Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 07-16-2012, 09:12 AM   #1
Member (9 bit)
 
Join Date: Jul 2001
Location: Western Pennsylvania
Posts: 300
Trojan disguised as Security Essentials Popup?

Yesterday I got the following popup message from what I assumed was Security Essentials ""Security Essentials detected items on your PC that it doesn't recognize. By sending the files listed below, you can help Microsoft analysts determine whether these items are malicious." I had a basic membership in the Microsoft Active Protection Service (MAPS), so I agreed to sending the sample, which was a dll located in one of the My Documents folder.

That's when my problems began. Shortly after, another popup, not from MSE, informed me that I had a disk sector error and to run a scan immediately, which I didn't do. Instead I shut down. After a cold start reboot, most of my desktop was gone and that remained was a link to this "suggested scan". With my system unusable I commenced the scan at the end of which it showed a bunch of supposed errors and asked that I activate their program to fix it? Instead I shut down once again. I rebooted in safe mode, did a system restore to the day before yesterday.

That restored my desktop and start menu, but problems remained. My Documents, Shared Files, the MalwareBytes folders were marked read only and hidden. That meant I could run, but not update MalwareBytes. After removing the hidden read only attributes I was able to run a full scan. One other problem was that Firefox had a locked profile, so it wouldn't run.

All problems seem to fixed now. After running full scans of MSE, MWB, Trend Micro Housecall and SuperAntiSpyWare, nothing was ever detected.

My question is: What happened to my computer? What worries me is that once I was able to scan, nothing got detected. I find it hard to believe that a system restore and fixing some attribute problems could fix things. Please share any similar experiences, insights, and opinions.

BTW: My OS is Windows Home XP, SP3

Last edited by oryx; 07-16-2012 at 09:22 AM. Reason: No OS listed.
oryx is offline   Reply With Quote
Old 07-16-2012, 09:32 AM   #2
Ride 'em Cowboy
Staff
Premium Member
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,495
Here's the Sticky thread that addresses the same problem: missing start menu shortcuts and hidden folders
__________________
Imagine a world where dogs took bad owners to the pound...
EzyStvy is offline   Reply With Quote
Old 07-16-2012, 10:15 AM   #3
Member (9 bit)
 
Join Date: Jul 2001
Location: Western Pennsylvania
Posts: 300
I've run TDSSkiller which showed nothing. I've run unhide.exe which seems to have unhidden too much. One example is the uninstall folders in the WINDOWS directory which I remember as hidden previously.
oryx is offline   Reply With Quote
Old 07-17-2012, 06:04 AM   #4
Member (9 bit)
 
Join Date: Jul 2001
Location: Western Pennsylvania
Posts: 300
Update: Ran Microsoft Safety Scanner which detected and removed Trojan: FakeSysdef. The description of it fit the symptoms I had. Safety Scanner ran for 90 minutes, so apparently it is a deeper scan than all the others which failed to detect anything.
oryx is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -5. The time now is 05:52 AM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1