Computing.Net > Forums > Security and Virus > Trojan has killed my computer!

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Trojan has killed my computer!

Reply to Message Icon

Name: jimbo 84
Date: August 22, 2007 at 09:31:37 Pacific
OS: Win XP SP2
CPU/Ram: 1.3ghz 512Mb
Product: Acer
Comment:

Antivirus: Nod32
Firewall: Outpost
Browser IE7

Software: Ad-Aware // HijackThis // SDFix // Dr. Web CureIt

I've never had any troubles in the past with Trojans; until now.

I'm infected with what I believe to be several Trojans & am at a loose-end on how to get rid of them.

Problems Trojans have caused: Taken ShutDown button from Start Menu // Taken Run command from Start Menu // Disabled keyboard shortcuts (Win+R = Run & Alt-F4 = to shutdown; gives message, 'operation cancelled due to restrictions...') // Removed Run option from Task Manager // When I try to access Safe Mode, computer hangs.

I created a command.bat to get to a command prompt, but the screen is just flooded, so I can't type.

IE windows can close at random moments.
1714 open ports at present - and rising!!

Trojan names: Rootkit.Agent.DW // Wigon.Z // Win32/BHO.G
Files that keep popping up: runtime.sys // jjj.dll // ip6fw

I've tried to be as thorough as possible with my dercriptions of my problem, without writing you out an essay.

Virus scans pick up and clean , but as I mentioned I can't access Safe Mode to have a thorough clean out.

Hope somebody can help, as i'm just at complete loss.

Kind Regards
Jimbo



Sponsored Link
Ads by Google

Response Number 1
Name: XpUser4Real
Date: August 22, 2007 at 10:25:35 Pacific
Reply:

**When I try to access Safe Mode, computer hangs.**
You mean it hangs at the listed drivers?
If so, wait untill the safe mode loads....could be between 2 minutes to an hour or more, but it will load.

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 2
Name: Surikas
Date: August 23, 2007 at 04:24:13 Pacific
Reply:

Here is some info about Win32/BHO.G :
http://research.sunbelt-software.co...
I have found some info about the Wigon.Z in Russian, but you probably do not understand that. As far as I see from that discussion there is no antivirus that could remove the trojan, so they have built some kind of script (yes, russians are good doing that). So please go to this link:
http://depositfiles.com/ru/files/13...
and download the file by clicking the red button on the right of the bottom. It should be free and in English.
And here is a forum discussion about the Rootkit.Agent.DW removal:
http://www.geekstogo.com/forum/Root...

Good luck and let us know how did that work.


0

Response Number 3
Name: jimbo 84
Date: August 23, 2007 at 09:07:22 Pacific
Reply:

Hi, thank you very much for the responses, much appreciated.

Update: Thanks to XpUser4Real advice to be patient, I finally got into Safe-Mode.

Surikas: Couldn't get away with the Russian one; kept asking me to pay. (Comes up with 3 or 4 price plans) But the article on geekstogo.com was brilliant in the tools & software it offered to remove the Trojans.

Removed 8 trojans, and as I write this things seem more stable.

Next Problem: As I described in my first post, I have lost my Shut Down button, and seemingly my Administrative privileges (although everything is fine in Safe-Mode, and nothing wrong with Account Type in Users).

So.... how do we get a new Shut-Down button, Run button, and administrative privileges?

Again, thank you for you quick and helpfull responses.

Kind Regards
Jimbo


0

Response Number 4
Name: XpUser4Real
Date: August 23, 2007 at 09:28:07 Pacific
Reply:

Good to hear you got into safe mode, now
For the shutdown button, this may work for you:
http://help.lockergnome.com/general...
It is the last suggestion on that page.

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 5
Name: XpUser4Real
Date: August 23, 2007 at 09:34:46 Pacific
Reply:

For the other problems....
If you have an actual XP disc, you may try an sfc /scannow and if that doesn't work, do a repair install:
http://www.microsoft.com/windowsxp/...

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Related Posts

See More



Response Number 6
Name: jimbo 84
Date: August 23, 2007 at 09:55:01 Pacific
Reply:

Regedit worked like a charm. Got my shutdown button back, and the key for the run button was in the same place.

Just ran an All Service Ports scan on Grc.com - got my results back to normal.

Your system has achieved a perfect "TruStealth" rating. Not a single packet — solicited or otherwise — was received from your system as a result of our security probing tests. Your system ignored and refused to reply to repeated Pings (ICMP Echo Requests). From the standpoint of the passing probes of any hacker, this machine does not exist on the Internet.

Thanks very much for your help in resolving this issue. From hopelessly infected, to clean; in almost exactly 24 hours. Very Nice.

Thanks Again.
Jimbo


0

Response Number 7
Name: XpUser4Real
Date: August 23, 2007 at 10:02:02 Pacific
Reply:

Thanks for posting back!!!
Glad it all worked out for you.

Some HELP in posting on Cnet plus free progs and instructions Glad to Help!


0

Response Number 8
Name: swinny1710
Date: August 27, 2007 at 15:23:06 Pacific
Reply:

Hi;
I am interested in reviewing these posts,.....not for some perverse pleasure of other problems,....but I have learned so much by doing so. I'm really happy to hear that Jimbo84 was so successful, but from a learning perspective,....or more importantly from a preventitive perspective,....just wondering Jimbo 84,....if you have discovered how you got infected in the first place,.....and how you plan to ensure it doesn't happen again?
Thanks!


0

Response Number 9
Name: jimbo 84
Date: August 28, 2007 at 02:26:21 Pacific
Reply:

Hi swinny,

Not really a lot to say. I'm not sure how I was infected; although I believe it came embedded in an exe.

As far as preventitive steps go, I'm really not going to change much. I have very good antivirus and firewall software, and as Surikas mentioned, "..there is no antivirus that can remove the Trojan."

I guess it was just a slip-up on my part. Prior to this incident, i'd never been infected, so hopefully it won't happen again.

Jimbo


0

Response Number 10
Name: swinny1710
Date: August 28, 2007 at 20:11:37 Pacific
Reply:

Thanks Jimbo;
Never hurts to use as ounce of prevention,....if possible, but like you say.....stuff happens!
Let's just hope it doesn't happen again tho'!
Cheers, Swinny!


0

Sponsored Link
Ads by Google
Reply to Message Icon

Dangerous Virus plz help ... trojan.w32.looksky has in...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Trojan has killed my computer!

what does trojan do to my computer www.computing.net/answers/security/what-does-trojan-do-to-my-computer/1041.html

trojan has kill my karspersky AV www.computing.net/answers/security/trojan-has-kill-my-karspersky-av/24599.html

Spyware literally killed my computer? www.computing.net/answers/security/spyware-literally-killed-my-computer/26531.html