Nasty Trojan - need help removing

Discussion in 'Malware Help (A Specialist Will Reply)' started by TerranCmdr, Jun 23, 2008.

  1. TerranCmdr

    TerranCmdr Private E-2

    Hi.
    I have a bad trojan, or cumulation of trojans, spyware, adware and worms on my computer that I believe was caused by a single source which I have yet to identify. Three things have happened in the time between when my computer was fine and when it went haywire.

    1. I moved my computer to a different house. Different network, different router, may have not been firewalled and my comp. didn't have windows firewall enabled.

    2. I installed a copy of a game.

    3. The newest episode of Top Gear finished downloading.


    The problems started right after the third event. My problems are as follows:


    Popups in my system tray - saying things like "Spyware detected" and "Your computer is infected with spyware". Clicking on the bubble leads to the webpage windows-privacy-protection.com, which I've found in my research is part of a takeover program

    I have new files in my C:\Windows directory. (systeem, systemcritical, rundll16, etc.) When deleted they replace themselves within a minute, meaning another program is running that won't let them go. Also have a file/folder called "fun" in my C:\Windows\System directory.

    I can't install certain new programs because my computer says I don't have admin. privileges.

    I can't access my task manager because it says "Task manager has been disabled by your administrator."

    Fake anti-virus program windows pop up occasionally.

    My comp. has blue-screened once (mem dump) but I suspect it was a fake...?(I pressed ESC, went back to desktop)

    My display adapter is screwed up. (bad resolution)

    My desktop background has been changed to something like (your computer is at risk, bla bla bla, I can't read it because of the bad resolution)

    So far I've taken these steps:

    Tried to edit my registry to regain access to the task manager. (failed)
    Tried finding and deleting the files I knew were bad. (failed)
    Tried a couple of "free" spy sweepers, one (SpyHunter) came up with quite a few malicious items, but of course wouldn't remove them for me.
    Rebooted in Safe Mode, wash rinse repeat, all symptoms are still present.
    Downloaded and tried out a program called Autoruns, no luck with that either.



    Any help with this would be greatly appreciated. I would like to avoid completely wiping my computer and reinstalling as it's a real pain. Thank you in advance.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!
    Uninstall ALL of these now before continuing.



    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds