Jump to content

Recommended Posts

Posted

Hi All ,

 

I am a bit stumped here !! I have been looking at a friends laptop for him after he downloaded a dodgy music track online. It basically installed a 'fake' windows security alert telling him to download a paid virus protection called paladin to remove it. I managed to get one care up and running on the laptop and removed the trojans on it .. they were :

 

PWS:WIN32/Zbot.gen!R

Trojan:Win32/fakecog

Trojan:Win32/alureon.DA

Trojan:Win32/hiloti.gen!D

Trojan:JS/Gord.B

TrojanDownloader:Win32/Reno...

 

A bunch of really nasty data stealing trojans! :(

 

 

if i try to use his laptop to get back online now .. thinking they had been removed .. either google chrome or IE crashes and i get the message it has been closed due to the data execution programme.

 

Is the laptop still infected somehow ? If so does anyone have any idea how i can get the system back to its old self ? Or is it pretty much a full re-format the only way to go ? Also the trojans listed are pretty nasty data stealers is this something my friend will now need to change al his online passwords etc .. ??

 

Any help would be great!!

  • Replies 7
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

  • ExTS Admin
Posted

Hi shaunyboy and welcome to FreePcHelp,

 

A bunch of really nasty data stealing trojans!
you are right to be concerned.

If we see these trojans before cleaning takes place, this would be our first reply:

 

Some browser hijackers and downloaders have been/are active on your computer. It is known that these trojans can communicate with remote computers, download and run code, send emails and redirect browser requests. Unfortunately we cannot be sure about what they have done.

 

If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable and it would be wise to contact those same financial institutions to apprise them of your situation.

 

Though the Trojans have been identified there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS.

 

For more information read ....Here

If you choose to format and reinstall read...... Here

 

Should you decide not to follow that advice, we will of course do our best to clean the computer of any infections that we can see but, as I already stated, we can in no way guarantee it to be trustworthy again.

 

As always.... it's your call.

I'm just trying to be honest with you.

Member of:

UNITE

Posted

Thanks Starbuck , thats pretty much my fears confirmed!! i have spoken to my friend and he is calling up his bank and credit card co and changing all his passwords on my laptop as its clean.

 

I am going to try a full reformat and install the OS again for him .. so is it likely that this trojan will be there regardless ? is there anyway once i have done the reformat to make sure there is no longer any traces of the trojans ?

 

Thanks for your help so far :)

  • ExTS Admin
Posted

If you just perform a reinstall of the OS, there's a good chance the malware will still be on the system.

If you reformat and then reinstall ... everything will be wiped out, including the malware.

Be careful what you backup first, just in case the malware is in any of the files/folders you are backing up.

especially if it arrived after downloading files from a P2P program.

Member of:

UNITE

Posted

Thanks starbuck , i am going to wipe the thing clean tonight. Theres alot of P2P downloads on there. So to be safe i am going to reformat and re-install the OS from the start. No major fils on it that need to be saved (phew)

 

Thanks for the assist :)

 

Shaun

Posted

Hi starbuck , i have hit a small snag i think while doing this, this will be my first re-format and reinstall ... my friend doesnt have a Vista install Cd. The Laptop was factory built with the OS installed. Whats the best way to sort this ? Will i need to purchase a copy of vista even though its on there ? Theres a recovery partition but i cant back this up either as DEP causes it to crash !!

 

Bad times!!

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...