Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

need help with trojans

Status
Not open for further replies.

Athanasopolous

Programmer
Jun 25, 2005
40
0
0
US
I suspect that my problem started when my spouse
downloaded what she thought was an anti-virus program
(these hackers are clever).

I have seen this program pop-up. The name is something
like "Anti-Virus 2008 XP".

I have a lot of questions in solving this problem.

First of all, the computer is using Windows Vista.
Isn't there some way to set the computer back to
a previous setting like you used to be able to do
with XP?

Secondly, the anti-virus program that caught the
the problem and yet did not fix it was AVG. All it
did is continue to pop up annoying notices that there
was a trojan but did not remove it. I did some
search and I found on a forum that it might be a
false positive. Is it?

Here is a screen shot of what AVG said:


I never saw anything online about the Trojan Horse SHeur.BZZL.
So I wonder if it is a false positive.

I ran BullGuard anti-virus and it seemed to notice it but
instead it wanted me to send a notice to its server about
the problem and it too did not seem to fix the problem.

Thinking it is a false positive, I removed the AVG program
because I could not do anything really with all of the AVG
pop-up warning messages.

On the other hand, where AVG pointed was a bit troubling.

C:\Program Data Secure Solutions\Antispyware 2008 XP\as2008xp.exe
does seem to be the culprit. I tried to delete this file but
it seemed to appear and then disappear and/or seemed to be protected.
So this leads me to this question. How do I start Vista in safe
mode so that I can remove a program or file?

I also tried to delete the temp file shown here.


C:\Users\Gelsana\AppData\Local\Temp\win61D3.exe

But this file was also protected or would appear and disappear.

It seems that Antispyware 2008 XP is an evil program.

After I removed AVG from the program, I ran BullGuard and it
gave different errors.


Now I have Trojan.Mezzia.DP

and BullGuard seemed to say that it could not remove it.

 
Hi there,

You could try using system restore to an earlier date.


Or you could boot to safe mode with networking and run a free online virus scan at eg.


To boot to safe mode:


HTH.

Peter.



Remember- It's nice to be important,
but it's important to be nice :)
 
Download copy of hijackthis from here


Then run it and post the log file here.

what she thought was an anti-virus program
(these hackers are clever).

Well no they are not that clever, they rely on many computer users not taking the care they should do.

The basic advice here is Never Ever just search for 'Anti virus' on the web, always get recommendations from forums or check out reviews in reputable magazines.

AVG is a fine program but its a first line defence only, it should always be backed up with Antispyware e.g Spywareterminator and a Firewall e.g COMODO plus a Hardware firewall e.g. a Router with NAT is good as well.



Steve: N.M.N.F.
If something is popular, it must be wrong: Mark Twain
 
Recently one of our users was infected with this virus and I followed these steps

First you need to stop the program from loading on startup. This is what you do to stop it:

Start, run

Type msconfig

Go to Startup tab

Uncheck lphc35dj0e1an
Uncheck rhc75dj0e1an

Click apply, then ok
Restart computer


Then you need to delete the main files this program uses. Delete the following file:

C:\windows\system32\lphc35dj0e1an.exe

Then delete the following folder and all files in it:

C:\program files\rhc75dj0e1an

This should remove the program from your system but you probably still have a warning message displayed as your wallpaper in Windows and the virus removed the ability to change the wallpaper or your desktop settings.

To restore ability to change your desktop settings and select a different wallpaper and screen saver do the following:

Start, run

type Gpedit.msc

Navigate to User configuration, Administrative Templates, Control Panel, Display

Right click on Remove Display in Control Panel
Click on Properties and select Disabled

Do the same steps to change the following attributes to disabled:

Hide Desktop Tab
Prevent changing wallpaper
Hide Apperance and Themes tab
Hide Settings tab
Hide Screen Saver tab

You should now be able to use your computer normally and change the wallpaper to something other than the warning message Antivirus XP 2008 set it to.



Twist

===========================================
Everything will be OK in the end.
If it's not OK, then it's not the end
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top