Question:
HELP Virus Win.32 Trojan!?
anonymous
2008-06-23 09:38:24 UTC
I am posting this again, because nothing worked!
On Saturday, I got bugged by a pesky spyware fraud virus, called Malware Bell, after using SuperAnti Spyware and Malware Bytes everything was fully removed. Then slowly hours later, all of a sudden my computer starts lagging and freezing, and then a bunch of spyware comes and it says computer critical condition? Anyway, I end up removing most of the stuff, then the next time I turned on my computer, the windows welcome screen apperaed, and it was just a blue blank screen, I read about the screen of death, and NO its not that, its just a blue blank screen, if I try using the alt ctrl thing, it doesnt work to end procedures! So, now im on safe mode and everything works fine and fast, I have tried several programs: AVG, SuperSpyware, Malware Bytes, Avast and even a couple others, I ended up removing several "Big" trojans, and many minor and low risk things, and now I am still in the dilema, of a blue blank screen. So I rebooted it back into safe mode, and ran the Avast boot scan. Which deleted over 600 files, but was unable to delete or move to chest a couple of them! I am assuming those are the ones causing this mess. I have a feeling the virus just keeps reinstalling itself? It is a Win.32 Trojan of somesort, every time I turn avast on safemode for a memory scan it says virus deteced and its identified as a Win32:Patched-EG located in c:\windows\explorer.exe, when I try to delete, or move it it says it cannot process it! Please help, I would like some specific instructions!
Seven answers:
golfer2
2008-06-23 10:20:04 UTC
The first thing is turn off your system restore if it hasn't already been affected.Then go to run and type in msconfig,go to startup and uncheck EVERYTHING but your anti-virus and firewall.Restart when it asks you,check the box and tell it not to run the utility again.Go to www.threatfire.com and get free threatfire, it's an amazing trojan tracker and remover.Install it and run a full scan.
anonymous
2008-06-23 11:10:21 UTC
use the hijackthis software, it is easy to use.

if you do not know, read this article that blog.acho that vai help you.

the hijackthis show a list of all processes and the site which it says are danger or not ...

http://howmakeyourself.blogspot.com/2008/05/how-to-use-hijackthis.html

look for more information on the blog.

I hope I have helped!
Sly_Old_Mole
2008-06-23 09:47:40 UTC
avg is a poor av do a free online scan:



http://www.bitdefender.com/scan8/ie.html



& download:



RogueRemover Free 1.24



http://www.majorgeeks.com/RogueRemover_d5360.html



& run:



http://www.bleepingcomputer.com/forums/topic18610.html



I think Win32:Patched-EG is a false positive: check by doing a free online scan here:



http://housecall.trendmicro.com/uk/



By the way you should only have one AV on your PC.
anonymous
2008-06-23 09:43:44 UTC
Your best solution would be saving everything and reformatting that for a fact will delete your virus.
anonymous
2008-06-23 10:05:54 UTC
Basically, your explorer.exe file has been meddled with. Your anti-virus can't delete it or fix it because the file is in use, obviously, as you are using your computer.



I am assuming you are using Windows XP. This may seem like a long solution, but it is simple if you follow the step-by-step instructions and don't jump the gun. Most of it is just me waffling on anyway.



You'll need to boot up in MS DOS mode, and if you run XP you'll need to create an MS DOS boot disk (can be floppy or USB).



When formatting a floppy diskette, users have the option of creating a MS-DOS startup disk (XP), follow the below steps to do this.



1. Place diskette in the computer.

2. Open My Computer, right-click the A: drive and click Format.

3. In the Format window, check Create an MS-DOS startup disk.

4. Click Start



Now you have an MS DOS boot disk.



Now, seeing as all explorer.exe files for windows are identical and should remain unchanged, you can swap your dud one's for my working ones. Download this:



http://www.fileden.com/files/2007/5/20/1096740/explorer.rar



Extract it using winRAR, 7zip or other program. Inside are two files, explorersp1.exe and explorersp2.exe - one is the file for service pack 1, the other is for service pack 2. You can find out which you run by right clicking on My Computer, and selecting properties. Now, for example if you run SP2, rename the explorersp2.exe file to explorer.exe, and put it on the MS DOS floppy. Make sure it is not in a folder or anything, just in the top directory.



Take the floppy, put it in your dud computer, boot up. When you arrive at the prompt stage, type:



"copy a:\explorer.exe c:\WINDOWS"



but without the quotation marks. This will copy a working explorer.exe to your system folder. Remove floppy, reboot computer, enjoy!



Any further question please email to clampstand@gmail.com



An alternative would be to insert the original Windows XP installation disk you got with your PC, and press "r" at the frst screen to repair system files. But I would use this as a latter option because it may replace all system files, which can be problematic and cause your programs to not function correctly/at all.



This will get your OS back on its feet.



Then install and run ESET NOD32, the best antivirus out there. I have included a link and instructions below.



http://www.fileden.com/files/2007/5/20/1096740/ESET%20NOD32.rar



ESET NOD32 link ^.



ESET NOD32 Business Edition. Firewall and antivirus/spyware. Offers real-time protection against threats. If you already have a firewall you can disable ESET's, but I wouldn't recommend it, you can use two firewalls in conjunction (but not two anti-viruses with real time protection, so be careful, it can lead to reduced performance).



Extract the .rar archive (with something like WinRAR or 7zip, you can google for them), double click the setup file (NB, a .msi file is just a different type of installer package, do not worry lawl). When it asks you, enable threatsense early warning system, and click the check box saying set update parameters later (this is for updates to your anti-virus definitions). Also, I like having my firewall on Interactive mode, for greater control. Then you just have to allow/deny the programs you choose internet access - i.e. allow Firefox/IE and any online games you may play, deny anything dodgy looking.



It'll install nicely, when it's open click the updates tab and press update Virus Signature Database (or words to that effect). It'll come up with a box asking for your username and password. Now double click the other file that was in the .rar archive, the "ESET Logins Viewer". Allow it internet access, and it'll come up with a list of usernames and passwords for ESET. Just take the top one and copy and paste them, hit okay and let it update.



The first update may take a while. Each username/password configuration will run out every week or so, so you'll have to update the username and password you use every so often, when it comes up with a box saying "Incorrect username/password".



Any further questions, just ask or email me - clampstand@gmail.com



Oh, and if anything asks, you should allow "egui.exe" access to the internet - that is ESET. "ekrn.exe" is also an ESET-related process.



If you are unsure about allowing anything access to the internet, google for it. If you get little/no results it's best not to, and if you do get results then look at a few to see whether to allow/deny accordingly.



If you do not like paying for or torrenting programs, you can also try here: http://www.webroot.com/En_US/consumer-downloads.html, and click the "get free scan" scan box for the top piece of software (Webroot Spy Sweeper). Spy Sweeper is another good piece of kit that isn't as well known as it ought to be, this link gives you a free computer scan.



Hope all goes well,



Regards,



- Jake (real name)



email: clampstand@gmail.com
mavis
2016-05-23 12:10:27 UTC
haha your asking the right person downlode one or more of these FREE malwarebytes superantispyware hitman pro 3.5 i like useing malwarebyte and superantispywar in combination malwarebytes should get the bulk of it though 10 points if you like just scan and you can remove essaly
anonymous
2008-06-23 10:05:11 UTC
Format your hardisk in MSDOS mode, and re-install the OS


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...