Trojan, Please HELP!!!

Page 2 of 3 FirstFirst 123 LastLast

  1. Posts : 46
    Windows Seven Ultimate
       #11
      My Computer


  2. Posts : 11,840
    64-bit Windows 8.1 Pro
       #12

    even though this is categorized as a low threat, I agree with Jimbo... a clean install!
      My Computer


  3. Posts : 268
    windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home
       #13

    EvilOzzmess said:
    Trying that now... let's hope this works.

    And of course, they want my money before getting rid of it.

    .
    hitman pro has free cleaning for 30 days....just activate trial license and it will clean for free.....
    Attached Thumbnails Attached Thumbnails Trojan, Please HELP!!!-hmp-30-days.png  
      My Computer


  4. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #14

    You can manually remove it:
    Encyclopedia entry: BrowserModifier:Win32/Zwangi - Learn more about malware - Microsoft Malware Protection Center

    Or, rescan with Malwarebytes'
    * Be sure that everything is checked, and click Remove Selected.

    Don't back up 'dirty' restore points!
      My Computer


  5. Posts : 14
    Windows 7 Enterprise 64bit
       #15

    Macrium


    I use Macrium Reflect and I take an image of my machine about once a month, it's quite easy to use and I have had to restore twice in the past after I messed things up, just download from there website, Macrium Reflect FREE Edition - Information and download make a rescue disk and make an image on an external HDD or network drive or a bunch of DVD's. It took about 40 mins to back up and the same to restore a 160gb HDD that was half full.
      My Computer


  6. Posts : 38
    7 Ultimate
       #16

    Jo 90 said:
    I use Macrium Reflect and I take an image of my machine about once a month, it's quite easy to use and I have had to restore twice in the past after I messed things up, just download from there website, Macrium Reflect FREE Edition - Information and download make a rescue disk and make an image on an external HDD or network drive or a bunch of DVD's. It took about 40 mins to back up and the same to restore a 160gb HDD that was half full.
    Jo 90 -

    I've been thinking of giving this app a try. Which rescue method do you use (linux disk, linux usb, bartPE disk)?

    Any tips/pointers in overall use?

    THANKS!
      My Computer


  7. Posts : 1,402
    Windows 7 Ultimate x64
       #17

    I removed the same trojan from a clients computer yesterday. I started it up in safemode with networking. Downloaded and ran Rkill then downloaded and ran Malwarebytes scan, do the full scan as it is much more accurate.

    While it is running go and do something else as it can take quite some time.

    It found 27 items. I quarantined and then removed all items. I restarted the machine and then deleted restore points see here

    http://windows.microsoft.com/en-US/w...-restore-point

    This is important as if you go back to a restore point at a later date you might restore this virus.

    Run the Malwarebytes scan again (quick this time) and bob's your uncle.
    __________________
      My Computer


  8. Posts : 301
    7 Ultimate x64 SP1
    Thread Starter
       #18

    Thanks guys, I chose a full factory restore - so my computer's now exactly back to how Acer shipped it out as (and subsequently was their recommended course of action for persistent, severe malware infestations). Along with five other programs, I tried running MBAM twice, fully - and twice quickly, and it DID detect and remove two Trojans - each time, but it was unable to fully remove whatever caused those two to get in here - so I really had no choice but to completely wipe out the system on this one.

    I wouldn't have trusted it if I hadn't, anyway. Just kind of ticked I forgot to save my Firefox bookmarks before doing it... this is why you shouldn't panic and try to do this stuff on an all-nighter whilst half asleep. Ha... >_<


    As for backup, I discovered I didn't really need that at all. I DO have a self-made Acer Restore Manager set of disks which did ghost the entire drive, along with drivers and the OS itself. But I find Factory Restore to do the exact same thing, so it's less complicated to just do that and then put everything back as it was before (like I'm doing right now, in fact). No big deal.

    Thanks again for all your help guys! Really appreciate it.
      My Computer


  9. Posts : 79
    Windows 7 Ultimate 64-bit
       #19

    Well good to here your virus problems are over, but for future reference have Microsoft Security Essentials as your antivirus if you cant afford to buy one and Malwarebytes along with it. These are two great programs that will keep you safe :)
      My Computer


  10. Posts : 301
    7 Ultimate x64 SP1
    Thread Starter
       #20

    No, wait...once again, not sure if it's completely gone. MBAM found "Hijack.DisplayProperties" Registry Data HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChange s

    I don't know how that is even possible, but there it is. What should I do now? I don't see the old Processes that I had with whatever it was last time, that I believe I did just get rid of, but... yeah. It's there, somehow.


    EDIT: I have found winlogon.exe in the processes, and when I checked it out it shows an icon with a WINDOW, WITH A MOON IN THE BACKGROUND. It is NOT capitalized, and it is NOT WINLOGIN.EXE which I know to be the TRUE Windows program type. How do I kill this?
    Last edited by EvilOzzmess; 10 Mar 2010 at 22:03.
      My Computer


 
Page 2 of 3 FirstFirst 123 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 01:24.
Find Us