ul]

After you do this, remain in safe mode, and then run your anti-virus stuff.

This also heled me out with a few things…

[http://www.download.com/Zero-Spyware/3000-8022\_4-10329083.html](http://www.download.com/Zero-Spyware/3000-8022_4-10329083.html)

---

<div class="post-metadata">

**Author:** ![VunderBob](https://avatars.discourse-cdn.com/v4/letter/v/839c29/32.png) [@VunderBob](https://boards.straightdope.com/u/VunderBob)\
**Post date:** [January 1, 2005, 8:19pm UTC](https://boards.straightdope.com/t/need-help-eradicating-a-trojan-horse/282553/3 "2005-01-01T20:19:44Z")

</div>

I ended up pulling out my XP install disk, and booted off that. It had a repair option, which gave me console access without starting Windows. I could then delete all the TH files manually, which got rid of the d\*mned thing.

Safe Mode didn’t work in this case, because the TH burrows into the XP code to the point that even Safe Mode starts it up, and I couldn’t delete because the file were in use.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [January 2, 2005, 2:16am UTC](https://boards.straightdope.com/t/need-help-eradicating-a-trojan-horse/282553/4 "2005-01-02T02:16:37Z")

</div>

Try downloading hijackthis and posting a log.
