Re: OT Virus/Trojan

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Bob Eyster wrote:

Wonder if someone out there can help me with this problem?

System: Windows XP Pro w/all updates

My daughter's PC got hit with a Virus/Trojan or something. She received an
email (from someone she didn't know) that say she had a card waiting and
clicked on the link for the card. When she clicked on the link her
computer rebooted and things haven't been the same since. Some web site
are blocked like Symantec, and Hot mail to name a couple.

Does anyone know the name of this bug and if so, where to find the removal
tool?

All scans that I able to do fines nothing. Also System Restore is no
longer working.

You've posted in a newsgroup for the Vista operating system. A better place
would be microsoft.public.security.virus. Since you didn't say what you
scanned with, I can't comment on that but from your description of the
problem it certainly sounds like your daughter's computer is infected. Here
are general malware removal steps:

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Include scanning with David Lipman's Multi_AV and follow instructions to do
all scans in Safe Mode. Please see the special Notes regarding using
Multi_AV in Vista.

http://www.elephantboycomputers.com/page2.html#Multi-AV - instructions
http://tinyurl.com/yoeru3 - download link and more instructions

When all else fails, get guided help. Choose one of the specialty forums
listed at the first link. Register and read its posting FAQ. PLEASE DO NOT
POST LOGS IN THE MS NEWSGROUPS.

Standard disclaimer: I can't see and test your computer myself, so these are
just suggestions based on many years of being a professional computer tech;
suggestions based on what you've written. You should not take my
suggestions as a definitive diagnosis. If you can't do the work yourself
(and there is no shame in admitting this isn't your cup of tea), take the
machine to a professional computer repair shop (not your local equivalent
of BigComputerStore/GeekSquad). Please be aware that not all local shops
are skilled at removing malware and even if they are, your computer may be
so infested that Windows will need to be clean-installed. If possible, have
all your data backed up before you take the machine into a shop.

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ

.



Relevant Pages

  • Re: All MS tools are missing or corrupt
    ... has damaged your Windows installation beyond repair. ... Include scanning with David Lipman's Multi_AV and follow instructions to do ... shop (not your local equivalent of BigComputerStore/GeekSquad). ...
    (microsoft.public.windowsxp.general)
  • Re: uthgnaz.exe - what the heck is it?
    ... Go through these general malware removal steps systematically - ... Include scanning with David Lipman's Multi_AV and follow instructions to ... shop (not your local equivalent of BigComputerStore/GeekSquad). ...
    (microsoft.public.windowsxp.general)
  • Re: My system is haunted!
    ... 17134.exe is running and is consuming quite a lot of memory space. ... Include scanning with David Lipman's Multi_AV and follow instructions to do ... shop (not your local equivalent of BigComputerStore/GeekSquad). ...
    (microsoft.public.windows.vista.security)
  • Re: when i start my pc the system configuration utility starts aut
    ... Include scanning with David Lipman's Multi_AV and follow instructions to do ... just suggestions based on many years of being a professional computer tech; ... machine to a professional computer repair shop (not your local equivalent ... all your data backed up before you take the machine into a shop. ...
    (microsoft.public.windowsxp.general)
  • Re: uthgnaz.exe - what the heck is it?
    ... Include scanning with David Lipman's Multi_AV and follow instructions to do ... http://tinyurl.com/yoeru3 - download link and more instructions ... shop (not your local equivalent of BigComputerStore/GeekSquad). ...
    (microsoft.public.windowsxp.general)