According to AVG Free, it's called Win32/Cryptor and appears as two files:
Every time I have AVG quarantine the files or forcefully remove them, they reappear immediately. Safe Mode doesn't help. I have to turn of Resident Shield in order to keep using the computer without being bugged every five seconds with AVG's warning.
So I then installed & ran Ad-Aware. It goes through life thinking everything is fine. So does Spybot Search & Destroy.
Searching Google, I try a software that appears to be highly recommended, Malwarebytes' Anti-Malware. It's quick scan sees "Trojan.TDSS" in two places:
As a Memory Module in \\?\globalroot\systemroot\System32\geyekrttiqbeep. dll
As a File in the same location and with the same filename.
Strange how MBAM doesn't detect the .SYS file that AVG detected earlier. Anyway, it claims to remove them and reboot, but they reappear. Same thing during Safe Mode.
Tried HiJackThis 2.0.2. The only thing it sees as bad is a service called "vhosts," but it can't do anything about it. I then got Trojan Remover, by Simply Super Software. It detects that vhosts service and even removes it with a reboot. Now HJT doesn't see it anymore. Small victory.
But the Trojan still exists and still won't go away. AVG, Ad-Aware, Spybot S&D, Multi Virus Cleaner 2009, MBAM, HJT, and Trojan Remover all failed me. (I know Ad-Aware & Spybot S&D aren't for viruses, but I thought I'd give them a shot anyway.)
So after SEVEN different programs and dozens of attempts to kill this trojan, I'm totally lost. As I said, I'll buy dinner for anyone who can recommend a program (or even manual solution) that WILL get rid of this trojan, short of reformatting & reinstalling Windows.
Probably the worst part of this trojan is that this evil lump of nastiness likes to redirect all of my Google search results to other sites, generally if I'm going to an anti-spyware or anti-virus site. I have to copy & paste the link or retype it in the address bar, or click on the link many times using the "Back" button whenever it redirects me until it finally works.
Edited by SturmB, 28 July 2009 - 01:05 PM.