fatdad1961
New member
Please help.
My son's laptop has become infected with a trojan. AVG detected the infection and removed some of the files to the virus vault but two have remained infected (see AVG scan results below).
I tried to produce a HJT log but couldn't - I downloaded the HJT installer, ran the install, ran the "Do a system scan and save a logfile" - it briefly displayed the logfile but then disappeared. Any attempts to run HJT now is greeted by the following message:
"Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item"
We get the same message when we try to launch Spybot S&D.
The laptop runs on VISTA.
AVG Scan results:
"Scan ""Scan whole computer"" was finished."
"Infections";"8";"6";"2"
"Warnings";"1"
"Folders selected for scanning:";"Scan whole computer"
"Scan started:";"07 September 2009, 01:50:45"
"Scan finished:";"07 September 2009, 02:25:31 (34 minute(s) 46 second(s))"
"Total object scanned:";"433758"
"User who launched the scan:";"Philip"
"Infections"
"File";"Infection";"Result"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OEX9D0T7\zoovid_275.40001[1].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D9KTRPSW\zoovid_275.40001[1].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JTHOFTP8\zoovid_275.40001[1].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JTHOFTP8\zoovid_275.40001[2].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JTHOFTP8\zoovid_275.40001[3].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Temp\b.exe";"Trojan horse Crypt.GSX";"Infected"
"C:\Users\Philip\AppData\Local\Temp\b.exe";"Trojan horse Crypt.GSX";"Infected"
"C:\Users\Philip\AppData\Local\Temp\c.exe";"Trojan horse Crypt.GTD";"Moved to Virus Vault"
"Warnings"
"File";"Infection";"Result"
"HKU\S-1-5-21-1535638791-1735451515-4138593479-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Monopod";"Found registry key with reference to infected file C:\Users\Philip\AppData\Local\Temp\b.exe";"Moved to Virus Vault"
Any help or guidance you can give would be greatly appreciated.
Thanks, Fatdad
My son's laptop has become infected with a trojan. AVG detected the infection and removed some of the files to the virus vault but two have remained infected (see AVG scan results below).
I tried to produce a HJT log but couldn't - I downloaded the HJT installer, ran the install, ran the "Do a system scan and save a logfile" - it briefly displayed the logfile but then disappeared. Any attempts to run HJT now is greeted by the following message:
"Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item"
We get the same message when we try to launch Spybot S&D.
The laptop runs on VISTA.
AVG Scan results:
"Scan ""Scan whole computer"" was finished."
"Infections";"8";"6";"2"
"Warnings";"1"
"Folders selected for scanning:";"Scan whole computer"
"Scan started:";"07 September 2009, 01:50:45"
"Scan finished:";"07 September 2009, 02:25:31 (34 minute(s) 46 second(s))"
"Total object scanned:";"433758"
"User who launched the scan:";"Philip"
"Infections"
"File";"Infection";"Result"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OEX9D0T7\zoovid_275.40001[1].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\D9KTRPSW\zoovid_275.40001[1].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JTHOFTP8\zoovid_275.40001[1].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JTHOFTP8\zoovid_275.40001[2].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JTHOFTP8\zoovid_275.40001[3].exe";"Trojan horse Crypt.GRX";"Moved to Virus Vault"
"C:\Users\Philip\AppData\Local\Temp\b.exe";"Trojan horse Crypt.GSX";"Infected"
"C:\Users\Philip\AppData\Local\Temp\b.exe";"Trojan horse Crypt.GSX";"Infected"
"C:\Users\Philip\AppData\Local\Temp\c.exe";"Trojan horse Crypt.GTD";"Moved to Virus Vault"
"Warnings"
"File";"Infection";"Result"
"HKU\S-1-5-21-1535638791-1735451515-4138593479-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Monopod";"Found registry key with reference to infected file C:\Users\Philip\AppData\Local\Temp\b.exe";"Moved to Virus Vault"
Any help or guidance you can give would be greatly appreciated.
Thanks, Fatdad