Solved

Trojan "Spyware protection, Designed to protect"

Posted on 2010-11-19
6
5,867 Views
Last Modified: 2013-12-09
I have a user who has contracted some sort of trojan.  Looks like it modifies defender.exe, and runs a program called "Spyware protection, Designed to protect" and gives the same garbage not letting me open just about anything, saying my computer is infected.  I've run malwarebytes anti-malware on it in safe mode, found something, removed it, but it is still there.  I even attached the HD to another computer and ran MBAM on the entire drive and nothing.  A system restore seems to have put a band-aid on the problem.  Symantec sees that defender is causing problems, but does not detect the virus.    any suggestions?
0
Comment
Question by:Winstink
6 Comments
 
LVL 5

Accepted Solution

by:
frostsystems earned 250 total points
Comment Utility
From safe mode, run Hitman Pro and then run Combofix. Problem solved.

Hitman Pro is available from www.surfright.nl

Combofix is available from http://www.bleepingcomputer.com/combofix/how-to-use-combofix
0
 
LVL 26

Assisted Solution

by:Thomas Zucker-Scharff
Thomas Zucker-Scharff earned 250 total points
Comment Utility
If your computer is now functioning properly make sure you delete all old restore points and create a new clean one:
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/XP/A_2209-Removing-protected-System-Restore-files-if-they-have-been-infected.html

BUT ONLY IF YOU HAVE A WORKING REBOOTABLE COMPUTER!

Check out the free version of this little tool, it may help:

http://www.iobit.com/ascdownload-promo.html
0
 
LVL 27

Expert Comment

by:Jonvee
Comment Utility
For the record, both Malwarebytes & ComboFix should be run in normal mode where Malware are usually the most active.  You can run in safe mode at times when you're unable to reach normal mode.

There is a good 'disinfection guide' here, by rpggamergirl :
http://www.experts-exchange.com/Software/Internet_Email/Anti-Virus/A_1979-THINGS-YOU-NEED-TO-DO-WHEN-YOUR-PC-IS-INFECTED.html

If still unsuccessful, try running an Eset online scan, it has proved to have been effective when other scanners have failed:
http://www.eset.com/online-scanner
0
Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

 
LVL 27

Expert Comment

by:Jonvee
Comment Utility
You could also try temporarily uninstalling Defender, if not yet tried.   Then re-install Defender & fully update.
0
 
LVL 9

Expert Comment

by:faizbaig
Comment Utility
Following option may resolve your issue..

-> Right click " Defender.exe" or " "Spyware protection" icon you see on the desktop..etc. and click on "Properties" and click on "Find target" tab and try deleting that ".exe" file via normal mode or safe mode.

&

-> Look for "defender.exe" or "Spyware protection" on startup list and unselect the box if you find one.

0
 
LVL 2

Author Closing Comment

by:Winstink
Comment Utility
nothing could be run in normal mode, the trojan would not allow anything to run that could allow you find where the virus originates.  combofix found a trojan and removed it.
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Sub-Titled: “My Way” (with apologies to Francis Albert Sinatra) Let me start by stating emphatically that I am one of those Experts who prefer doing things “My Way”. It’s kind of a no-brainer. “The following procedure works for me, so here is …
It started not too long ago. It was at first annoying. My keystrokes seemed to be randomly generated, not the ones I typed on the keyboard. For some reason this only happened in certain applications (especially browsers such as IE11, Firefox and Chr…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now