2010-10-03, 19:35
So here it is - I started trying to fix this prob when XP Firewall stopped running because "Windows cannot start the Windows Firewall/Internet Connection Sharing (ICS) service."

Tried installing spybot and a2AntiMalware, but can't connect to their servers for updates etc

That's what led me here. I should mention that this laptop I'm on has had issues for quite a while, where it just freezes up and nothing can be done except pull the plug and reboot. I've just got a new laptop so I'm trying to fix this one.

Sorry If I've misunderstood your requirements from me, or if I'm not following the correct procedures, but there is my DDS report:-


2010-10-06, 11:13
One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? (http://www.dslreports.com/faq/10451)
When Should I Format, How Should I Reinstall (http://www.dslreports.com/faq/10063)

However, if you do not have the resources to reinstall your computer and would like me to attempt to clean it, I will be happy to do so.
Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next post.

2010-10-07, 11:16
No Way! :oops:

Thankyou very much for pointing this out to me. I've contacted the relevant banks who have suspended online banking until I can be sure the infected computer is clean again. I've also changed the passwords to my ebay, amazon and paypal accounts.

As it happens, I've just got a new laptop from Medion, so I should be OK to use this whilst I reformat the infected one. It is odd however that this problem occurred around the same time I connected the two computers on the same network. It could just be conincidence I suppose.

I do worry - could the new laptop have picked anything up by being networked to the old? It came bundled with Bullguard, which doesn't seem to be picking up any problems. Is this enough security in itself, or would you suggest other security applications to go with it?

Thanks again for your time and advice, I haven't got a clue about this sort of thing, although I know I can manage a reformat and OS install OK.

2010-10-07, 17:12

I do worry - could the new laptop have picked anything up by being networked to the old?
If no issues then I'd say it's safe to assume it hasn't picked anything bad.

It came bundled with Bullguard, which doesn't seem to be picking up any problems. Is this enough security in itself, or would you suggest other security applications to go with it?
I'm not familiar with Bullguard so can't say about it. Anyway, please find some good solutions listed next (note: don't install more than one antivirus program in same workstation).

Good free antivirus programs are:
Antivir (http://free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html) and
Avast! (http://www.avast.com/eng/download-avast-home.html)

Good commercial ones are from:
Kaspersky (http://www.kaspersky.com/homeuser) and
ESET (http://www.eset.com/products/index.php)

2010-10-08, 12:03
Blade, Yes everything seems OK on the new laptop. Bullguard is the security suite that came bundled with Windows 7, so I suspect it is fairly robust. :police:

I wonder if it was just a computer program that got into my other system? Or a real person? How do they do it? :confused: I know these answers are probably available to me if I google them.

Where does the trojan sit though? Is it safe to bring files and folders over from that system to the new one? I guess I'd do it by memory stick and I should scan them first. I'll have to be more careful in the future. muha:

Most of all though, :thanks:, for making sense of the situation for me. I do wonder though, if the Windows firewall hadn't turned off, how long could I have been under attack without knowing. It's like they made a mistake and 'trod on a twig' if you know what I mean.

As it happened I intended to reformat and reinstall OS anyway, because I've had the laptop for years and it was slowly grinding to a halt. More often than not it would freeze up and I'd have to force it to turn off rather than close down in the proper way. Do you think this was a symptom of the infection at all?

It's all quite exciting, but i can see it could be potentially catastrophic, I have two years worth of business accounts on there, as well as doing online banking and things. Makes you feel a bit queesey :sick:

2010-10-08, 18:48

Looking at the log it looks possible bad stuff got there via exploitable vulnerabilities. For example Java and Adobe Reader are badly outdated (and also some of those most exploited ones too).

2010-10-14, 15:47
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

