View Full Version : Avast Detected Trojan And Its Not Letting Me Open My IE Browser
sooflymami
December 14th, 2008, 07:29 PM
A while ago, I clicked on the IE icon on my desktop and went to check my messages on Myspace. And then all the sudden, Avast popped up on my screen saying that the virus has been detected and it was a Trojan one that said worm/malware I believe. I want to open my browser on IE again, but when I click on the IE icon on my desktop, it opens for like 1 second and then it disappears..I tried doing that many times and it did that. I also saw my bar (That bar place that has the Start button and the clock and all those icons) disappear as well few times after that. And When avast detected a trojan that said worm/malware, I clicked "Move To Chest Button". What should I do? I'm doing a boot scan right now.
cheater87
December 14th, 2008, 09:54 PM
Hello I'm on the phone with Soofly right now and the Avast Boot scan finished. Now its been 10 minutes and the screen is still black. We tried shutting down with the power button but the screen is still black and nothing comes up. The courser can still be seen but the screen is black and we can't click on anything or do anything. What is the problem???
noway
December 14th, 2008, 10:59 PM
Have you tried booting into Safe Mode?
http://www.computerhope.com/issues/chsafe.htm#02
sooflymami
December 14th, 2008, 11:15 PM
I'm on my other computer right now since it's not letting me go on the other one and when I did the boot scan, nothing detected..but I did see a name of a certain file saying avast.boot something as a reported file. Other than that, no infections was found. What should I do? I still think it's some virus or spyware that's affecting my computer because after that trojan virus has been detected and moved it to the chest, it has been acting very strange and it wont let me go into the windows starting up thing..I don't even know why it's still acting strange even though it's in the chest now. Was I supposed to delete instead of move it to the chest? What can I do in order to fix this problem?
djohn
December 14th, 2008, 11:40 PM
You can try this. http://freedrweb.com make a live CD rescue and burn the ISO,Follow instruction it may or may not help.
sooflymami
December 14th, 2008, 11:55 PM
-{ Quote: "Have you tried booting into Safe Mode?
http://www.computerhope.com/issues/chsafe.htm#02" }-
Haven't tried that yet..would it let me update definitions on SuperAntiSpyware by going under Safe Mode and then scan with that program?
And does anyone know if that certain virus thats inside the chest is causing these issues or if its something else?
Pseudo
December 15th, 2008, 12:42 AM
-{ Quote: "Haven't tried that yet..would it let me update definitions on SuperAntiSpyware by going under Safe Mode and then scan with that program?
And does anyone know if that certain virus thats inside the chest is causing these issues or if its something else?" }-
Boot Windows into Safe Mode with networking if you wish to update any programs or access the Internet.
cheater87
December 15th, 2008, 02:58 AM
Soofly wants to know if the virus she moved to the chest could be causing the black screen.
Tarq57
December 15th, 2008, 04:55 AM
Virus inside the chest causing the black screen? Absolutely not. Not in the sense she means, anyway.
Once something is in the chest, it cannot run.
That doesn't exclude the possibility of other malware being on the computer, though, run SAS or MBAM as suggested above (safe mode with networking.)
Can you post the full path and name of the infected file, please, and also the name of it as it appears in the "infected files" section of the chest.
Myspace is notorious for malware. A lot of the social networking sites are, unfortunately. I've had a look at your intro page, and (of course) can not get further than that, but there was no sign of malware on it. Just some pretty pictures, and a few gifs.
Had you opened any of the messages when the warning first popped up? Logged in? Just where were you up to?
GideonD
December 15th, 2008, 06:58 AM
I got a message this morning about ils.dll, which I think it netmeeting related, being a rootkit and after this Avast prompts for a boot scan. I ignored it for now and did not do the scan as I'm fairly certain this is a false positive. I submitted the file to Avast and I'll wait until the next update before I do a system scan.
GES/POR
December 15th, 2008, 07:05 AM
Wasnt it some critical system file that got quarantined wich causeing the malfunction?
