Computers and Technology A general forum for discussions about computers, technology, and the Internet. If you just want to "geek out" or talk about how computers tick, then this is the place!


advertisement
Reply
 
Thread Tools Display Modes
Old 07-08-2015, 02:15 AM #1
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
Default S.O.S. Trojan virus or 'False Positive'?

Hi All

Bit panicky here - will try and keep it short.
Laptop with Windows 7, Running AVG free version as main scheduled antivirus with Malwarebytes as alternative. Last 3 days AVG has started reporting IRP Hook Rootkit Trojan (9 entries). Run removal each time but next day same IRP Hook files reappear.

Have searched online etc for how to fix. Come up with varying info: either these are false positives generated by AVG or a problem with driver, or a really nasty, potentially system destroying Trojan. If latter the fixes are very complex and don't always seem successful and how do you trust that those suggesting the fixes are above board.

So thought I'd ask here as you folk haven't steered me wrong yet. So if any one has any recommendations of sites they know can be trusted or suggestions it would be appreciated.

I know I could take it to repair shop but just 3 wks ago I took it in because it was slow on start-up - they said it was an unrepairable corrupt hard drive - new hard drive was $275.00. They cloned my old hard drive on to the new one - now I'm beginning to wonder if the Trojan was hidden on the old hard drive & causing the problem. Only other thing I changed was removed AVG 2014 and downloaded the 2015 version shortly before this started happening.

I'm too scared to even start up my laptop at the moment until I can either find a fix or figure out if this is an AVG bug. (Fired up a second-hand I-pad to do this).

Thanks for reading.
bluesfan is offline   Reply With QuoteReply With Quote

advertisement
Old 07-08-2015, 02:55 AM #2
Lara Lara is offline
Legendary
 
Join Date: Sep 2006
Posts: 10,984
15 yr Member
Lara Lara is offline
Legendary
 
Join Date: Sep 2006
Posts: 10,984
15 yr Member
Default

Have you tried scanning in safe mode with malwarebytes?

There were a lot of places on google search but some were difficult to follow and complicated.

This one seemed more straightforward.

http://www.im-infected.com/trojan/ir...it-trojan.html
Lara is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
bluesfan (07-08-2015)
Old 07-08-2015, 03:00 AM #3
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
Default

Hi Lara
Thanks for getting back so quick. Malwarebytes doesn't detect it - as many of the others who had the same problem found. I'll try that link you provided then I think I'll leave it for tonite - bit of a mental overload right now.

Have a good evening.
bluesfan is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
Lara (07-08-2015)
Old 07-08-2015, 03:02 AM #4
Lara Lara is offline
Legendary
 
Join Date: Sep 2006
Posts: 10,984
15 yr Member
Lara Lara is offline
Legendary
 
Join Date: Sep 2006
Posts: 10,984
15 yr Member
Default

I looked for a while before posting.
I'm on a mac these days so have forgotten a lot of what to do I'm sorry.

If I find anything less complicated I'll post it.

take care there. Must be cold too.
Lara is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
bluesfan (07-08-2015)
Old 07-08-2015, 03:09 AM #5
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
Default

Just read that link Lara. It's much clearer than most of the others I found and I do recognise some of the names there eg Symantec. Will bookmark it and try it tomorrow.

Thanks for finding it - I'll sleep easier tonite.
bluesfan is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
Lara (07-08-2015)
Old 07-08-2015, 03:10 AM #6
Lara Lara is offline
Legendary
 
Join Date: Sep 2006
Posts: 10,984
15 yr Member
Lara Lara is offline
Legendary
 
Join Date: Sep 2006
Posts: 10,984
15 yr Member
Default

Sleep well. By tomorrow someone else may have some ideas as well.
talk later
Lara is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
bluesfan (07-08-2015)
Old 07-08-2015, 04:32 AM #7
kiwi33's Avatar
kiwi33 kiwi33 is offline
Grand Magnate
 
Join Date: Jan 2015
Location: Sydney, Australia.
Posts: 3,093
8 yr Member
kiwi33 kiwi33 is offline
Grand Magnate
kiwi33's Avatar
 
Join Date: Jan 2015
Location: Sydney, Australia.
Posts: 3,093
8 yr Member
Default

Hi bluesfan

Adding to the link which Lara provided (which looks good to me) this one might also help in zapping the Trojan; http://www.antivirusgateway.com/how-...emoval-guides/ .
__________________
Knowledge is power.
kiwi33 is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
bluesfan (07-08-2015), Lara (07-08-2015), mrsD (07-08-2015)
Old 07-08-2015, 10:54 AM #8
Jomar's Avatar
Jomar Jomar is offline
Co-Administrator
Community Support Team
 
Join Date: Aug 2006
Posts: 27,685
15 yr Member
Jomar Jomar is offline
Co-Administrator
Community Support Team
Jomar's Avatar
 
Join Date: Aug 2006
Posts: 27,685
15 yr Member
Default

A LOT of the search results I found are marked as not safe by WOT.. (web of trust)
I would only get programs from well known anti virus sites in this case..

Have you tried Hijack this?
http://sourceforge.net/projects/hjt/
how to use it-
http://www.wikihow.com/Use-HiJackThis
http://www.bleepingcomputer.com/tuto...se-hijackthis/

other free tools-
http://free.antivirus.com/us/#cleanup-and-prevention
http://usa.kaspersky.com/downloads/TDSSKiller
__________________
Search NT -
.
Jomar is offline   Reply With QuoteReply With Quote
"Thanks for this!" says:
bluesfan (07-08-2015)
Old 07-08-2015, 01:55 PM #9
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
Default

Quote:
Originally Posted by kiwi33 View Post
Hi bluesfan

Adding to the link which Lara provided (which looks good to me) this one might also help in zapping the Trojan; http://www.antivirusgateway.com/how-...emoval-guides/ .
Thanks for this kiwi33 - read through it and although for a non geek like me it's quite complicated I think I may be able to follow it.
bluesfan is offline   Reply With QuoteReply With Quote
Old 07-08-2015, 02:05 PM #10
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
bluesfan bluesfan is offline
Member
 
Join Date: Jun 2014
Posts: 733
8 yr Member
Default

Thanks Jo*mar
Is WOT a program I can download onto my laptop - does it review sites before they're downloaded?
Thanks for the other sites - I had read some of the Bleeping Computer forum & info. I'll look at the various options later today and figure out which of them might be manageable for me to attempt.

It's times like these I get really frustrated with computer manufacturers. They've well & truly forgotten the K.I.S.S principle when it comes to making computers for non-technical customers.
bluesfan is offline   Reply With QuoteReply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
False-Positive Urinalyisis snafu Chronic Pain 8 04-21-2011 12:41 PM
Did you know Protonix can cause THC false positive urine? Dejibo The Stumble Inn 4 08-05-2010 12:58 PM
False positive drug test Floridagal Parkinson's Disease 2 05-29-2009 01:00 AM
False positive anti-tTG in primary biliary cirrhosis jccgf Gluten Sensitivity / Celiac Disease 0 09-09-2006 07:21 PM


All times are GMT -5. The time now is 02:36 AM.

Powered by vBulletin • Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.

vBulletin Optimisation provided by vB Optimise v2.7.1 (Lite) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
 

NeuroTalk Forums

Helping support those with neurological and related conditions.

 

The material on this site is for informational purposes only,
and is not a substitute for medical advice, diagnosis or treatment
provided by a qualified health care provider.


Always consult your doctor before trying anything you read here.