Results 1 to 7 of 7

Thread: Troian infection and running services

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Βασιλευς και Αυτοκρατωρ Αρχης Member Centurio Nixalsverdrus's Avatar
    Join Date
    Jan 2007
    Location
    Γερμανια Ελευθερα
    Posts
    2,321

    Default Troian infection and running services

    Hi,

    unfortunately my computer got infected by a Troian lately. I'm not sure if I got entirely rid of it yet. To my knowledge, the viciousness of most Troians lies in the fact that they get into your registry to get restarted with every Windows start.

    Do you know the following services that get started every time Windows starts? I suspect them to be created by the Troian.

    1. prun.exe / prunnet. Resided in username/Lokale Einstellungen/Temp/prun.exe
    2. P17Helper. Command from Registry: Rundll32 P17.dll, P17Helper It's still in the recycle bin, because I'm not entirely sure, I think it might be a little program of Creative Soundblaster
    3. BM215d2bec. Command: Rundll32.exe "C:\windows\system32\ojpfkatv.dll", s
    4. 226e1870. Command: Rundll32.exe "C:\windows\system32\dheikmmn.dll", b
    Also, I suspect a process called CTSVCCDA.exe. It's in system32 and I'm not sure about it...

    I encountered these in the registry. Unfortunately I did not write down the name of each infected file, but no. 4 was definitely detected as infected. I noticed these "prun" thing in the manager and I have never seen it before.

    Of course there is always a danger in deleting entries from the registry. The ones left now I definetely know. What do you think? Anything else I should / should not delete?

    Thank you very much for your help.

    PS: My PC showed definitely very erratic behaviour. Killing these entries stopped it, but now my RTW won't start, and I'm afraid that it's not entirely deleted or that I deleted too much. Thx.
    Last edited by Centurio Nixalsverdrus; 09-16-2008 at 01:54.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Single Sign On provided by vBSSO