I'm sorry to say that your computer is infected with one or more backdoor trojans.
This means that sensitive information could have been stolen
. I would advise to change any passwords for any accounts that you have accessed with the infected computer using a clean computer ASAP. If you have used this computer for banking, I would strongly suggest that you report the possible stolen information. Please do not
use the computer for any further transactions, or to enter any other information, if at all possible, until it is declared clean.
You may want to read this article
on how to handle identity theft.
You may also want to read this article
regarding preventing of identity theft.
This computer can still be cleaned, however, I cannot guarantee that it will be 100% safe even after disinfection.
Please read When Should I Format, How Should I Reinstall
.I will proceed assuming you wish to disinfect. If you want to do a reinstall, reply back saying so.Install ERUNT
This tool will create a complete backup of your registry. After every reboot, a new backup is created to ensure we have a safety net after each step. Do not delete these backups until we are finished.
- Please download erunt-setup.exe to your desktop.
- Double click erunt-setup.exe. Follow the prompts and allow ERUNT to be installed with the settings at default. If you do not want a Desktop icon, feel free to uncheck that. When asked if you want to create an ERUNT entry in the startup folder, answer Yes. You can delete the installation file after use.
- Erunt will open when the installation is finished. Check all items to be backed up in the default location and click OK.
You can find a complete guide to using the program here:http://www.larshederer.homepage.t-online.de/erunt/erunt.txt
When we are finished with fixing your computer (I will make it clear when we are), you can uninstall ERUNT through Add/Remove Programs
. The backups will be stored at C:\WINDOWS\erdnt
, and will not be deleted when ERUNT is uninstalled.How to Restore from the ERUNT Backup
Only restore from the backups if instructed to, or you need
to do so. You need it if after doing somethine, your computer will only boot in Safe Mode and you are unable to contact us (or anyone else) for help by other means, or if your computer will not boot into Windows at all.
To restore when booted, navigate to C:\WINDOWS\erdnt
, choose the folder with the most recent date, and double click ERDNT.EXE
. Check all boxes in the restoration options.
To restore from the Recovery Console using the Windows CD:
Install Recovery Console and Run ComboFix
- Turn on your machine with the disk in the drive.
- Type in the number of the Windows installation you want to repair (usually 1), then press Enter.
- Type in the Administrator password (leave blank if you are unsure what it is or if you do not have one) and press Enter.
- Type without quotes "cd erdnt" followed by Enter.
- Type without quotes "dir" followed by Enter. This will list out the available folders, whose names are the date on which the backup was taken in (M)M-DD-YYYY format. Try the most recent dates first.
- Type without quotes "cd **name of the folder**" followed by Enter.
- Type without quotes "batch erdnt.con" followed by Enter.
- Type without quotes "exit" followed by Enter.
- Remove your CD from the drive and reboot your computer into the restored registry. If you still cannot boot, try again with an earlier restore date.
from any of the links below, and save it to your desktop
. Link 1
, Link 2
, Link 3
Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System.
Leave your computer alone while ComboFix is running.
- Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
- Download the file and save it as it's originally named onto your desktop.
- Drag the setup package onto ComboFix.exe and drop it.
- Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.
- At the next prompt, click NO to skip the scan for now.
ComboFix will restart your computer if malware is found; allow it to do so.Install Antivirus
An anti-virus is essential in keeping your computer safe while surfing the Internet. Please install a free anti-virus program from one of the trusted venders below:
After installing, update the database, run a full system scan and remove any items found.
Please post back with:
-the ComboFix log
-a new HijackThis log