The Mudcat Café TM
Thread #117375   Message #2527539
Posted By: Bernard
30-Dec-08 - 12:41 PM
Thread Name: Tech: Trojan infection
Subject: Tech: Trojan infection
Two of my PCs have been hit by an as yet unidentified trojan infection, which seems to be similar to Zlob, but not as intense. So far I've not lost any Start Menu icons or suchlike...!

So far the only symptoms are denial of some network connectivity, and odd Internet behaviour, part of which was down to the cookie setup being messed up.

The main inconvenience is denial of access to my Network Attached Storage - the dirves can be seen, but report as 'not formatted' if I try to access them. They are fine, because my other machines can still access them normally.

One infected machine is running XP Home SP3, the other XP Pro SP3, and both have AVG v8 and Windows Defender installed. Since the trojan arrived, neither can connect to its server to update, and Windows Update diverts to the MSN homepage. Google behaves strangely, too - if I click on a search link it goes anywhere but where the link says it should, but if I copy and paste the link into the address bar it takes me to the correct page...!

Occasional pop-up adverts are appearing, but not to nuisance level yet.

If I reboot into Safe Mode and try to use System Restore, everything seems normal until I press the 'next' button to initiate the chosen restore point. The button simply does not do anything!

There do not seem to be any abnormal services running, and HiJackThis v1.99 hasn't found anything out of the ordinary.

Clearly this trojan is quite cleverly cloaked, and I've turned off all other PCs on my network until I can get to the bottom of it, as this thing may propagate itself through the rest of my system.

I do have Webroot's SpySweeper (up-to-date licence), which I'd had trouble with and unistalled a few months back. If I try to install that on the XP Home machine it causes a cold reboot about 90% into the install, and on the XP Pro machine it gives a fatal error message after about 60%, but doesn't cause a reboot.

This happens whether I install normally or in Safe Mode...

A few web searches come up with little or no information, other than the usual registry fixes for some of the symptoms - which are all very well, but not applicable in this instance.

Sooooo... has anyone any suggestions I may not have already tried?