This sounds particularly nasty. You can troubleshoot it for a few hours and still not get anywhere with it, or you can cut your losses and do a PC Restore back to factory default. A PC Restore is different from a Windows re-installation, because a PC Restore will restore the computer back to how it was when you opened it out of the box with all the applications and drivers already installed. It takes about 10 minutes or less compared to the one hour+ it takes with the Windows CD. To perform a PC Restore hit CTRL + F11 at the Dell splash screen at the startup to start the application. From there, just follow the prompts.
If that is the exact name, that particular Trojan allows attackers to access your computer from remote locations, stealing passwords, Internet banking and personal data. If it were my computer and I just discovered this type of trojan, I would be backing up my important files and
reinstalling everything from scratch. There are so many changes that could have been done if that backdoor was used.
Here are some informative links to use to help you make a decision:
However, if you do not have the resources to reformat your computer and reinstall your operating system and programs and would like us to attempt to clean it, we will be happy to do so. Please post a HijackThis log on the HijackThis Board.
** There is a list of trained analysts at the top of that board in the Announcements. If someone else replies, it will be your decision whether or not you want to take advice from them.
Please download
HJT Installer from
Here to your desktop.
If not available use this alternate link:
Here
Click the
Download button.
When the Trend Micro HJT install box appears, double click on the
HJTInstall.exe.
Click on Install.
It will be installed by default here: C:\Program Files\Trend Micro\HijackThis
A shortcut to the application will also be placed on your Desktop.
The program will open automatically after installation.
You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder.
The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.
Close all open windows except HijackThis.
Click on "
Do a system scan and save logfile" When the log pops up in Notepad copy and paste that file as a NEW MESSAGE on the HijackThis Board.
Before closing HJT, please click on the
Analyze This button. "Analyze This" is for Trendmicro use, and does not mean "Analyze My Log". You must post on the forum in order to receive an analysis of your log.
Close the web page that appears and then close the program HJT.
Posting Your Log:
1. Just click the New Message button in the HijackThis forum here:
http://www.dellcommunity.com/supportforums/board?board.id=si_hijack to start your own thread requesting assistance.
2. In the Message Body window that opens, simply Right-Click and select Paste.
3. Please add text to describe your symptoms.
4. Include in the message subject line a description of your problem. For example, "Popups warning of infection".
5. Make certain you post the entire log by clicking the Preview Post link at the bottom of the window and comparing it to the log from your scan before you click Submit Post
** Note: "The box next to Automatically convert carriage returns to HTML line breaks" should be checked if that appears at the bottom of your Message Body when composing your post.
* DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or required.
Doing a PC Restore back to factory default may not completely clean your problem, depending on how deeply the infection was hooked into your system. That is why I suggested reinstalling from scratch. It might be good to run an in-depth Anti-Virus/Anti-Rootkit scan.
Platypus123
30 Posts
0
August 8th, 2007 02:00
Bugbatter
3 Apprentice
•
20.5K Posts
0
August 8th, 2007 13:00
Here are some informative links to use to help you make a decision:
Danger: Remote Access Trojans
Consumers � Identity Theft
When should I re-format? How should I reinstall?
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
Rootkits: The Obscure Hacker Attack
Help: I Got Hacked. Now What Do I Do?
Help: I Got Hacked. Now What Do I Do? Part II
Microsoft Says Recovery from Malware Becoming Impossible
However, if you do not have the resources to reformat your computer and reinstall your operating system and programs and would like us to attempt to clean it, we will be happy to do so. Please post a HijackThis log on the HijackThis Board. ** There is a list of trained analysts at the top of that board in the Announcements. If someone else replies, it will be your decision whether or not you want to take advice from them.
Please download HJT Installer from Here to your desktop.
If not available use this alternate link: Here
Click the Download button.
When the Trend Micro HJT install box appears, double click on the HJTInstall.exe.
Click on Install.
It will be installed by default here: C:\Program Files\Trend Micro\HijackThis
A shortcut to the application will also be placed on your Desktop.
The program will open automatically after installation.
You can double-click the icon that was placed on the Desktop to run subsequent HijackThis scans or you can use the icon inside the folder.
The folder HijackThis is where you will find the HJT logs that you save. When you use the application to remove anything, you will also find the backup copies made by HJT inside this folder.
Close all open windows except HijackThis.
Click on " Do a system scan and save logfile" When the log pops up in Notepad copy and paste that file as a NEW MESSAGE on the HijackThis Board.
Before closing HJT, please click on the Analyze This button. "Analyze This" is for Trendmicro use, and does not mean "Analyze My Log". You must post on the forum in order to receive an analysis of your log.
Close the web page that appears and then close the program HJT.
Posting Your Log:
1. Just click the New Message button in the HijackThis forum here: http://www.dellcommunity.com/supportforums/board?board.id=si_hijack
to start your own thread requesting assistance.
2. In the Message Body window that opens, simply Right-Click and select Paste.
3. Please add text to describe your symptoms.
4. Include in the message subject line a description of your problem. For example, "Popups warning of infection".
5. Make certain you post the entire log by clicking the Preview Post link at the bottom of the window and comparing it to the log from your scan before you click Submit Post
** Note: "The box next to Automatically convert carriage returns to HTML line breaks" should be checked if that appears at the bottom of your Message Body when composing your post.
* DO NOT have Hijack This fix anything yet. Most of what it finds will be harmless or required.
humphrad
2 Posts
0
August 8th, 2007 21:00
Bugbatter
3 Apprentice
•
20.5K Posts
0
August 9th, 2007 00:00