I managed to pick up a nasty trojan this morning.
The symptoms were a quick change from a very stable computer with AVG antivirus running to one that took over and scanned the internet itself and then popped up a screen that advised me I had been attacked by some 60 different spywares and trojans. Then asking me to buy protection etc.
Well, I know better than that but I know I had been bitten by this virus. I looked up the notice (on another computer) since I yanked out the ethernet cable immediately. I also learned the hard way in the past not to shut the computer down. The extortionist was "Antivirus System Pro" However, the google search was not helping since none of the remedies were giving me any useful fixes. There was a clue that did turn up on one forum. The file sysguard.exe showed up in my task mgr processes. and would sync with the activity on screen. But the file name was a bit different. It was "jetsysguard.exe and was located in the windows system folder. There was no other software added in Programs files as indicated for that extortionware listed in the google references. There was no jetsysguard.exe in google search. So I shut down the process in task manager and voila! the activity on my desktop ended. I deleted the file and then found it hidden in a new folder in Programs called "htopfl"
Finally, I found a key in the registry that referenced the file in the run section and deleted that.
Excitement is over now and time to get some sleep!
The symptoms were a quick change from a very stable computer with AVG antivirus running to one that took over and scanned the internet itself and then popped up a screen that advised me I had been attacked by some 60 different spywares and trojans. Then asking me to buy protection etc.
Well, I know better than that but I know I had been bitten by this virus. I looked up the notice (on another computer) since I yanked out the ethernet cable immediately. I also learned the hard way in the past not to shut the computer down. The extortionist was "Antivirus System Pro" However, the google search was not helping since none of the remedies were giving me any useful fixes. There was a clue that did turn up on one forum. The file sysguard.exe showed up in my task mgr processes. and would sync with the activity on screen. But the file name was a bit different. It was "jetsysguard.exe and was located in the windows system folder. There was no other software added in Programs files as indicated for that extortionware listed in the google references. There was no jetsysguard.exe in google search. So I shut down the process in task manager and voila! the activity on my desktop ended. I deleted the file and then found it hidden in a new folder in Programs called "htopfl"
Finally, I found a key in the registry that referenced the file in the run section and deleted that.
Excitement is over now and time to get some sleep!