Solved Suspected Blaster Worm.. Trojan..?

Kaoruko

New member
Local time
6:40 AM
Messages
20
I recently downloaded a file from Mediafire, ( a 3rd Party Theme for Windows ) After a day or so, I began noticing while using Google chrome, I had a massively increased amount of popup ads, "YOU'VE WON!!! CLAIM NOW!!!!!" Windows, and even cases where when clicking Google search Result links, I'm redirected elsewhere, often a website that's filled with ads or bogus sweepstakes, etc. I downloaded AVG and ran a Safe-Mode system scan, and it showed that I had numerous Backdoor Trojans. (From what I've read, these particular viruses can resist removal when connected to the internet, so I disabled my WiFi switch before scanning)
-http://www.symantec.com/security_response/writeup.jsp?docid=2001-062614-1754-99

The part I'm worried about: is that my computer crashed while scanning (The sequence windows alerts you of when running "start shutdown -i" ) and it locked up, so I had no way of aborting it.
So.. my AVG scan was interrupted, of course. When I rebooted Windows, I got the error that %hs was missing from system.

(I flipped on that one, but eventually restored windows to before I even downloaded AVG)

The problem now is, I have just gotten rid of the Relevant Knowledge spyware-whatever; and i would REALLY like to get rid of what AVG refers to as having Generic Backdoor Trojans.. (one of them.. Generic 27 or something, was found in iTunes... ) but I have no means of purchasing antivirus software, my Norton Subscription ended, and I really don't want my computer full of Trojans (My last computer was ruined by my brother, who likes to play with Powershell)
I also would like to know a legitimate programm to clean my registry of errors and such.. I don't trust any programs that I've found so far. I attempted to do it manually, but regedit crashed every time I opened it, even with elevated control >.<

Thanks. Any advice or help is appreciated :)
 

My Computer

Computer Manufacturer/Model Number
Compaq Presario
OS
Windows 7 64 bit
CPU
1 Ghz
Memory
2 GB
Graphics Card(s)
Radeon HD 6250
Sound Card
RealTek HD
Mouse
Logitech Wireless

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Inspiron 530
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core 2 Duo Processor E8300 @ 2.83GHz
Motherboard
Dell Inc. 0RY007 (Socket 775)
Memory
4.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15)
Graphics Card(s)
Intel(R) G33/G31 Express Chipset Family
Sound Card
Integrated 7.1 Channel Audio
Monitor(s) Displays
Acer G245HQL 23.6" LED(1920x1080@60Hz)
Screen Resolution
1920 x 1080
Hard Drives
Disk 0 HITACHI 1TB OS Installed - Disk 1 HITACHI 1TB For Backups
Keyboard
Dell USB Keyboard
Mouse
Dell Optical USB Mouse
Internet Speed
DSL 10 meg
Antivirus
Symantec(SEP)
Browser
Pale Moon
I've used Malwarebytes.. After the scan, it asks for a subscription before removing any detected malicious data...
SAS is down.. I tried last night and their server is down.

I would use Norton Power Eraser; but it requires Internet conection to use, and I don't have internet except on occasion.
 

My Computer

Computer Manufacturer/Model Number
Compaq Presario
OS
Windows 7 64 bit
CPU
1 Ghz
Memory
2 GB
Graphics Card(s)
Radeon HD 6250
Sound Card
RealTek HD
Mouse
Logitech Wireless

My Computer

Computer Manufacturer/Model Number
Compaq Presario
OS
Windows 7 64 bit
CPU
1 Ghz
Memory
2 GB
Graphics Card(s)
Radeon HD 6250
Sound Card
RealTek HD
Mouse
Logitech Wireless

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Inspiron 530
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core 2 Duo Processor E8300 @ 2.83GHz
Motherboard
Dell Inc. 0RY007 (Socket 775)
Memory
4.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15)
Graphics Card(s)
Intel(R) G33/G31 Express Chipset Family
Sound Card
Integrated 7.1 Channel Audio
Monitor(s) Displays
Acer G245HQL 23.6" LED(1920x1080@60Hz)
Screen Resolution
1920 x 1080
Hard Drives
Disk 0 HITACHI 1TB OS Installed - Disk 1 HITACHI 1TB For Backups
Keyboard
Dell USB Keyboard
Mouse
Dell Optical USB Mouse
Internet Speed
DSL 10 meg
Antivirus
Symantec(SEP)
Browser
Pale Moon
I've just ran Wise registry Cleaner a few times, thinning away the errors with each scan. I re-downloaded Malaware Bytes, but I have yet to scan just yet. (I'm quite busy; using multiple programs during a virus scan can be an arduous task.)
AVG left behind some data after my restore, but I deleted each of them from both Program files (x86) and just now from the registry, but the application and it's .dll files were all removed during System Recovery (why it was still withi the reg, I don't know...)

So far, I have yet to have any trouble with ads like I had before, but even now I still get the inline ad that shows multiple "download" 'images' (all one embed.. doesn't matter where you hover; url never changes) for Ilivid or something-or other.


Anyway, for now, I think things are returning back to what I called normal.

Thanks for the input :)

Oh, should I go on and remove Norton Internet security? I'm not 100% on if it will conflict with Malwarebytes or not.
 

My Computer

Computer Manufacturer/Model Number
Compaq Presario
OS
Windows 7 64 bit
CPU
1 Ghz
Memory
2 GB
Graphics Card(s)
Radeon HD 6250
Sound Card
RealTek HD
Mouse
Logitech Wireless
As long as Malwarebytes is the free version, Norton is ok to keep.

Remember to only have one antivirus installed.

Also, a registry cleaner can make a good door stop out of a PC. Be careful!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Inspiron 530
OS
Windows 7 Professional SP1 64-bit
CPU
Intel Core 2 Duo Processor E8300 @ 2.83GHz
Motherboard
Dell Inc. 0RY007 (Socket 775)
Memory
4.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15)
Graphics Card(s)
Intel(R) G33/G31 Express Chipset Family
Sound Card
Integrated 7.1 Channel Audio
Monitor(s) Displays
Acer G245HQL 23.6" LED(1920x1080@60Hz)
Screen Resolution
1920 x 1080
Hard Drives
Disk 0 HITACHI 1TB OS Installed - Disk 1 HITACHI 1TB For Backups
Keyboard
Dell USB Keyboard
Mouse
Dell Optical USB Mouse
Internet Speed
DSL 10 meg
Antivirus
Symantec(SEP)
Browser
Pale Moon
Back
Top