Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

trojan


  • Please log in to reply

#1
moyra

moyra

    Member

  • Member
  • PipPip
  • 77 posts
hi guys. i contacted you a couple of months ago when i was having problems. the problem was not resolved and i ended up buying a new computer. all was going well until a few dll,s dissapeared the end result was i had to reformat and lost a fair few photo's etc. i sent myself an email from the old computer as it had details of downloading the update of my virus protection and so i think maybe i sent the virus i had in the old computer to the new one.
after totally reformatting and setting up trend micro again, i set up my email. the same email came in from myself which i had already recieved before having to reformat and did not send again and i am now getting the same symptoms.... start menu and other windows/windows popping up, shut downs on the email and the web?
downloaded a free scan and it said i had a trojan? can anyone help???
PLEASE
Moyra
forgot to mention. this computer is only four days old. with the probs i have had i havent even had time to load my office program

hi. moyra here, has any staff member looked at this yet??? i dont want to go any further istalling programs if it is a waste of time and i have to re-format again.

i would really appreciate your expert help.
thank you

i did an online scan from panda software and it states i have potentially unwanted software but can not find a fix for it !!!

Hi again. i was reading another log with similar problems and followed the instructions using sdfix. i ran the program and it found a trojan. i will post the log here. sorry if it is the wrong area i am not sure where i should put it. here it is. I would appreciate it if someone could have a look and see if i need to do anything else. thank you for your time.

SDFix: Version 1.124

Run by moyra on Sun 06/01/2008 at 06:03 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\Program Files\Setup.exe - Deleted




Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-06 06:04:50
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

IPC error: 2 The system cannot find the file specified.
scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Wed 2 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\410ff09308a833491dba7686f0aee2eb\BIT5.tmp"

Finished!

Edited by moyra, 05 January 2008 - 01:14 PM.

  • 0

Advertisements


#2
moyra

moyra

    Member

  • Topic Starter
  • Member
  • PipPip
  • 77 posts
hi guys
i logged a problem on jan 2nd and have had no reply. last time i had a problem i was told to edit my post not to reply to it but i have been editing and have had no response ... please tell me what i am suppose to be doing because i have no idea. sorry if i have done the wrong thing again.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP