I am totally new to this site but have been reading a little bit through a few posts.
I have come across two machines yesterday that were infected with a Trojan and/or Malware .
The machines infected all showed similar behaviour. Task Manager would flash on the desktop but would not open completely and a popup kept saying to install a language pack. The mouse and keyboard cursor was jumping around the screen.
When I booted up into Safe mode it was all OK. I ran a Scan with Symantec Corporate 10.2 and it picked up some infected files with the names Backdoor.Trojan. I went to Symantec site and ran all the Backdoor removal software. No viruses were found.
I installed and ran MBam which picked up a trojan and deleted all infected entries that it found.
Still when I logged in again the behovior returned. Over the last 5 hours or so I tried the following applications ATF-CLeaner, CCleaer, Super Anti Spyware, RUbotted, Trojan Guarder, GMER, COMBOfix, Hitman Pro, Winsockfix, was watching unusual traffic go back to Singapore and beyond using Wireshark.
In the end I used Hijackthis to create a log and manually go through all the entries that looked suspicious. Processors were infected, .exe files found in C:\windows, C:\windows\System32, C:Program Files, services were added, registry was completely infected....Basically the machine was a mess.....
After manually deleting the services, removing the .exe's from Program Files and System Files etc the machine seems to be stable...However I am still going to blow it away as I just wanted to learn more about this infection.
I have attached the Hijackthis log..I understand this is not the proper software to run and attach however the machine seems to be clean now so i dont want to waste anyones time running more software and posting results when it might not show teh complete picture......
I would be very gratefull thought if someone could please tell me what infected my machine and is there any software dedicated to removing this Trojan/Virus/Malware etc?
Many THanks for your help