|
|
|
Sunday, September 17, 2006
[Trojan!]
I'm pissed. Actually, very pissed.
My rig's infected with a Trojan, and I'm not sure what it is, hence I cannot remove it. I have NAV 2005 installed, and this afternoon the auto-protect feature caught three Trojans on my hard drive. If my auto-protect was turned on, how did they get onto my hard drive in the first place?
Anyway, two of them were deleted without much fuss. One of them could not be deleted, and access to it was blocked. I didn't think much it'd cause any trouble, since access to it was blocked.
Boy, was I wrong.
What happened next was a blur. I can't remember exactly what I did, but here's the current situation:- There will be a ton of msvcrt.exe processes when I boot up. I killed them off one by one, I think there were 19 of them.
- Win XP is behaving funny...Some of my shortcuts for Windows Explorer will tell me they can't open (null), but still opens Windows Explorer anyway.
- My task bar's fucked. Volume Control is no longer shown, and some of my icons have changed colour, two are invisible. They're still there, they still take up space. They're just a solid grey. Hence, "invisible".
There may be some other problems which I've yet to discover.
I tried following Symantec's suggestions on removing Infostealer.Banker.B (this is what NAV thought it was...I have a feeling it might be wrong) in safe mode, didn't work. None of the registry strings that I'm supposed to delete are in my registry to begin with. And I can't start any applications at all when I'm in safe mode. I can't start msconfig, so I was actually stuck in safe mode for a while, until I thought of a way to modify boot.ini while in safe mode. I couldn't run NAV in safe mode neither, I think the Trojan's still alive in safe mode, blocking NAV from being executed or something. If I could run a manual scan in safe mode, I might just be able to track the Trojan down and delete it.
Aragh.....Anyone has any ideas what can I try now? What I'm doing now at each start-up is just basically kill all the msvcrt.exe processes and try to do my work as per-normal.
^^^ by Locksley @ 9:35 PM.
4 comments.
[Read Comments]
[Post Comments]
|
RSS
|
|