Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Need opinion on virus / trojan issue?

Status
Not open for further replies.

algae1

Vendor
Jan 9, 2005
41
CA
Recently my daughter confessed that she accepted and (choke) RAN an unknown attachment from an unknown user on MSN.
My first indication that something was amiss was that msconfig will run for about 5 seconds and then shut off. I tried taking a look in the AVG control centre and it also shut down. It also killed my Firefox preset Tabs.
In safe mode I ran Spybot S & D and it found FakeMsn8 and deleted it. I also ran Stinger and it found Qhosts and told me it repaired it. AVG turned up nothing in safe mode. Neither did Adaware.
However in normal mode I still can't run msconfig or the AVG control centre so I think it's still infected. I'm at work now so I can do any troubleshooting but I thought I'd post this message to see if I can get some advice in advance of going home to work on this.
Thanks for any help.
Gary
 
If the pc is having real problems, boot it up normally and do a ctrl/alt/del to get up the task manager. Then check all of the processes running (not the applications).

Just type the full name into google and it should return with descriptions of what those processes are actually doing or if they are part of any malware/virus. You can then search the symantec (or any of the virus prog websites) for manual removal of the infection. Usually a deletion of the exe and some registry editing.

You could also try running 'stinger' a free stand-alone app from McAfee. It's not 100% as it only scans for some of the major nastys out there, but it's a good start. I would try this before you check out all the processes and hack the registry.

Good luck.

Rob.
 
Oh, one more thing... While you are doing this turn off system restore (if you are running Win ME or XP) for the duration of the clean as some nasties hide themselves there and restore themselves afterwards.
 
You could try to reinstall AVG. If when removing viruses some infected files were deleted, that could render some programs inoperable. As for msconfig, look online which files are required to run it, then download them and manually copy them to the correct location (yes, it may be time consuming).

But you are totaly correct, first you must make sure all the infections are removed.

Good luck. You were the victim of a rather nasty situation, that's for sure.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top