1.

Solve : Help! I'm infected with a Trojan Horse!?

Answer»

Hi Mr. & Mrs. HOPE! For about 2 weeks I've noticed major issues with my computer. At first I suspected my Verizon Security Suite was the gateway to these issues and despite removing it, ladies and gents, the damage has been already done!

At start-up "Data Execution Prevention" MS window pops up "To help protect your computer, Windows has closed this program." Name: Windows Update Automatic Updates Publisher: Microsoft Corporation. Then the only option is to close message.

Once I close message a whole slew of MS windows pops up. Let me know if you need this info. In the meantime, I came here and followed all the steps for House Cleaning. I think everything went well.

Except I have AVG running and I keep getting a pop up "Threat detected!" File name: C:\WINDOWS\system32\hsvnrtf.dll Threat name: Virus IDENTIFIED Win32/Cryptor Detected on open. (Whenever I open IE) AVG won't allow me to heal or move this to the vault.

Let me know what should be the next step. Here are my logs: (Oh and THANK YOU! for your ANTICIPATED help!...really thanks!)

Here is AVG Virus Vault prior to the other steps:

"Infection";"Trojan horse Generic13.XKB";"C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP4\A0000018.exe";"";"5/4/2009, 1:25:10 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP4\A0000004.dll";"";"5/4/2009, 1:25:08 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 1:10:24 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 1:05:13 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 12:51:28 PM"
"Warning";"Found Tracking cookie.Tacoda";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/4/2009, 12:25:41 PM"
"Warning";"Found Tracking cookie.Realmedia";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/4/2009, 12:25:41 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/4/2009, 12:25:41 PM"
"Infection";"Virus identified Java/ByteVerify";"C:\Documents and Settings\Lopez\Application Data\Sun\Java\Deployment\cache\6.0\22\74018dd6-52ca3251";"";"5/4/2009, 12:23:24 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 12:10:04 PM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 11:51:59 AM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 11:16:00 AM"
"Infection";"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\hsvnrtf.dll";"";"5/4/2009, 10:27:43 AM"
"Infection";"Trojan horse Generic13.XKB";"C:\WINDOWS\system32\sdra64.exe";"";"5/2/2009, 10:57:08 PM"
"Warning";"Found Tracking cookie.Zedo";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Tribalfusion";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Webtrendslive";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Revsci";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:42 PM"
"Warning";"Found Tracking cookie.Questionmarket";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Mediaplex";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Adrevolver";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Doubleclick";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Advertising";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Adbrite";"C:\Documents and Settings\Phoenix\Cookies\[email protected][2].txt";"";"5/2/2009, 10:00:41 PM"
"Warning";"Found Tracking cookie.Yieldmanager";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:40 PM"
"Warning";"Found Tracking cookie.247realmedia";"C:\Documents and Settings\Phoenix\Cookies\[email protected][1].txt";"";"5/2/2009, 10:00:38 PM"
"Infection";"Trojan horse Downloader.Generic8.AGSF";"C:\Documents and Settings\Lopez\Local Settings\Temp\wJQs.exe";"";"5/2/2009, 9:55:37 PM"
"Infection";"Trojan horse Generic13.XKB";"C:\Documents and Settings\Lopez\Local Settings\Temp\futu.exe";"";"5/2/2009, 9:55:31 PM"
"Warning";"Found Tracking cookie.Tribalfusion";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:39 PM"
"Warning";"Found Tracking cookie.Trafficmp";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:39 PM"
"Warning";"Found Tracking cookie.Tacoda";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:39 PM"
"Warning";"Found Tracking cookie.Serving-sys";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Revsci";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Realmedia";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Webtrends";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:38 PM"
"Warning";"Found Tracking cookie.Serving-sys";"C:\Documents and Settings\Lopez\Cookies\[email protected][1].txt";"";"5/2/2009, 9:54:37 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Lopez\Cookies\[email protected][2].txt";"";"5/2/2009, 9:54:37 PM"
"Warning";"Found Tracking cookie.2o7";"C:\Documents and Settings\Lopez\Application Data\Mozilla\Firefox\Profiles\xmikmln5.default\cookies.txt";"";"5/2/2009, 9:52:57 PM"
"Warning";"Found Tracking cookie.Zedo";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Valueclick";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Trafficmp";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Tribalfusion";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Tacoda";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Webtrendslive";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:53 PM"
"Warning";"Found Tracking cookie.Revsci";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:52 PM"
"Warning";"Found Tracking cookie.Questionmarket";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:52 PM"
"Warning";"Found Tracking cookie.Pro-market";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:52 PM"
"Warning";"Found Tracking cookie.Overture";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Overture";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Mediaplex";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Adrevolver";"C:\Documents and Settings\Becky\Cookies\[email protected][3].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Hitbox";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:51 PM"
"Warning";"Found Tracking cookie.Fastclick";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Doubleclick";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Casalemedia";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Burstnet";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:50 PM"
"Warning";"Found Tracking cookie.Atdmt";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Advertising";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Adrevolver";"C:\Documents and Settings\Becky\Cookies\[email protected]evolver[2].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Adbrite";"C:\Documents and Settings\Becky\Cookies\[email protected][2].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.2o7";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Yieldmanager";"C:\Documents and Settings\Becky\Cookies\[email protected][1].txt";"";"5/2/2009, 9:45:49 PM"
"Warning";"Found Tracking cookie.Zedo";"C:\Documents and Settings\Becky\Application Data\Mozilla\Firefox\Profiles\jaazt64k.default\cookies.txt";"";"5/2/2009, 9:45:34 PM"

End AVG

[attachment deleted by ADMIN]after your pm

you now have sas and malware run them every week

http://www.filehippo.com/download_ccleaner/

go to above and download run every week

and keep them all up to date

avg 8 is not very good if you want to take it out come back

and download avast or AVIRA both free



Discussion

No Comment Found