Niels
December 15th, 2008, 08:20 AM
Did you already tried starting Internet Explorer without add-ons? To do that right click on the Internet Explorer(IE) icon click on no add-ons. It could be that Avast is denying that an iexplore.exe to run an add-on and that could be the reason why Internet Explorer will not load.
Did you already removed the installation disk of Avast or the bootable disk that you created to scan? See if you now are able to boot. Try this also keep pressing the left shift button after you saw the BIOS screen this will only load necessary drivers.
The behavior of the disappearing taskbar is related to explorer.exe. Does it happen very frequently? If so you can try this (http://www.ehow.com/how_4592369_problem-windows-xp-taskbar-disappears.html).
What file was being quarantined? It might be a critical windows file or file that is needed so that IE can work without problems.
Tarq57
December 15th, 2008, 03:38 PM
-{ Quote: "I got a message this morning about ils.dll, which I think it netmeeting related, being a rootkit and after this Avast prompts for a boot scan. I ignored it for now and did not do the scan as I'm fairly certain this is a false positive. I submitted the file to Avast and I'll wait until the next update before I do a system scan." }-
I received the same message after start this morning (about 15min ago.)
Have located the file in two places; system 32 and i386 service packs.
Also pretty sure this is a FP.
Possibly related to the OP.
Sooflymami
run a search for "ils.dll" (no quotes) and let us know if this file is present in your system 32.
Tarq57
December 15th, 2008, 03:47 PM
Big thread running about ils.dll here. (http://forum.avast.com/index.php?topic=40975.0)
cheater87
December 15th, 2008, 06:18 PM
We can't get into safe mode either. The black screen stops us yet again. :(
Tarq57
December 15th, 2008, 06:41 PM
Have a look at this. (http://support.microsoft.com/KB/314503)
If you're fortunate, it's cause (1).
(Hope you have install media - ie: a Windows disk - if it's cause 2.)
Given the number of issues she has had with this computer posted about at Wilders, with several of them seeming to be unresolved (or at least, not posted as resolved, the threads just seem to peter out...) it may be time to look at a format and re-install. (You'd loose everything, except Windows, of course. Passwords, ISP configuration, programs etc., basically, anything that isn't part of Windows.)
If you were to select this course of action, it would be worth trying to boot off the Windows disk first, and if the thing works, immediately backup all valuable files,favorites, and write down any passwords used for forums, Myspace etc. You can Google for tutorials on re-formatting.
(A repair install of Windows might work.)
Then it would be beneficial to have stuff you want to load on the fresh install on a flash drive. Like the AV install file, and SP3, which, despite your reservations, I've had no issues with, and it would save you maybe half an hour or more of Windows updates. (One of the updates offered will be SP3 anyway.)
cheater87
December 15th, 2008, 06:50 PM
I'll burn her the Dr Web CD and boot off of that. :) I hope that helps.
Tarq57
December 15th, 2008, 06:53 PM
I really think the problem is (at least partly) that a required Windows file (or more than one) has been removed or quarantined. It could be malware, but there are a lot of FP's reported at the Avast forum in the last day or so. If she has quarantined system files, and you can get into the chest using the DrWeb CD (sorry, I don't know what this does - never had to use one) you might be able to restore the files and get things working.
sooflymami
December 15th, 2008, 07:53 PM
-{ Quote: "Virus inside the chest causing the black screen? Absolutely not. Not in the sense she means, anyway.
Once something is in the chest, it cannot run.
That doesn't exclude the possibility of other malware being on the computer, though, run SAS or MBAM as suggested above (safe mode with networking.)
Can you post the full path and name of the infected file, please, and also the name of it as it appears in the "infected files" section of the chest.
Myspace is notorious for malware. A lot of the social networking sites are, unfortunately. I've had a look at your intro page, and (of course) can not get further than that, but there was no sign of malware on it. Just some pretty pictures, and a few gifs.
