Trojan.killAV-similar experiance?

Trojan.killAV-similar experiance?

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trojan.killAV-similar experiance? JT 09-18-2007
Posted by =?Utf-8?B?SlQ=?= on September 18, 2007, 12:48 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello all,
I've run into two different windows XP machines at 2 different clients now.
Norton picks it up as Trojan.KillAV. The files: info.exe, system.exe and
print.exe all show up in the system with this infection in the
%winnt%/system32 folder, the startup folder and the run reg keys for
HKEY_LOCAL_USER and HKEY_LOCAL_MACHINE. In addition you'll see a process
running called print.exe. Also, you get the following message when attempting
to access the properties of my computer, when trying to access control panel
or other system changing areas, either directly or via the RUN menu: "THIS
OPERATION HAS BEEN CANCELLED DUE TO RESTRICTIONS IN EFFECT ON THIS COMPUTER.
PLEASE CONTACT YOUR SYSTEM ADMINISTRATOR". The previous error message did not
relate to a local or group policy. Also, the control panel is no longer
visable. Oh, and some popups too. It's very resistant to removal and the most
i've been able to do is disable it by killing the files with a program and
replacing the infected files with dummy files and locking them. But I can
never repair the error message with accessing system changing areas. Has
anyone else had any luck with this?? perhaps been able to remove and repair?
Any advice or experiance with this would be helpful.

Sorry its so long! Thanks in advace.
Justin

Posted by Malke on September 18, 2007, 2:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
JT wrote:
> Hello all,
> I've run into two different windows XP machines at 2 different clients now.
> Norton picks it up as Trojan.KillAV. The files: info.exe, system.exe and
> print.exe all show up in the system with this infection in the
> %winnt%/system32 folder, the startup folder and the run reg keys for
> HKEY_LOCAL_USER and HKEY_LOCAL_MACHINE. In addition you'll see a process
> running called print.exe. Also, you get the following message when attempting
> to access the properties of my computer, when trying to access control panel
> or other system changing areas, either directly or via the RUN menu: "THIS
> OPERATION HAS BEEN CANCELLED DUE TO RESTRICTIONS IN EFFECT ON THIS COMPUTER.
> PLEASE CONTACT YOUR SYSTEM ADMINISTRATOR". The previous error message did not
> relate to a local or group policy. Also, the control panel is no longer
> visable. Oh, and some popups too. It's very resistant to removal and the most
> i've been able to do is disable it by killing the files with a program and
> replacing the infected files with dummy files and locking them. But I can
> never repair the error message with accessing system changing areas. Has
> anyone else had any luck with this?? perhaps been able to remove and repair?
> Any advice or experiance with this would be helpful.
>
> Sorry its so long! Thanks in advace.
> Justin

I haven't seen this on any of my clients' machines but there is a lot of
information about removing it available:

http://www.google.com/search?hl=en&q=Trojan.KillAV&btnG=Google+Search


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Similar ThreadsPosted
Trojan August 2, 2005, 8:42 pm
Trojan August 19, 2005, 6:31 pm
trojan by icq November 4, 2005, 6:40 am
Trojan November 7, 2005, 3:45 pm
trojan November 8, 2005, 3:46 pm
Trojan.moo December 18, 2005, 3:23 pm
Trojan! ? August 14, 2006, 9:52 pm
ssu.exe is it trojan ??? March 21, 2007, 5:49 pm
Possible trojan??? April 30, 2007, 12:40 pm
What is this Trojan August 3, 2007, 6:15 pm

The site map in XML format XML site map

Contact Us | Privacy Policy