Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Can You Help Rescue my Laptop??

  • 03-07-2008 10:39pm
    #1
    Registered Users, Registered Users 2 Posts: 636 ✭✭✭


    I have a 6 day old Acer Extensa 5620Z with Norton Anti Virus installed and working.

    However, after 2 days, my IE7 slowed down and will not load any website pages. My Norton trial expired, and I installed Avast and it immediately found win32:trojano-1165, a trojan horse that dates back to 2006.

    After 2 evenings of working on it and scans of the latest version of several tools, I'm still unable to remove this, completely and my IE7 performance has not improved, thats when it actually works at all.

    Currently installed are both Avast Home, which will not update since yesterday, and SUPERAntiSpyware which is completely up to date yet picks up nothing.
    Spybot with updates dated 2nd July also finds nothing.
    System Restore is currently turned off as ALL restore points under my user profile were infected (and shoudl have been removed when I switched it off yesterday.

    I've used MConfig, RunAnalyzer and CCleaner to inspect the startup items and have currently blocked just 1 suspicious entry from an unknown supplier.

    Bottom line, it looks like I need to get rid of the startup entry BM299b28c0 which is calling run32dll.exe and references a file called "bcmbclaf.dll,s"

    Every time I delete this registry key from the currentversion\run key it gets recreated and using Spybot real time protection engine can see attempts to create this key every few seconds.

    Can you please help me? How do I get rid of the remains of this trojan?

    AND was it on the preload, an even bigger concern?

    and finally, thanks :D


Comments

  • Registered Users, Registered Users 2 Posts: 30,469 ✭✭✭✭Ghost Train


    6 days old?

    well you seem to know what you want to get rid of, so maybe try hijackthis

    also might be a good idea to try turn off system restore and work in safe mode


  • Registered Users, Registered Users 2 Posts: 636 ✭✭✭cute_cow


    eolhc wrote: »
    6 days old?

    well you seem to know what you want to get rid of, so maybe try hijackthis

    also might be a good idea to try turn off system restore and work in safe mode

    hey, thanks for the reply. I've turned off the system restore and working in safe mode is not an option.

    I will try hijackthis and see what happens, thanks again.


  • Registered Users, Registered Users 2 Posts: 86,729 ✭✭✭✭Overheal


    you should have your thread here moved over to Virus Removal: ActorSeeksJob will probably be so good as to lend you a hand removing this one surgically.


  • Registered Users, Registered Users 2 Posts: 4,565 ✭✭✭jaffa20


    only a few days old so reformat computer. you wont love anything massive or the 6 days. you should get the installation disk with the computer.
    then install firefox and avg free.


  • Registered Users, Registered Users 2 Posts: 86,729 ✭✭✭✭Overheal


    avg is a resource hog... I have to reccomend Avast Free Home edition myself.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 7 cabinit


    cute_cow wrote: »
    hey, thanks for the reply. I've turned off the system restore and working in safe mode is not an option.

    I will try hijackthis and see what happens, thanks again.

    If its only 6 days old, then maybe you should try formatting the hardrive, that should get rid of any problems, a bit extreme perhaps but you will never have to worry about it resurfacing again.


Advertisement