|
![]() |
Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security | |
Need help to KILL this trojan horse/virus
|
||
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) | ||||||||||||
|
AMD Overclocker
![]() |
Was browsing some websites then a torjan horse downloaded itself. Its spread and AVG cant do ****. It wont let me access websites that contain anti virus programs either. Heres a hijackthis log.
Logfile of HijackThis v1.99.1 Scan saved at 17:10:44, on 04/11/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Unable to get Internet Explorer version! Quote:
__________________
"I can't carry a conversation when I'm alone with Hisashi. That cool Hisashi becomes shy. Probably we become too conscious of each other because we're similar."
|
||||||||||||
|
|
|
|
|
#2 (permalink) | |||||||||||||
|
4.0ghz
![]() |
malwarebytes might do the trick ??
__________________
Water Cooled Case suggestions Cosmos S w/Classified water cooled(1st) w/ heatkiller and feser 360 rad NZXT Tempest mod log(360 installed) (Fiance Build) Heatkiller Club NZXT Tempest User Community Xbox 360 mods thread http://www.overclock.net/xbox/435678...dders-out.html
|
|||||||||||||
|
|
|
|
#3 (permalink) | ||||||||||||
|
PC Gamer
![]()
Join Date: Aug 2009
Location: Southern California
Posts: 461
Rep: 39
![]() Unique Rep: 34
Trader Rating: 0
|
Also try http://www.superantispyware.com .
__________________
intel 65nm Quad @ 4.1 GHz air cooled on a 680i mobo: LINK 4 GHz Overclock Club ![]() Southern California's Premier CS:S Server -- The Hotel California: 67.201.15.22:27015 2 AWP's max per team, FF on, 100 tic & 28 player slots! Click here to connect now.
|
||||||||||||
|
|
|
|
|
#4 (permalink) | |||||||||||||
|
Overclocking Addict
![]() |
Try creating another profile and logging in there. Then download Malewarebytes and Avast and run both.
If that doesn't work your stuck trying to locate the files yourself. Boot into safe mode (F8 on boot) and start searching C:\WINDOWS and C:\WINDOWS\system32 for files that were just recently created, or modified/accessed and look suspicious. Check your registry for entries in the Run section that look like '8en3NE82n3.exe' or other random files or that match any recently modified or accessed files in the windows or system32 folders and delete them. (Most legit entries aren't random letters/numbers) Be careful what you delete though as you can damage the system. I'd export a backup of the registry first. Start > Run > regedit HK_LOCAL_MACHINE > SOFTWARE > Microsoft > WINDOWS > CurrentVersion > Run / RunOnce (Also look in HK_CURRENT_USER while logged into the infected profile)
__________________
Last edited by Slider46 : 2 Weeks Ago at 12:40 PM |
|||||||||||||
|
|
|
|
#5 (permalink) | |||||||||||||
|
*cough* Stock *cough*
![]() |
AVIRA Bootdisk <boot into AV rescue system>
before you get on the desktop thats already infected I figured that what what Id do
|
|||||||||||||
|
|
|
|
|
#6 (permalink) | ||||||||||||||
|
Blunted
![]() |
Quote:
Malwarebytes is pretty good.
__________________
Add me on Steam! the_sellout
|
||||||||||||||
|
|
|
|
#7 (permalink) | |||||||||||||
|
4.0 GHz
![]() |
Check your hosts file, clear out any crap in there. Sometimes they block sites via hosts file. If you can get malwarebytes downloaded, you can rename the installer and also the two program exes and the program will run. I usually do that to get around the nasty stuff.
The other problem with these bad ones is that they can be rootkits. I do IT consulting and in recent months I've seens alot of people infected with the UAC rootkit, luckily its easy to remove if you know what ur doing. Quote:
__________________
Want to get ~25,000PPD folding on your i7 running a Virtual Machine? EVGA 680i FOR SALE i7 920 @ 4.2Ghz ![]() O o /¯/___________________________ _\ | BBBBBAHHHHHHHHHHHHHHHHH ------------------ HEATWARE \_\¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ ¯/
|
|||||||||||||
|
|
|
|
|
#8 (permalink) | ||||||||||||
|
Overclocker
![]()
Join Date: Apr 2009
Location: Atlantic City, New Jersey
Posts: 1,227
Rep: 64
![]() Unique Rep: 60
Trader Rating: 1
|
safe mode w/ networking work?
__________________
don't tell me u guys really thought sc2 was going to be released in Q3/4 of 2009... BNIB Phenom II 920 for sale $145
|
||||||||||||
|
|
|
|
|
#9 (permalink) | |||||||||||||
|
ATI Enthusiast
![]() |
Trojans don't download themselves . . .
They are disguised files for something that you downloaded.
__________________
Nostalgic cookies taste old.
|
|||||||||||||
|
|
|
|
|
#10 (permalink) | |||||||||||
|
New to Overclock.net
Join Date: Sep 2009
Location: Casa Grande, Arizona
Posts: 385
Rep: 22
![]() Unique Rep: 17
Trader Rating: 0
|
So, did you delete the services using Hijackthis?
__________________
ATX PSU design standerds (V2.2) recomend psu fans orentation is to draw intake air from the case as an exhaust.
|
|||||||||||
|
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|