PDA

View Full Version : Trojan


mimseridge
10-19-2008, 06:47 PM
I appear to have a virus (or more) running on my desktop pc.

I have run AVG Anti Virus (v7.5 Free version with all updates) and it identified numerous trojans on my C:\ disk (windows disk) and my E:\ disk (data disk). It deleted/isolated the identified viruses but I am still experiencing problems.
I have also run Lavasoft Ad Aware, Spy Bot and Win Optimizer

Problems:
Every now again and an Alert Window pops up saying "Possible Infection Click 'Check Now' to protect your pc" or something similar. I am suspicious of this message.
Task Manager has been deactivated (it says my Administrator has disabled it. I have not)
Display Panel has been deactivated (same message as above)
Control Panel, Programmes, Folders, Run, Search etc are missing from Windows Menu
Registry has been locked down (I tried "regedit" in Run and it says it has been locked by the Administrator)
Internet is working but oddly I am locked out of certain websites such as Trend Micro, Bit Defender etc I intended to use their online virus scanners but I cannot access them
In AVG there is a comment that Says "Boot Sector Changed C:\" or something to that effect
Every time I log on there is a message in the System Tray saying next to date & time saying "VIRUS ALERT!"
There are 3 black Shortcuts that appear on my desktop "Malware Defender", "Protect Your Privacy", & "System Error Fixer". They reappear when I log on even though I have repeatedly deleted them
PC is crashing though not frequently
I logged onto the Admistrator account and I can not access the "regedit" although I can access Control Panel, Programmes etc from Windows Menu
I can access "msconfig" (using Windows Key + R) but am not comfortable tinkering with it

Info:
I have two Windows Profiles "Administrator" (hidden) and my personal Profile both have Admin privileges
I am running Win XP SP2
I have Zone Alarm

I have just finished scanning my C:\ drive again and it seems clear but the problems still persist
It would appear some setting has been changed possibly in the Registry, which persists despite the viruses having been deleted?

Thanks

rjfvillarosa
10-19-2008, 07:18 PM
Every time I log on there is a message in the System Tray saying next to date & time saying "VIRUS ALERT!"
There are 3 black Shortcuts that appear on my desktop "Malware Defender", "Protect Your Privacy", & "System Error Fixer". They reappear when I log on even though I have repeatedly deleted them
You are doing the right thing by ignoring these. Try downloading and running Malwarebytes, you can download it free here www.malwarebytes.org. If you can run it in SafeMode.
If you are still having problems after running malwarebytes check the HJT sticky in the Securities forum and compare what scanners you have run against the recommended scanners then consider posting a HJT log for analysis.

Negeva
10-20-2008, 01:42 PM
I would post the HJT log after running a FULL system scan with malwarebytes. This Malware Defender is a scareware product as you can read about in the sticky.

Fixing access to regedit can be as simple as downloading TweakUI and asking it to fix it from the options it has. And the chances are we'll have to repair/remove some entries from the HOST and IE settings.

mimseridge
10-20-2008, 07:26 PM
Thanks for the advice. I could not access the software/website you guys posted as it too was "locked out"
In the end I went for a clean install of XP. I am one of those people that backs stuff up on a weekly basis so all it cost me was a few hours work re-installing everything.
Thanks anyway

Negeva
10-21-2008, 03:29 PM
Thanks for the advice. I could not access the software/website you guys posted as it too was "locked out"
In the end I went for a clean install of XP. I am one of those people that backs stuff up on a weekly basis so all it cost me was a few hours work re-installing everything.
Thanks anyway

With these newer infections especially the type you posted about it is far easier to nuke and re-install. Now might be an idea to look into hard-drive imaging programs such as Acronis TrueImage. These programs take a 'snap-shot' of your drive and can recover back to that snapshot in minutes and not hours.

Now you're fixed and clean, I advise you it looking at malware prevention. Using Spybot Search and Destroy's Immunize feature is one way and so is using MVP HOSTS (http://www.mvps.org/winhelp2002/hosts.htm), which uses one of the methods Spybot uses to block unwanted 'software'.