Computer Security & Viruses/fake security alert trojan
Expert: Lorry - 1/20/2009
QuestionHi Lorry,
I have this fake security alert popping up every 5 minute
on my screen. I was browsing web and it appeared first,
saying there is virus called Zafi.f trojan(not sure of
exact name but something in that order) in your system
which records key strokes and make copy of your personal
info. It's format was very similar to windows notification.
It had title Windows security center. I foolishly clicked
on it and it had gradually disabled all my
browser(Firefox,IE can't open any), run, control panel
everything which will help me remove it. I ran windows malicious software(when browser was running), Mcafee 2008
full scan and windows defender but any of it did not detect it. One thing though Mcafee keeps poping up message fake alert detected and removed but I guess it keeps reinstalling it. I am considering formatting my computer. I
am really scared if it does not go away even by format what would I do then? And I have copied drivers and some data
from my hard drive, I am afraid what if that Trojan has
attached itself to one of those copied files.I can't afford
to loose data from my hard drive. My laptop is Dell vostro
and operating system is Windows XP. Please help.
Thank you
AnswerHi Neena,
Win32/Zafi.F is known as W32.Erkez.G@mm with Symantec. The following site explains how to remove the threat:
http://www.symantec.com/security_response/writeup.jsp?docid=2005-100616-4203-99&...
After removing the threat, using internet Explorer and run the free scan from Symantec to verify that the threat is gone. Once you know for sure, enable System Restore.
http://security.symantec.com/sscv6/WelcomePage.asp
Click "Continue to Symantec Security Check", in the next window click No when asked if you want to close this window, that will bring you to a window where you should click Virus Detection.
Write down exactly anything it finds, then go to:
http://www.symantec.com/search/ and do a search for what was found. Symantec usually has a removal tool and/or directions for removing manually. Make sure that you follow the instructions for removal, step by step, especially the part regarding disabling System Restore.
Hope this helps!
Lorry