GrpConv Trojan

0
You helped me a good deal but I still have a problem with some program that is modifying windows, anti-spyware, repair and malware programs so they either cannot update or so I cannot be run or cannot 'see' the changes made to them. 

After 6 days I finally found that I have the GrpConv Trojan - Nothing I could find to download found it except when I opened SpyBot's Startup Tools and found two entries in Autorun - one was blank (no name) and one was grpconv -o - and I researched what they are.

Now I have a backup, cleanup and reinstall problem to solve so I do not reinfect the windows system again (so far the trojan has deleted over 150 system files (I ran - Registrar Registry Manager - a very interesting and useful program to find what OS files were missing). Any ideas or links to finish the cleaning would be appreciated so I can run off 'Safe Mode'.

As soon as I removed the two entries, Spybot Tools was modified so that feature no longer works.


Share
Asked Jun 17 '14 at 21:41
Add a comment

4 Answers

 
0
I strongly recommend using the free kaspersky rescue cd. Alternatively, if all is lost, boot in on a linux or any unix-shell os from a removal media system ie, cd, dvd, usb etc and back up all the important files that You want to keep onto another or the same removal media system. After that, best thing is to reinstall the OS. You can download a trial version of windows and use the sticker code on You machine to activate this version of windows.

I hope this helps, please keep me posted.

Going by the results from AV comparatives, give avira a try.
Share
Answered Jun 19 '14 at 19:30
Add a comment
 
 
0
Run system in safe mode, and run full scan with HerdProtect and MBAM. Report back.
Share
Answered Jul 8 '14 at 3:23
Add a comment
 
 
0
Run system in safe mode, and run full scan with HerdProtect and MBAM. Report back.
Share
Answered Jul 8 '14 at 3:23
Add a comment
 
 
0
I say you need malwearbytes if it does not run get this program to boot it up!: http://downloads.malwarebytes.org/file/chameleon
Share
Answered Oct 1 '14 at 12:22
Add a comment

Know someone who can answer? Share a link to this question via email, Google+, Twitter, or Facebook.

Your Answer

Not the answer you're looking for? Ask your own question.