Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan.win32/fakesysdef- help


  • Please log in to reply

#1
Yogibear1

Yogibear1

    New Member

  • Member
  • Pip
  • 2 posts
I noticed a previous post on this, but there was a warning that the solution was specific to each computer.

Last night I was browsing the internet, and i clicked on a link when suddenly Firefox closed, and multiple error messages began popping up. There are approximately 15 to 20 individual error messages stating "Windows - Delayed Wire Failed"..."Failed to save all the components for the file xxxxxx. The file is corrupted or unreadable. "Disk-Error"."
All desktop icons have vanished and when I click on the Start menu it is blank.
I was able to run a microsoft security essentials scan from the programs toolbar and it detected a Trojan with the name "Trojan.win32/fakesysdef".
MSE says it removed the trojan and it says it is successful it doing so, however I cannot see ANY ICONS AT ALL.
I could not even see " My computer" and the start/programs has no programs.
I was able to get to "users" and I added a new user, thinking it might rebuild it and return the programs.
when I logged in using that new user, I can see "my computer, control panel etc.. still NO Programs.

Looking in "My computer", All previous users " My documents" folders are empty.
when I click on "My computer" and the "C-Drive" root ,I see only one file- 26c0bc0de12c878bffc8860fa8fc00
when I open it, i see a bunch of files with 4-digit numbers- all show 0 bytes in file properties, but with "ACCESS DENIED"- so I cannot open them

I'm sure there is alot more information you may need to assist me so just let me know and I'll get it to you. This PC is about 3-4 years old.
Your help is greatly appreciated.
  • 0

Advertisements


#2
Yogibear1

Yogibear1

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
I downloaded and installed RogueKiller:
Alot of my programs have been restored.. System tools is still blank
below are the results of the text files:

RogueKiller V6.1.7 [11/05/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: home-nikki [Admin rights]
Mode: Remove -- Date : 11/05/2011 16:18:21

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Registry Entries: 6 ¤¤¤
[DNS] HKLM\[...]\ControlSet001\Parameters\Interfaces\{4875AE51-38EE-4D4A-ACB3-03B67826F582} : NameServer (64.105.197.58) -> NOT REMOVED, USE DNSFIX
[DNS] HKLM\[...]\ControlSet003\Parameters\Interfaces\{4875AE51-38EE-4D4A-ACB3-03B67826F582} : NameServer (64.105.197.58) -> NOT REMOVED, USE DNSFIX
[HJPOL] HKLM\[...]\System : DisableTaskMgr (1) -> DELETED
[HJ] HKLM\[...]\Security Center : AntiVirusDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\Security Center : FirewallDisableNotify (1) -> REPLACED ()
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED ()

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt


RogueKiller V6.1.7 [11/05/2011] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: home-nikki [Admin rights]
Mode: Shortcuts HJfix -- Date : 11/05/2011 16:28:45

¤¤¤ Bad processes: 0 ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 2 / Fail 0
Quick launch: Success 2 / Fail 0
Programs: Success 17378 / Fail 0
Start menu: Success 44 / Fail 0
User folder: Success 83 / Fail 0
My documents: Success 36 / Fail 0
My favorites: Success 14 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 102970 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[D:] \Device\CdRom0 -- 0x5 --> Skipped

¤¤¤ Infection : ¤¤¤

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP