Please help with unremovable trojans/viruses

S

Starman

My anti-virus has found 68 different variations of this trojan most of them
satrting with downloader.agent. Most of these infected files are exes. I ran
the computer in safe mode and used ad-aware, spy-bot, anti-virus software,
cwshredder and god knows what else to no avail. These infections are still
remaining on my computer. Particularly the nasty three of Search
Assistant/Search Extender? Downlader.agent. Please help me in what to do to
rid these. I'm at
of my tether and am genuinely seeking somebody's help.

Thank you.
 
D

David H. Lipman

I'll take it you saw my other reply already.

Dave



| My anti-virus has found 68 different variations of this trojan most of them
| satrting with downloader.agent. Most of these infected files are exes. I ran
| the computer in safe mode and used ad-aware, spy-bot, anti-virus software,
| cwshredder and god knows what else to no avail. These infections are still
| remaining on my computer. Particularly the nasty three of Search
| Assistant/Search Extender? Downlader.agent. Please help me in what to do to
| rid these. I'm at
| of my tether and am genuinely seeking somebody's help.
|
| Thank you.
|
|
 
M

Max M.Wachtel III

Starman said:
My anti-virus has found 68 different variations of this trojan most of them
satrting with downloader.agent. Most of these infected files are exes. I ran
the computer in safe mode and used ad-aware, spy-bot, anti-virus software,
cwshredder and god knows what else to no avail. These infections are still
remaining on my computer. Particularly the nasty three of Search
Assistant/Search Extender? Downlader.agent. Please help me in what to do to
rid these. I'm at
of my tether and am genuinely seeking somebody's help.

Thank you.
Beginning of standard canned reply….

Update Windows. Use a firewall.
Use an Anti-Virus of your choice and keep it updated.
In Windows Explorer, set Folder Options to “show all files”.
Clean out all temp, cache, ect. files.
Download BeClean here:
http://boozet.xepher.net/beclean/

Download Sysclean from here:
http://www.trendmicro.com/ftp/products/tsc/sysclean.com
Read this:
http://www.trendmicro.com/ftp/products/tsc/readme.txt
Reboot into safe mode and run Sysclean, write down results, then reboot
normally.
If offending file is in “restore” read this:
http://service1.symantec.com/SUPPOR...2001111912274039?OpenDocument&src=sec_doc_nam

Download AdAware from here:
http://www.majorgeeks.com/download506.html
Read the help files and then Update and run AdAware.
If you lose your Internet connection after running AdAware download
Winsock Fix here:
http://www.tacktech.com/display.cfm?ttid=257

Download Spybot Search+Destroy here:
http://www.safer-networking.org/en/download/index.html
Read this:
http://www.safer-networking.org/en/tutorial/index.html
Update and run Spybot (enable all protection).

Download Spyware Blaster here: (enable all protection)
http://www.javacoolsoftware.com/spywareblaster.html

Run a couple of online scanners (pick a different one than your main AV):

BitDefender:
http://www.bitdefender.com/scan/licence.php

Norton:
http://security.symantec.com/sscv6/...d=sym&plfid=23&pkj=XHPGJRSOMVZGYYTZXPE&bhcp=1

Panda:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

eTrust:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

House Call:
http://housecall.trendmicro.com/housecall/start_corp.asp

If the previous do not solve your problems:
Download Bazooka here:
http://www.kephyr.com/spywarescanner/

Download SwatIt here:
http://swatit.org/

Download KL-Detector here
http://dewasoft.com/privacy/kldetector.htm

Download CWShredder here
http://www.intermute.com/spysubtract/cwshredder_download.html

Download HijackThis here:
http://www.majorgeeks.com/download3155.html
Install, run and save the log that is created. Don’t let it fix anything
yet!
You can find forums to post the log to have it analyzed here:
http://tomcoyote.org/hjt/

Download Stinger here:
http://vil.nai.com/vil/stinger/

Download eScan here:
http://www.mwti.net/antivirus/free_utilities.asp
Rename the downloaded file escan.zip and extract (with a zip program) to
C:\Downloads, which you will have to create. Run the updater
(kavupd.exe) and then run eScan (mwavscan.exe).


…. End of standard canned reply.

--
Keeping Windows Clean: http://www.geocities.com/maxpro4u/madmax.html
Virus Cleaning+Fixes: http://www.geocities.com/maxpro4u/TechPros
Change nomail.afraid.org to neo.rr.com so you can reply by e-mail
(nomail.afraid.org has been set up specifically for
use in Usenet. Feel free to use it yourself.)
 
S

Starman

I've tried everything as outlined by everyone and others. I even purchashed
the
software Spyware Doctor which found the infections and deleted. But, they
returned and now the Spyware Doctor says I have no infestations but the
culprits are still there.

In my control panel you can';t delete Search Assistant or Search Extender so
the hijacking keeps infecting my computer. Please, please help me, I'm at
the end of my tether. There has to be something to rid this infection. And
these infections are somehow preventing me from downloading updates for my
anti-virus, spyware doctor etc softwares.

Star
 
J

James Egan

In my control panel you can';t delete Search Assistant or Search Extender so
the hijacking keeps infecting my computer. Please, please help me, I'm at
the end of my tether. There has to be something to rid this infection. And
these infections are somehow preventing me from downloading updates for my
anti-virus, spyware doctor etc softwares.


Download these two utilities from sysinternals

http://www.sysinternals.com/ntw2k/freeware/procexp.shtml
http://www.sysinternals.com/ntw2k/freeware/autoruns.shtml

Run the process explorer first and close down processes you don't want
or know about. You might find that as soon as you close a process down
it is started up again as the child of another process, If this
happens use the kill process tree option to zap the unwanted processes
at the same time.

After you have done the above (and it appears there's more than one),
run the autoruns program to see what is loading at system startup.
Uncheck the boxes of programs you don't want to load. That should do
it. You should be able to delete any residual files if you want to.

Don't do step 2 until step 1 has been satisfactorily completed. The
unwanted running programs will likely also be checking the system
startup entries in the registry and if you remove the registry
references before shutting down the unwanted processes they will most
likely be written straight back.


Jim.
 
S

Starman

Jim,

Thanks for this, I will do this and report back with the results later.
Here's hoping this finally works! If it does, I owe you one big time.

Star
 
S

Starman

I finally got rid of these trojans by purchasing and running Spyware Doctor
in safe mode. My system is now completely clean!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top