PDA

View Full Version : Trojan Virus



Orion_11
2011-05-14, 19:39
I am having a serious problem with a trojan virus that bypassed my old etrust virus software. It is a generic win32 trojan, and that was not hard to find out since etrust told me it cured the file.

But! Recently, my computer kept spitting out errors about Generic Win32 something or another. I checked out the error report and it kept leading me to the Temp folder in my local settings.

At first, I just surveyed the file in the temp folder, and the first time, was looking at it, and it jumped. Completely disappeared. So, I restarted my computer and waited for the error to pop up again. Sure enough, it did. I went to delete it this time, and did so. Emptied my recycle bin and done was done.

THEN! I went to get on my net, and it would not let me connect due to firewall trouble. So I went to check firewall settings, and it would not let me access my firewall. It said the associated program was not running.

Now, I went to check my temp folder again to make sure everything was gravy, but that damn file was back. It was at the following location:

C:\Documents and Settings\Debate\Local Settings\WERc08f

In that folder, there were four file, sometimes two when I opened. The important file that always kept coming back was appcompat.txt. I always deleted the files in that folder because they were responsible for major errors that happened on the computer.

I know its the generic trojan and I found out how to delete it here:


Now, I was following the direction in the Registry, but when I got to the "run" part, there was no rnd1 and rnd2 things, so I was not helped. So, i stopped and did nothing.

I went back to the temp files and deleted them all, save for the Perflib_Perfdata_ee0 file. I could not and still cannot delete that one and when I tried to, it did nothing. So i left it open while I tried to go back on the net, and it created empty file when IE8 opened as a trial, even though I use firefox. So, this is where I am at.

That last file is the problem and I cannot delete it, so how do I do it? I need help please and asap. Thank you.

tashi
2011-05-14, 21:50
Hello Orion_11,

So that everyone is on the same track please see the forum FAQ which also includes instructions for posting preliminary DDS logs for analysis in post #2.
"BEFORE You POST"(Please read this Procedure Before Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start a new topic providing the DDS logs as shown in that sticky and a link back to this thread. A volunteer analyst will advise you when available. :)

If the DDS won't run please start a new topic anyway and make a note of the issue.

Best regards.