Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

My computer has been completely taken over by a trojan [Closed]


  • This topic is locked This topic is locked

#1
Synalon Etuul

Synalon Etuul

    New Member

  • Member
  • Pip
  • 1 posts
Okay, basically, my computer no longer works at all. I sent this Facebook message to a friend of mine who is good with computers. I sent it Christmas night, when my computer still worked. It describes what was happening at the time:

"Symantec keeps saying it's blocked a malicious attack on my computer, so I click view details and it says "An intrusion attempt by [MY NAME]-PC was blocked". It keeps saying that I've had attacks blocked, and that something called "HTTP Zbot Malicious File Download" has been blocked. The statistics it gives are:

Risk level: High
Default action: Block
Action taken: Block
Attacking Computer: [MY NAME]-PC (192.168.1.2, 62929)
Destination Address: 222.122.60.186, 80
Traffic Description: TCP, 62929

What does this mean? How do I get rid of it? I don't have anything important on my PC, but what am I at risk of losing here?

Also, Windows Defender keeps deleting (and I think at first it quarantined) "TrojanDownloader:Win32/fakeinit".

So I kept deleting it/blocking it and it kept coming back so I typed these things into the search engine and none of the results were helpful. Basically they said that TrojanDownloader often posed as antivirus software and then once downloaded installed lots of spyware and such on your computer. They gave some files it posed as, and suggested deleting them but none of them were on my computer (well none of them came up when I searched, anyway).

Finally, sometimes a popup box appears and says something like "Microsoft Windows Search Protocol Host stopped working and was closed"."

After that, he took control of my PC remotely, but he couldn't help because the virus had control of my system and kept shutting down programs that tried to help (for instance, I tried performing a full system scan with Norton but it delivered the "Norton blah blah blah has stopped working and was closed" message). It would also redirect from potentially helpful websites, though I was still able to get to them if I clicked back and then clicked the link again.

While I was still fiddling around and listening to music, reading webcomics etc., suddenly I heard an advert for Philadelphia come on that was DEFINATELY, 100% coming from my laptop. I checked Youtube, MSN, everything I was doing, and nowhere could I find where it was coming from. The audio advert stopped, and another one for Philadelphia came on. After that ended, one for Windows 7 came on but was cut out halfway through so another Philadelphia one started but it also stopped halfway through. I asked my friend, over MSN, what the [bleep] was happening, and he said that someone else may be remotely controlling my computer but that he didn't know because he'd never used a trojan. He said over MSN (assuming that whoever may have been controlling the laptop could see) "get off my friend's computer, pick on someone else" and my Internet connection briefly disappeared but I was able to log on again right away. I assumed that someone was remotely accessing my computer and started a Word document and wrote "you are pathetic" in big letters (lol I know :) ) and Word immediately crashed (with the "Word has stopped working and was closed" message). I tried opening Word again just in case to see what would happen, and it would close immediately each time, but the original Word document had just frozen and would not close.

Straight after that happened I unpluggged my Internet connection. I plugged it in again 10 minutes later, then unplugged it after about 2 minutes and turned off the laptop.

Now when I power up the laptop, nothing out of the ordinary happens until I log into a user. When I do that, I receive this exact message:

"Security Warning!

Worm.Win32.NetSky detected on your machine.
This virus is distributed via the Internet through e-mail and Active-x objects.
This worm has its own SMTP engine which means it gathers e-mails from your local computer and re-ditributes itself.
In worst cases this worm can allow attachers to access your computer, stealing passwords and personal data.
Viruses can damage your confidential data and work on your computer.
Continue working in unprotected mode is very dangerous.

Type: Virus
System Affected: Windows 2000, NT, ME, XP, Vista, 7
Security Risk (0-5): 5
Recomendations: It is necessary to perform a full system scan."

After that message, all I see is my background picture. There are no shortcut icons, no startbar, no sidebar, only my background picture and the occasional message saying "Windows Explorer has stopped working. A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available."

Other messages similar to this refer to Word not working, Windows Movie Player, Norton Internet Security etc. Somtimes the wording is slightly different.

So if any of you have any idea about what to do then I would love you forever.

Side note: There's nothing on my computer like bank account details or whatever, so that's a plus, but there is a load of stuff I don't want to lose so if there's any way of getting rid of the problem without losing all of my data, that would be great. I know I still have stuff on my computer because my downloaded screen saver, Electric Sheep, is still on there.

Also, sorry about the wall of text!
  • 0

Advertisements


#2
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Hi Synalon Etuul,

Welcome to Geeks to Go! My name is SpySentinel and I will be helping you fix your malware problem.

If for any reason you do not understand any of the instructions, or are just unsure then please post back with your question, and we will go through it together :)


The IP 222.122.60.186 resolves to China and is on a malicious range:
http://hosts-file.ne...86&view=matches


Please read the Malware and Spyware Cleaning Guide and then post the

  • OTL
  • Malwarebytes' Anti-Malware
  • Gmer Anti-Rootkit
Logs here in a reply.
  • 0

#3
SpySentinel

SpySentinel

    R.I.P.

  • Retired Staff
  • 5,152 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP