Folder AVG Forums » Other topics » Virus Removal, Tools for Removing » Fake Anti-Virus With Trojan Horse Invasion
Page 1 of 2 12››
May 7, 2012 08:25 Fake Anti-Virus With Trojan Horse Invasion #200917
Reply with Quote | Quick Reply | Top
xXrejectedXx

Avatar

Novice
Join Date: 8.11.2011
Posts: 16
had a virus come thru that posed as an anti-virus program, went into safe mode and did a system restore, windows logged back in and the restore had gotten rid of the program but left a dropper and i am getting 3-4 trojan horse alerts every minute from fake .dll files being made, also and https site comes up with a weak algorithm warning. Have attached both GMER scans and latest resident shield detection list
May 7, 2012 14:54 Re: Fake Anti-Virus With Trojan Horse Invasion #201017
Reply with Quote | Quick Reply | Top
nemethste

Avatar

Administrator
Join Date: 1.11.2011
Posts: 1730
Hello xXrejectedXx,

According to the scan result analysis it seems that your computer is infected by MBR rootkit.

In order to get rid of this kind of infection please restore master boot record in offline mode. You may do it using AVG Rescue CD.

Right after the MBR is restored, please scan your computer with updated AVG Rescue CD to kill all remains of infection.

After all above mentioned procedures are done, please provide us with new Gmer and AVG scan results so we can confirm that your computer is clean.

Thank you.



AVG Team
How-To articles | FAQ | Free Support
May 7, 2012 15:35 Re: Fake Anti-Virus With Trojan Horse Invasion #201025
Reply with Quote | Quick Reply | Top
Gary Bee

Avatar

Novice
Join Date: 29.7.2010
Posts: 296
Hi xXrejectedXx,

If you, like many others on the Forum, have a difficulty in obtaining or using ("Do you know your Administrator Password?") the Windows Recovery CDs. This post discusses the Alternatives in more detail, as referred to by Nemethste, “You may do it using AVG Rescue CD”.
May 10, 2012 03:12 Re: Fake Anti-Virus With Trojan Horse Invasion #201409
Reply with Quote | Quick Reply | Top
xXrejectedXx

Avatar

Novice
Join Date: 8.11.2011
Posts: 16
I went thru and ran the rescue cd and reset the mbr, then did a scan thru the cd and said it fixed the infections. when i booted windows back up it came up with another resident shield detection and now it isnt letting me login to anything on the internet and now keeps kicking me from servers on online games, res shield keeps comming up with trojan horse crypts, generics and zero access detections
May 10, 2012 10:59 Re: Fake Anti-Virus With Trojan Horse Invasion #201481
Reply with Quote | Quick Reply | Top
nemethste

Avatar

Administrator
Join Date: 1.11.2011
Posts: 1730
Hello xXrejectedXx,

Please provide us with new diagnostic files, so we can check if rootkit remained or what exactly had happened.

Thank you.



AVG Team
How-To articles | FAQ | Free Support
May 14, 2012 06:18 Re: Fake Anti-Virus With Trojan Horse Invasion #202061
Reply with Quote | Quick Reply | Top
xXrejectedXx

Avatar

Novice
Join Date: 8.11.2011
Posts: 16
ok these are the scans, sorry for the delay but have had issues gettin onto the internet with this computer ie th virus throwing up fake https sites
May 14, 2012 06:23 Re: Fake Anti-Virus With Trojan Horse Invasion #202063
Reply with Quote | Quick Reply | Top
xXrejectedXx

Avatar

Novice
Join Date: 8.11.2011
Posts: 16
also have this scan from aswMBR and have used bitdefender bootkit to scan the mbr and both have come up saying there is nothing in the mbr
May 14, 2012 11:18 Re: Fake Anti-Virus With Trojan Horse Invasion #202125
Reply with Quote | Quick Reply | Top
nemethste

Avatar

Administrator
Join Date: 1.11.2011
Posts: 1730
Hello xXrejectedXx,

It seems that your computer become infected by various viruses of the most dangerous kind.

In order to resolve Zbot infection please download and run this tool. (Don't forget to change power management settings to not to sleep).

Reset access tool will resolve issues with permissions.

Also please note that the best solution may be to backup important documents and re-install Windows, since it appears to be severely damaged by infection.

Thank you.



AVG Team
How-To articles | FAQ | Free Support
May 15, 2012 13:25 Re: Fake Anti-Virus With Trojan Horse Invasion #202327
Reply with Quote | Quick Reply | Top
xXrejectedXx

Avatar

Novice
Join Date: 8.11.2011
Posts: 16
has gotten rid of all but a trojan horse zero access infection in one system file, will upload gmer scans and computer scan tomorrow
May 16, 2012 08:20 Re: Fake Anti-Virus With Trojan Horse Invasion #202507
Reply with Quote | Quick Reply | Top
xXrejectedXx

Avatar

Novice
Join Date: 8.11.2011
Posts: 16
can only get the autostart scan ang avg computer scan
the rootkit scan log wont save tried 3 times
Page 1 of 2 12››