Solved

Trojan "Spyware protection, Designed to protect"

Posted on 2010-11-19
6
5,899 Views
Last Modified: 2013-12-09
I have a user who has contracted some sort of trojan.  Looks like it modifies defender.exe, and runs a program called "Spyware protection, Designed to protect" and gives the same garbage not letting me open just about anything, saying my computer is infected.  I've run malwarebytes anti-malware on it in safe mode, found something, removed it, but it is still there.  I even attached the HD to another computer and ran MBAM on the entire drive and nothing.  A system restore seems to have put a band-aid on the problem.  Symantec sees that defender is causing problems, but does not detect the virus.    any suggestions?
0
Comment
Question by:Winstink
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
6 Comments
 
LVL 5

Accepted Solution

by:
frostsystems earned 250 total points
ID: 34175449
From safe mode, run Hitman Pro and then run Combofix. Problem solved.

Hitman Pro is available from www.surfright.nl

Combofix is available from http://www.bleepingcomputer.com/combofix/how-to-use-combofix
0
 
LVL 26

Assisted Solution

by:Thomas Zucker-Scharff
Thomas Zucker-Scharff earned 250 total points
ID: 34175826
If your computer is now functioning properly make sure you delete all old restore points and create a new clean one:
http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Windows/XP/A_2209-Removing-protected-System-Restore-files-if-they-have-been-infected.html

BUT ONLY IF YOU HAVE A WORKING REBOOTABLE COMPUTER!

Check out the free version of this little tool, it may help:

http://www.iobit.com/ascdownload-promo.html
0
 
LVL 27

Expert Comment

by:Jonvee
ID: 34182193
For the record, both Malwarebytes & ComboFix should be run in normal mode where Malware are usually the most active.  You can run in safe mode at times when you're unable to reach normal mode.

There is a good 'disinfection guide' here, by rpggamergirl :
http://www.experts-exchange.com/Software/Internet_Email/Anti-Virus/A_1979-THINGS-YOU-NEED-TO-DO-WHEN-YOUR-PC-IS-INFECTED.html

If still unsuccessful, try running an Eset online scan, it has proved to have been effective when other scanners have failed:
http://www.eset.com/online-scanner
0
Instantly Create Instructional Tutorials

Contextual Guidance at the moment of need helps your employees adopt to new software or processes instantly. Boost knowledge retention and employee engagement step-by-step with one easy solution.

 
LVL 27

Expert Comment

by:Jonvee
ID: 34182200
You could also try temporarily uninstalling Defender, if not yet tried.   Then re-install Defender & fully update.
0
 
LVL 9

Expert Comment

by:faizbaig
ID: 34182203
Following option may resolve your issue..

-> Right click " Defender.exe" or " "Spyware protection" icon you see on the desktop..etc. and click on "Properties" and click on "Find target" tab and try deleting that ".exe" file via normal mode or safe mode.

&

-> Look for "defender.exe" or "Spyware protection" on startup list and unselect the box if you find one.

0
 
LVL 2

Author Closing Comment

by:Winstink
ID: 34182798
nothing could be run in normal mode, the trojan would not allow anything to run that could allow you find where the virus originates.  combofix found a trojan and removed it.
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Can I legally transfer my OEM version of Windows to another PC?  (AKA - Can I put a new systemboard in my OEM PC?) Few of us are both IT and legal experts but we all have our own views of Microsoft's licensing rules and how they apply.  There are…
Sometimes people don't understand why download speed shows differently for Windows than Linux.Specially, this article covers and shows the solution for throughput difference for Windows than a Linux machine. For this, I arranged a test scenario.I…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

710 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question