1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive I think I have a trojan

Discussion in 'Malware and Virus Removal Archive' started by jparnold, 2011/04/12.

  1. 2011/04/12
    jparnold

    jparnold Inactive Thread Starter

    Joined:
    2005/09/08
    Messages:
    345
    Likes Received:
    1
    [Inactive] I think I have a trojan

    Some strange things happened on my desktop pc the other night. All of a sudden Firefox would not connect to any website displaying an error about proxy settings. As I had installed some software just before this happened and as I am not familiar with what the proxy settings should be I decided to RESTORE my pc to the previous day.
    This all went well and Firefox was working correctly again HOWEVER I started to get windows opening stating that AVG (antivirus) had located a problem with a file in C:\WINDOWS\TEMP and prompted me to quarantine it. But after this occurred a few times I searched for the file (before electing to quarantine it) but it did NOT exist. I started to become quite concerned so did a FULL SCAN with AVG which located some windows files in C:\WINDOWS\SYSTEM32 and also C:\WINDOWS folders which contained a trojan (sorry I can't remember the exact name). AVG asked me if I wanted to quarantine them which I attempted to do but I don't think worked.

    Now here comes another strange thing. When I selected the C:\WINDOWS folder, right clicked and selected SCAN WITH AVG nothing was displayed, yet a full scan of my system finds the files with a trojan.
    I have done this same procedure 3 times with the same result.

    I am now considering (cold) rebooting my system with say UBUNTU on a USB memory stick and then copying fresh copies of the infected files from a PC which is clean (the infected files cannot be copied with Windows running because they are in use with Windows running).

    If that doesn't fix the problem I am considering reformating C: and rebuilding it but thought I would post a question "is there an easier way to fix this problem ".
     
  2. 2011/04/12
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Hi,

    Read this post as indicated at the top of this forum & follow the instructions.
     

  3. to hide this advert.

  4. 2011/04/12
    jparnold

    jparnold Inactive Thread Starter

    Joined:
    2005/09/08
    Messages:
    345
    Likes Received:
    1
    Thanks Arie,
    I am out of town at the present time so will do all these things when I get home.
    Sorry for not reading the 'read this' post.
    After reading this I remember some time ago someone walking me through all those steps one at a time via email.
    I must mention here that I DID run the Malwarebytes anti-malware application also which found NO threats.

    One question though before I do all those (other) things.
    I do NOT run Windows (or any other) Firewall as I have a router which I was once told has an inbuilt (hardware) firewall and I was told that using a software firewall in these circumstances was a waste of (cpu) resources.
    What do you think of these claims?

    When I get home I will run all those applications and if there is still a problem I will post the logs.

    Thanks again
     
  5. 2011/04/12
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    They're good claims... IF (big IF) the hardware firewall is indeed running.
     
  6. 2011/04/13
    jparnold

    jparnold Inactive Thread Starter

    Joined:
    2005/09/08
    Messages:
    345
    Likes Received:
    1
    I attempted to use the procedure in the "readme first" post and got to running MalWareBytes scan which didn't seem to behave the way I believe it should have so decided to reformat and rebuild my system.

    I will now close this post but in the meantime I think that I should point out that when I ran TFC it displayed a message that it will only run when the user is logged in as ADMINISTRATOR.
    The only place that the readme refers to run as an administrator is for MBRCheck.exe so perhaps the post should be updated.
     
  7. 2011/04/13
    jparnold

    jparnold Inactive Thread Starter

    Joined:
    2005/09/08
    Messages:
    345
    Likes Received:
    1
    HELP

    Maybe I'm a bit think but I cannot remember and find how to close this thread.
    I checked every drop down menu I could see on the page for this thread without finding anything which resembles 'close thread' (or similar).
    I even checked in 'posting rules'.
     
  8. 2011/04/13
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    In this particular forum, you can't.
    I'll do it for you.

    Thank you for letting us know :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.