Link to home
Start Free TrialLog in
Avatar of Daniele Brunengo
Daniele BrunengoFlag for Italy

asked on

I have a virus or trojan which has blocked antivirus and antispyware on my pc. I cannot install them back. What can I do?

Today I found that Nod32, Spybot and Zsoft Uninstaller have disappeared from my pc and I cannot install them back. The executables don't show up anymore in their folders and the icons pointing to them have become generic icons, but if I try to reinstall or copy the executables from a backup they won't be copied. For instance if I try to rename any file to uninstaller.exe (the name of the Zsoft executable) I get an error: "Impossible to write uninstaller.exe", anywhere I try to write it. I cannot have a file named uninstaller.exe or nod32.exe anywhere on my pc anymore! Please help me I'm desperate, I've never been beaten by a virus before.
Avatar of Crash2100
Crash2100
Flag of United States of America image

You could try an online virusscan, or booting from your anti-virus CD.

http://housecall.antivirus.com/
ASKER CERTIFIED SOLUTION
Avatar of IndiGenus
IndiGenus
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Daniele Brunengo

ASKER

I have uploaded this to my site:

http://www.deathless.it/hijackthis.txt

I am running the findawf utility, seems to take a while.
And here is the log, but I've checked it and they're all bak files made by me:

http://www.deathless.it/awf.txt
Looks like this virus kills also browser windows when I run an online antivirus software and it tries to clean the system...

I have a backup of my hard disk from the last few days, if I recover the windows hard drive do you think it will work?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Ok I'll give it a try,,, The infection is from today for sure, so the image is from before the infection.
It seems to have worked, it's back to normal apparently. But I'm quite irritated by the fact that Nod32 didn't warn me about this infection at all.
Glad it's working. Do you know you have a keylogger installed?

O4 - HKLM\..\Run: [Free Key Logger] "C:\Programmi\Free Key Logger\FreeKeyLogger.exe" minimized
This is exactly why I can't stress the value of backing things up enough!  I'm glad to hear you got it working again.
About the keylogger, I tried one out once for a friend, but it's not there now so it may have been another present from the virus package that hit me today. The online scanner was signaling 5 viruses before being closed... I don't really know what happened.

I'm glad I back up the main hard drive each morning. I guess I'll give points to you both, is it ok?
That's fine with me.