HELP

I got a trojan, it disabled task manager, regedit, safe mode, and it shuts off avast everytime i try ti uninstall, install, open, close, ect, all it lets me do is scan, can someone tell me how to fix this? ive fixed everything else.

Thanks
-Dibiase

If you have XP, vista32bit or Win2k, you could enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, a memory scan will take place followed by the opening of the Simple User Interface, Menu, ‘Schedule boot-time scan…’ Or see http://www.digitalred.com/avast-boot-time.php.

How to restore Safe Boot.
The malware may have deleted the SafeBoot registry keys.
Here are some options to restore them:

http://didierstevens.wordpress.com/2006/06/26/restoring-safeboot/
http://didierstevens.wordpress.com/2007/02/19/restoring-safe-mode-with-a-reg-file/
Also see http://forum.avast.com/index.php?topic=26554.msg216924#msg216924

If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode and report the findings (it should product a log file).

  1. SUPERantispyware On-Demand only in free version.
  2. MalwareBytes Anti-Malware, On-Demand only in free version http://download.bleepingcomputer.com/malwarebytes/mbam-setup.exe, right click on the link and select Save As or Save File (As depending on your browser), save it to a location where you can find it easily later.

i have avast pro


Welcome to the forums, Dibiase. :slight_smile:

Please follow David’s advice above and let us know the results.


Some other tools as this could be using a rootkit to hide it.

Also see, anti-rootkit, detection, removal & protection http://www.antirootkit.com/software/index.htm. Try these as they are some of the more efficient and user friendly anti-rootkit tools.

they didnt work :frowning:

o forget it… no one knows my problem unless you see it(or have/had it)

Which didn’t work ?

Are you talking of the Didier Stevens links, or SAS or MBAM and can you expand a little on ‘they didn’t work,’ that gives us nothing to work with ?

I can’t believe that you have downloaded all of the anti-rootkit tools and run them in the 15 minutes or so since I posted them ?


Well, Dibiase … we do not give up so easily but if you do, then we can not help you.