Infected with 'Total Virus Protection'

#1 Lack


Posted 03 March 2009 - 10:28 PM

The infected computer is running Windows XP SP2. My father’s computer has become infected with what I believe is the rouge-ware known as ‘Total Virus Protection.’ He opened the file, so it has become active, but he did not buy the fake software. The symptoms include a significant slowdown in running programs, and non-stop pop-ups advising that I buy the program and claiming that the system is failing. There is also a fake button in the start bar, which came with a fake windows alert. In addition to these issues, I have also been unable to start the task-manager through any means. It has been completely disabled and the system does not recognize the account as an administrator. All of these problems also are apparent in Safe-Mode. When I ran my virus scanner, Asquared, it detected over 30 viruses that had come in with it and removed them. However, my scanner has been unable to remove ‘Total Virus Protection.’ In addition to the DDS log I am also including a HJT log. Thank you very much for taking the time to read this and help me out. You are the best.

HJT Log Below

#2 random/random


  Malware Response Team
Posted 12 March 2009 - 03:27 PM

This computer is heavily infected, including variants of Infostealer.Banker.C, Backdoor.IRC.Zapchast and Infostealer.Ldpinch.

I am sorry to inform you that one or more of the identified infections on your system is a Backdoor Trojan.

Backdoor Trojans are the most dangerous and most widespread type of Trojan. Backdoor Trojans provide the author or "master" of the Trojan with remote "administration" of victim machines. Unlike legitimate remote administration utilities, they install, launch and run invisibly, without the consent or knowledge of the user. Once installed, Backdoor Trojans can be instructed to send, receive, execute and delete files, harvest confidential data from the computer, log activity on the computer and more.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

In addition to the Backdoor Trojans that have been identified, your computer is afflicted with multiple other infections. Although we can make an attempt to clean this machine, we cannot guarantee that it will be secure afterwards. Your best and safest course of action is a reformat and reinstallation of the Windows operating system.

If you do decide to attempt cleaning rather than a reformat, do understand that although we may be able to remove all known visible malware, we cannot guarantee that unknown and unseen malware will have been removed, nor will your system be restored to its pre-infection state. We cannot remedy unknown changes the malware may likely have made in order to allow itself access, nor can we repair the damages it may possibly have caused to vital system files.

Please note that even if we should be successful in removing these infections from your system, it is quite possible that the changes made to the system by the malware may impact negatively on your computer during the removal process. In short, your system may never regain its former stability or its full functionality without a reformat.

Should you have any questions, please feel free to ask.

#3 Lack

  Topic Starter

Posted 13 March 2009 - 11:58 AM

Thank you very much. I thought that it was probably a lost cause, but I wanted to be sure. I disconnected it from the web as soon as I saw that it was infected and now I am very glad that I did. Once again, thank you very much. I will definitely post here in the future.

#4 Lack

  Topic Starter

Posted 13 March 2009 - 12:02 PM

Actually, I do have one question. Would it be safe to move picture files on the infected PC to a clean one? Thanks again.

#5 random/random


Posted 13 March 2009 - 10:18 PM

It will probably be OK to move the picture files, but it would be best to scan them with an antivirus program.

