We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help Please! Trojan backdoor.win32.MSNMaker.ab

Options
Have got this Trojan but don't know how to shift it.

DD clicked a link in a MSN window and it started spamming her contacts.

Windows defender keeps finding: toolbar888 and CheckSpring.PuritySCAN.Downloader

AVG virus vault has Trojan Horse Collected AF

While connected to the Internet there is a pop up window opening titled: C:\DOCUME~1\USER\usetup.exe

System is connected via a router.

Running win xp sp2
AVG 7.5
zonealarm
spywareblaster
spybot SD
AdAware SE
Ewido 3.5
CCleaner

Any help appreciated
I have a cunning plan!
Proud to be dealing with my debts.

Comments

  • Try wiping temp files with ccleaner, then run a scan with all your scanners in safe mode (F8 at startup), after making sure they are upto date. If anything is found in your system restore area, turn it off and back on again to clear it.

    You might also want to try these scanners:

    http://www.clamwin.com/

    http://www.bitdefender.com/PRODUCT-14-en--BitDefender-8-Free-Edition.html

    for a bit of belt and braces.. (download them, update them, drop into safe mode and scan with them).

    Don't attempt to launch messenger until all scans are negative. Check to see if c:\windows\system32\drivers\etc\hosts has any suspicious entries, and it may also have disabled the firewall, or added itself as an allowed application. If using zonealarm, delete all allowed applications from the list.
    Ever get the feeling you are wasting your time? :rolleyes:
  • So AVG has the trojan in it's vault be you're still getting the symptoms you describe? Are you using a different machine to the infected one cos you really shouldn't be on the net if you've got this thing on your computer? Do you have a firewall running as well in which case you might be ok staying on the net to try and fix it?

    First thing i would try is to do a complete virus scan using AVG and seeing if it comes up with more infected files. There isn't a log on the net about this particular trojan unfortunately, but it sounds as though one of the things it's doing is trying to trick you into deleting usetup.exe, as far as i can tell that is a system file, so don't delete it, first see what AVG has to say when you do the really long complete deep virus scan.
    :j Ready to take control of my life! :j
  • sorry albertross, didn't see your post cos i was writing mine at the time!
    :j Ready to take control of my life! :j
  • Don't apologise, I'm sure all help is welcome..
    Ever get the feeling you are wasting your time? :rolleyes:
  • So AVG has the trojan in it's vault be you're still getting the symptoms you describe? Are you using a different machine to the infected one cos you really shouldn't be on the net if you've got this thing on your computer? Do you have a firewall running as well in which case you might be ok staying on the net to try and fix it.

    Posting from my laptop. zonealarm software firewall and hard firewall in router.

    Looks like 2 trojans 1 trojan horse collected AF in avg virus vault. scan not showing other one.

    backdoor.win32.msnmaker.ab was found with online scanner version of Kaspersky

    Running ewido as we speak
    I have a cunning plan!
    Proud to be dealing with my debts.

  • Ewido turned up nothing.

    Now running AVG in safe mode.
    I have a cunning plan!
    Proud to be dealing with my debts.

  • skiddy2k
    skiddy2k Posts: 1,627 Forumite
    Didnt Kaspersky online scanner tell you where the file was located? find the file and remove it manually.
    Or
    you can temporarily uninstall AVG and download Kaspersky trial version: http://www.kaspersky.com/uk/trials... once you deleted all the malware on your PC, delete Kaspersky and re-install AVG
    OR
    you can uninstall AVG and use AOL Active Virus Shield http://www.activevirusshield.com/ which uses Kaspersky's signatures and is also 100% free

    Personaly, I'll opt for the last option... leave AVG and use AVS... up to you still.
  • Ewido turned up nothing.

    Now running AVG in safe mode.

    Avg scan missed it and only scan error was it didn't read boot partition.
    I have a cunning plan!
    Proud to be dealing with my debts.

  • Touch wood I seem to have sorted it. Following the instructions HERE.

    I had to delete Ewido and reinstall the rebranded AVG anti-spyware or whatever they call it now. Found 6 trojans that the earlier Ewido 3.5 missed.

    Also had to manually delete a couple of files, but seems ok.
    I have a cunning plan!
    Proud to be dealing with my debts.

This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 599K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.