How do you remove Trojan Win32/BOAXXE.I

A

alxrays

I've tried Spybot,Adaware, STopzilla, PC Tools Antivirus program, Sophos,
McAfee,
Malwarebytes,etc..
I can not remove this Spyware.Please let me know what else I could do to
remove
Trojan Win32/BOAXXE.I
 
M

Mick Murphy

Install "Malwarebytes" and "Spybot search & destroy"
Once installed, and updated, reboot, go into Safe Mode, and scan while there.
All info below.

http://www.spybot.info/en/index.html

Spybot Search & Destroy 1.6 is a very good, FREE Anti-Spyware Program.
Download, install, update, and immunize your System with it.
Then SCAN with it.
Update it, and scan your System once a fortnight.

http://www.malwarebytes.org/mbam.php

Malwarebytes is as the name says, a Malware Remover!
For the Free version scroll down their page to either download from
Download.com, or Major Geeks.com

Download, install, and update.

Important re: Safe Mode
If you happen to find a problem that you can’t uninstall / delete, reboot
the computer, and go into Safe Mode.
To get into Safe mode, tap F8 right at Power On / Startup, and use UP arrow
key to get to Safe Mode from list of options, then hit ENTER.
RESCAN your computer with your Anti-Virus, Malwarebytes and Spybot S & D
while in Safe Mode.

If unable to install above Programs in Normal Mode:
Sometimes Trojans, Viruses, Malware, etc stop you installing and/or updating
Programs to remove them.
If that happens, reboot into Safe Mode with Networking (from F8 list of
Startup Options), and install, update and scan from there.
 
D

David H. Lipman

From: "Randem" <[email protected]>


If you are going to answer, give SPECIFIC advice for the malware at hand not some generic
stuff that leaves people scratching their heads.
 
D

David H. Lipman

From: "alxrays" <[email protected]>

| I've tried Spybot,Adaware, STopzilla, PC Tools Antivirus program, Sophos,
| McAfee,
| Malwarebytes,etc..
| I can not remove this Spyware.Please let me know what else I could do to
| remove
| Trojan Win32/BOAXXE.I
| --
| thank you

| --
| thank you



Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe

Then post the contents of the HJT log in your post in one of the below expert forums...

{ Please - Do NOT post the HJT Log here ! }

Forums where you can get expert advice for HiJack This! (HJT) Logs.

NOTE: Registration is REQUIRED in any of the below before posting a log

Suggested primary:
http://www.thespykiller.co.uk/index.php?board=3.0

Suggested secondary:
http://www.bleepingcomputer.com/forums/forum22.html
http://www.malwarebytes.org/forums/index.php?showforum=7

Suggested tertiary:
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.atribune.org/forums/index.php?showforum=9
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://forum.networktechs.com/forumdisplay.php?f=130
http://forums.maddoktor2.com/index.php?showforum=17
http://www.spywarewarrior.com/viewforum.php?f=5
http://forums.spywareinfo.com/index.php?showforum=18
http://forums.techguy.org/f54-s.html
http://forums.tomcoyote.org/index.php?showforum=27
http://forums.subratam.org/index.php?showforum=7
http://www.5starsupport.com/ipboard/index.php?showforum=18
http://aumha.net/viewforum.php?f=30
http://makephpbb.com/phpbb/viewforum.php?f=2
http://forums.techguy.org/54-security/
http://forums.security-central.us/forumdisplay.php?f=13
 
L

Leythos

Well, if you coul READ... It tell you what you need to know and will remove
just about everything. But that information would elude you...

With a Sig that violates Usenet standards, look like spam, why would
anyone even read your posts....
 
F

FredW

I really don't care what you think. If one doesn't want real answers then
keep your heads in the sand...


Reread the advice of David H. Lipman
He really knows what he is talking about, you don't.
:-(
 
F

FredW

How would you know? You don't have enough sense to read and see what is in
the document before attemtpting to judge ANYTHING!


I read your "document" completely and your "30 years experience" is
nowhere visible.

Reread the advice of David H. Lipman.
He knows what he is talking about, you don't seem to have a clue.
:-(
 
L

Leythos

I really don't care what you think. If one doesn't want real answers then
keep your heads in the sand...

So, you claim you don't want to be a good participant of Usenet, not
follow Usenet standards, not show respect for existing norms in a old
community system....

You sound more and more like the "I'm the only important thing in the
world" time with each post.

The posting standards for Usenet are available via searches, it's "not
my opinion" that I'm trying to get you to see - it would help you be a
better member of the "Community" if you actually cared.
 
A

alxrays

Hi R. McCarty,
Thank you but it didn't work -I guess it's because I have a single
Browser.But I did find more information regarding the trojan infested in my
computer. it comes up as Win32 Rootkit. Podnuha.trojan
I've tried changing it in RegEdit but I get Access Denied
 
A

alxrays

Hi Mick,
Thank you but it didn't work -I did find more information regarding the
trojan infested in my computer. It comes up as Win32 Rootkit. Podnuha.trojan
I've tried changing it in RegEdit but I get Access Denied
 
A

alxrays

Hi Dave,
I found the problem when scanning with HiJack This-
It comes up with the Following:
BHO:(no name) (05EB7E2A-55E5-4C1A-9808-C832FC3E3278)
C;/Windows/System32/cfgbkendk.dll
I place a check to remove it but it keeps coming back. So I went into
REGEDIT and found it there, But I still can not remove it, I keep getting
Access Denied.
When scanning with Anti Virus Progams it tells me this is a Win32
Rootkit.Podnuha.Trojan but it can not Quarrentine or delete it.
I'm lost- I guess I have to re-format my computer.
 
R

Randem

Incorrect, I am not the one telling other that what they do is wrong along
with the ideas and solutions they provide. the only ones who do that are
afraid that someone else has ideas that differ from theirs and might
possibly be better so they bass other without providing ONE iota of proof of
anything... For or against. They are just fear mongers that prey on thers
and should be in the same category at the SCAREWARE makers...

--
Randem Systems
Your Installation Specialist
The Top Inno Setup Script Generator
http://www.randem.com/innoscript.html
 
R

Randem

Scare mongers attempt to create fear for other ideas and solutions that are
not thier own. They attempt to trash other ideas without giving ANY evident
as to why they state what they state. Since you have no proof of ANYTHING,
one because you have neither tried the solutions or have any evidence that
they do not work, you are only attempting to scare others into your web of
lies...

--
Randem Systems
Your Installation Specialist
The Top Inno Setup Script Generator
http://www.randem.com/innoscript.html
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads


Top