Had you opened any of the messages when the warning first popped up? Logged in? Just where were you up to?" }-
Yes, I was already logged in when it said virus has been detected. I opened messages from my friends and then after I opened one of my friends messages, thats when it said "virus has been detected"...it didn't have any links when I opened the messages though. I'm thinking maybe it was Myspace Advertisements loaded a virus on my computer. And I meant if that same virus that I moved it to the chest was causing my computer to not take me to the windows start up screen and other strange stuff that's been doing since I got a virus.
Tarq57
December 15th, 2008, 07:59 PM
Sooflymami, how long had the computer been running when you got the detection message, and do you remember the name of the file or virus it reported? And which Avast module reported it?
(Always a good idea to jot those down. Makes troubleshooting easier.)
Maybe the message contained an infection. Or maybe, if it was not long ofter the computer start, the avast antirootkit detected something incorrectly. If you look at the avast forum, you'll see there have been a large nr. of FP's with that over the past day.
cheater87
December 16th, 2008, 03:02 AM
We don't know what shield detected it unfortunately.
Tarq57
December 16th, 2008, 04:19 AM
And how long had since startup when the warning came up?
And do you remember anything about the name of the infection?
If you don't know the answers to any questions anybody asks, just say so.
(Don't make me keep posting the questions.)
Any luck with the Avira disk? Tried that yet?
Got a Windows CD?
Niels
December 16th, 2008, 09:01 AM
Did you already tried what I suggested? Because you didn't answered if it worked or not. My second reply should apply to try to get past the black screen. Do you see anything on the screen? Did you checked that all the cables are still connected into the monitor?
djohn
December 16th, 2008, 09:15 PM
I am also curious to the conclusion of this thread.
sooflymami
December 16th, 2008, 09:35 PM
-{ Quote: "And how long had since startup when the warning came up?
And do you remember anything about the name of the infection?
If you don't know the answers to any questions anybody asks, just say so.
(Don't make me keep posting the questions.)
Any luck with the Avira disk? Tried that yet?
Got a Windows CD?" }-
like 10mins. i think because i turned on my computer to check my messages and then that happened. and no i dont remember the name of the file..all i know is it said trojan worm/virus.
Tarq57
December 16th, 2008, 09:39 PM
Hey, Gemini lady, and the answers to the other questions might be.....
sooflymami
December 16th, 2008, 09:41 PM
-{ Quote: "Did you already tried what I suggested? Because you didn't answered if it worked or not. My second reply should apply to try to get past the black screen. Do you see anything on the screen? Did you checked that all the cables are still connected into the monitor?" }-
I didn't really understand what you meant on the post and its not even letting me go on the main screen. Yes, all the cables are connected into the monitor.
Niels
December 17th, 2008, 05:48 AM
This might be because of my English. I will try if I can be more specific.
Do you see any text on your monitor when you start your computer? If that is the case keep pressing on the left shift button on your keyboard after you see the first text appear. That key (shift button) is located above the ctrl (left control button) button on your keyboard.
Did you also verified if the cable of your monitor is also attached to your computer case at the backside?
I just saw that you don't need a cd-rom of Avast to be able to perform a boot scan so my solution wouldn't help. Sorry about that.
If nothing is visible on your monitor it might be your video card. Try this shutdown your computer and unplug the powercable of your computer now open your system case and see if you find any dust clean it with a soft cloth. Be sure that the videocard is being attached in the slots. See if you now still see the black screen.
GES/POR
December 17th, 2008, 11:04 AM
In adittion to Niels, Have you paid your electric bills? All kidding aside, you got some good suggestions there - Op stay with him
sooflymami
January 14th, 2009, 11:16 PM
A computer repairman finally fixed it! Do you think I should get the ad-block for internet explore? would that be safer?
firzen771
January 14th, 2009, 11:21 PM
-{ Quote: "A computer repairman finally fixed it! Do you think I should get the ad-block for internet explore? would that be safer?" }-
what wuld be safer is to just use firefox and use the addblock add-on. i dont understand why people are still using IE...
Malcontent
January 15th, 2009, 01:15 AM
-{ Quote: "what wuld be safer is to just use firefox and use the addblock add-on. i dont understand why people are still using IE..." }-
The "NoScript" add-on would be helpful also.
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums