I got a trojan, it disabled task manager, regedit, safe mode, and it shuts off avast everytime i try ti uninstall, install, open, close, ect, all it lets me do is scan, can someone tell me how to fix this? ive fixed everything else.
Thanks
-Dibiase
I got a trojan, it disabled task manager, regedit, safe mode, and it shuts off avast everytime i try ti uninstall, install, open, close, ect, all it lets me do is scan, can someone tell me how to fix this? ive fixed everything else.
Thanks
-Dibiase
If you have XP, vista32bit or Win2k, you could enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, a memory scan will take place followed by the opening of the Simple User Interface, Menu, ‘Schedule boot-time scan…’ Or see http://www.digitalred.com/avast-boot-time.php.
How to restore Safe Boot.
The malware may have deleted the SafeBoot registry keys.
Here are some options to restore them:
http://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/
http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/
Also see http://forum.avast.com/index.php?topic=26554.msg216924#msg216924
If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).
i have avast pro
Welcome to the forums, Dibiase. ![]()
Please follow David’s advice above and let us know the results.
Some other tools as this could be using a rootkit to hide it.
Also see, anti-rootkit, detection, removal & protection http://www.antirootkit.com/software/index.htm. Try these as they are some of the more efficient and user friendly anti-rootkit tools.
they didnt work ![]()
o forget it… no one knows my problem unless you see it(or have/had it)
Which didn’t work ?
Are you talking of the Didier Stevens links, or SAS or MBAM and can you expand a little on ‘they didn’t work,’ that gives us nothing to work with ?
I can’t believe that you have downloaded all of the anti-rootkit tools and run them in the 15 minutes or so since I posted them ?
Well, Dibiase … we do not give up so easily but if you do, then we can not help you.