Windows Infected with SHeur3.AQRA trojan (AKA Joe's PC is broken again)

Discussion in 'Tech Support' started by CardJoe, 29 Sep 2010.

  1. CardJoe

    CardJoe Freelance Journalist

    Joined:
    3 Apr 2007
    Posts:
    11,346
    Likes Received:
    312
    So, my girlfriend had a bunch of Virus warnings tonight, thrown up by AVG free. It claims she's heavily infected with a trojan called SHeur3.AQRA, along with Generic.VBS scripts.

    I'm having trouble finding information on this scourge, but obviously we want it gone.

    So, does anyone have any bright ideas on how to fix this problem? I'm looking ideally for advice on how to remove the trojan and save the date, but failing that some comprehensive advice on how to nuke the thing from orbit. I don't want to reformat three times just to find it's been hiding somewhere, nor do I want to overlook any data it might have stolen.

    Basically, throw your suggestions and ideas at me and I'll reward whoever is the most helpful with a massive amount of rep and a custom avatar. If that means anything to you.
     
  2. Jedra

    Jedra Supermodel

    Joined:
    11 Sep 2010
    Posts:
    1,821
    Likes Received:
    44
  3. bulldogjeff

    bulldogjeff The modding head is firmly back on.

    Joined:
    2 Mar 2010
    Posts:
    8,403
    Likes Received:
    634
    Ah ha, to nuke this little blighter from orbit, what I usually do,especially with stubborn viruses is to pull the drive out and install it into another PC..Disconnect yourself from the Internet so it can't try and reload and what ever you do DO NOT click on the drive to explore it or do anything with it, just right click and do a virus scan on that drive and then run maleware bytes. By doing it this way your anti virus can access the windows files but the virus can't run because the windows it wants to run on is not running and it can't access the main PC because it needs to be installed directly into windows, unless it's buried deep in the root you can usually dig it out....Happy nuking:D
     
    Last edited: 29 Sep 2010
  4. Otis1337

    Otis1337 aka - Ripp3r

    Joined:
    28 Nov 2007
    Posts:
    4,623
    Likes Received:
    161
    if your willing to format..... nothing......NOTHING! gets past Boot n Nuke, google it, its free and used by US government such as MOD and FBI
     
  5. Phalanx

    Phalanx Needs more dragons and stuff.

    Joined:
    28 Apr 2010
    Posts:
    3,712
    Likes Received:
    156
    CardJoe, that virus is well known for being sorted out by a program called ComboFix. I've done it on a work PC before and it involves sorting out a script to use. Hang on...

    Edit: Here you go, Joe.
     
  6. CardJoe

    CardJoe Freelance Journalist

    Joined:
    3 Apr 2007
    Posts:
    11,346
    Likes Received:
    312
    From the looks of that thread though, I'd need to go through that whole palava of creating custom scripts and reports though, right?

    Might just nuke it.
     
  7. Phalanx

    Phalanx Needs more dragons and stuff.

    Joined:
    28 Apr 2010
    Posts:
    3,712
    Likes Received:
    156
    Hardly a palava. I'm sure a journalist (and Intergalactic Kingpin) like yourself is a dab hand with copy and paste :) It's all in that thread.
     
  8. capnPedro

    capnPedro Hacker. Maker. Engineer.

    Joined:
    11 Apr 2007
    Posts:
    4,381
    Likes Received:
    241
    Have you tried running Malwarebytes? It usually sorts most stuff out for me.
     
  9. Otis1337

    Otis1337 aka - Ripp3r

    Joined:
    28 Nov 2007
    Posts:
    4,623
    Likes Received:
    161
    nuke it into the 14th century, easiest option
     
  10. Mongwopman

    Mongwopman King Ding-a-ling!

    Joined:
    28 Sep 2010
    Posts:
    368
    Likes Received:
    9
    Malwarebytes is good, i recommend that along with superantispyware.
     
  11. TheBlackSwordsMan

    TheBlackSwordsMan Far over the misty mountains cold

    Joined:
    16 Aug 2009
    Posts:
    4,028
    Likes Received:
    435
    Why dont you try the oldschool HijackThis in safe mode ?
     

Share This Page