Click to See Complete Forum and Search --> : My third trogan in the past two weeks
dayneman1
January 4th, 2004, 10:04 PM
I run on Windows Xp home and I have now found my third Trojan of the past two weeks in this folder, C:\Program Files\Windows NT\Kernel32 , and the Trojan was named as hider.exe
Do I need this folder our can it safely be deleted. Any information on this folder would be great.
tyfon
January 4th, 2004, 10:14 PM
third trojan in two weeks? Ok i am also a newbie and i dont know if you should remove it for certain (even though i know that normally it shouldn't be such an easy task) but..... do you use any firewall protection or antivirus software? If not consider that carefully....also consider carefully becoming a linux user.....:)
Cheers
Und3ertak3r
January 4th, 2004, 10:16 PM
Seems you are not practicing safe computing.. get a condom..
I would not recomend deleteing the C:\Program Files\Windows NT Folder. If it has a subfolder Kernal32 It could be sus..
A quick search on the file you mention yeilded the following..
http://antivirus.nih.gov/archives/floodvar.asp
http://www.google.com.au/search?sourceid=navclient&ie=UTF-8&oe=UTF-8&q=hider%2Eexe
You may be best advised to D/L The Cleaner from Moosoft.. and remove the crap properly..
Cheers
dayneman1
January 4th, 2004, 10:25 PM
Yes I do use Norton firewall 2004 and Norton antivirus 2004. And the way I found the Trojans is from the cleaner, and yes I have deleted the trogans. I was just wondering if it was ok to delete the folder holding them because it has other files in it. I would love to linux but i have smaller ones using the computer to, and i don't think the would like if i changed the OS.
Agent_Steal
January 4th, 2004, 10:56 PM
Have you thought about making accounts for them ? If not then maybe it might be a good idea. Here's an article that should help you do that :
Sharing a Computer - Create User Accounts (http://www.microsoft.com/windowsxp/home/using/howto/gettingstarted/sharing/default.asp)
Also I would not recommened that you use software like Kazaa since well it's virus ridden.
As for deleting the sub-folder humm well since I dont know much info about it. I dont know what files are within that sub-folder. I really wouldn't advise that you delete it.
I hope this helps ....
Tedob1
January 4th, 2004, 11:01 PM
hider.exe does as its name implys. it hides things. its not a trojan in itself but is used by worms and warez group hackers to hide processes they dont want you to see, like radmin, serve-u, an mIRC client just about anything. my guess is its not the third trojan you got but a third component of the first one. do an update for you AV software and do a full system scan.
id also venture to say you firewall is not configured correctly to allow these things in
im not familar with XPhome but i cant imagine microsoft puting system files in the "programs" directory. system32 yes but not programs. if you would, please list the other files in that directory.
Modderfokker
January 5th, 2004, 12:10 AM
when little ones use the computer is wise to monitor what they download and what cookies/etc that they accept, basicially secure your system down, but at the same time tell the other users to ask you before downloading or using anything suspicious.