Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Error Message - Help..

Status
Not open for further replies.

Juleswc

Technical User
Jan 6, 2004
33
GB
Hi All,

Whenever I load Windows 2000 I get the following error message.

C:\WINNT\SYSTEM32\WHBOY.exe

Anybody know, what, where and how I get rid of this?

ANY advice would be great!

Thanks

Jules
 
Searching with Google gives the description of this trojan TROJ_LEGMIR.BI
It modifies the following registry entry to ensure its automatic execution at every Windows logon:

From:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\
CurrentVersion\Winlogon
Shell = "Explorer.exe"

To:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\
CurrentVersion\Winlogon
Shell = "Explorer.exe C:\WINDOWS\System32\whboy.exe"

See the rest of the description here:
----------------------------------------

Everybody has the right to be stupid -- but some people abuse the privilege. (a quote from Stalin - and I am one of the abusers, sometimes...)
----------------------------------------
Experienced in the IT-chaos since 1984...
 
Thanks for the info, It looks like I'll just format the hard drive, and start from scratch...

Cheers

Jules
 
you dont have to.......



Aftertaf

"Resolve is never stronger than the night before it was never weaker
 
suggestions as to how I can get rid of this?
As I would of course prefer not to format the disk...

I've booted in safe mode, and ran Norton Virus...
 
1. Go to Safe Mode
2. Start regedit, and navigate to:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

Edit the value "Shell" so that it says only:
"Explorer.exe"

3. Delete three files:
\Winnt\bak.exe – this is a copy of the original Trojan.
\Winnt\System32\whboy.exe – this is a copy of the original Trojan.
\Winnt\System32\whboy.txt – this is a .DLL component of the Trojan that is used to run its malicious routines.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top