Hi:
Yesterday I got hit with a trojan. I am running windows XP SP3, using ZoneAlarm version:8.0.298.000 (free) and Symantec-Endpoint Protection AV. Also have SpywareDoctor (free version), WinPatrol (free), and AdAware. I cannot visit websites like windows update or Malwarebytes, and cannot update any anti-spyware. I can, however, get to most other website and I can download programs so long as they are provided on a third party website so that I can right-click save them. Using this method I downloaded Malwarebytes and Trens Micro's rootkitbuster beta. Also I can run the programs.
AdAware and WinPatrol saw the thing on the way in; Adaware removed some of it, WinPatrol blocked it from running (more than it already had), and malwarebytes removed a it more (see below). From WinPatrol history the troubles are most likely associated with Cwf, CWG and/or FJ5MWNZTHI
From Malwarebytes log (3 problems):
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\00000244.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully
From AdAware:
Win32.Hoax.Renos process
Both quarantined but not removed
Obviously the thing is still in my machine, because I cannot update my security programs and cannot go to malwarebytes or windows update websites. Because of this, please do not suggest that I manually update my programs from malwarebytes website. Tried that. I can post HJT and/or DDS logs. Please Help??
Yesterday I got hit with a trojan. I am running windows XP SP3, using ZoneAlarm version:8.0.298.000 (free) and Symantec-Endpoint Protection AV. Also have SpywareDoctor (free version), WinPatrol (free), and AdAware. I cannot visit websites like windows update or Malwarebytes, and cannot update any anti-spyware. I can, however, get to most other website and I can download programs so long as they are provided on a third party website so that I can right-click save them. Using this method I downloaded Malwarebytes and Trens Micro's rootkitbuster beta. Also I can run the programs.
AdAware and WinPatrol saw the thing on the way in; Adaware removed some of it, WinPatrol blocked it from running (more than it already had), and malwarebytes removed a it more (see below). From WinPatrol history the troubles are most likely associated with Cwf, CWG and/or FJ5MWNZTHI
From Malwarebytes log (3 problems):
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\msa.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\spool\prtprocs\w32x86\00000244.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully
From AdAware:
Win32.Hoax.Renos process
Both quarantined but not removed
Obviously the thing is still in my machine, because I cannot update my security programs and cannot go to malwarebytes or windows update websites. Because of this, please do not suggest that I manually update my programs from malwarebytes website. Tried that. I can post HJT and/or DDS logs. Please Help??

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked


Back to top










