Results 1 to 6 of 6

Thread: Trojan-Ransom.Win32.SMSer.qm is displaying Russian Messages

  1. #1
    Join Date
    Nov 2009
    Posts
    75

    Trojan-Ransom.Win32.SMSer.qm is displaying Russian Messages

    My computer is hacked by the Trojan-Ransom.Win32.SMSer.qm as detected by the Kaspersky anti virus. Though the Kaspersky anti virus detected and deleted the Trojan but still the was a message displayed which I recently discovered is in Russian language. It states that the Network connections is disabled and to restore Internet usage I have to send a SMS with the displayed Unlock code. How to deal with this?

  2. #2
    Join Date
    May 2008
    Posts
    3,516

    Windows Firewall

    It can be that there is a remote attacker accessing your computer that was infected by the trojan detected as Trojan-Ransom.Win32.SMSer.qm. Probably the attacker is getting access to your machine as the there is no Firewall installed or the Firewall is disabled. You can enable the Firewall in Windows 7 as follows:
    1. Go to the Search box by opening the Start Menu.
    2. Enter firewall in the search box to get the Firewall settings section.
    3. Open the Windows Firewall by clicking on it.
    4. Browse to Turn Windows Firewall on or off and click on it.
    5. Select the Block all incoming connections to block everything to safeguard your machine.

  3. #3
    Join Date
    Apr 2008
    Posts
    3,339

    Safe Scan in Safe Mode

    I suggest you to run a safe scan with your Kaspersky anti virus in the Safe mode of Windows. It looks from your description that the Trojan is not actually removed but is actually hiding itself because if the Trojan was removed then the message should not be displayed. Verify the presence of the Trojan by re-booting your computer and tapping the F8 key to enter your computer in Safe mode and then Scan.

  4. #4
    Join Date
    May 2008
    Posts
    2,945

    Re: Trojan-Ransom.Win32.SMSer.qm is displaying Russian Messages

    The Trojan-Ransom.Win32.SMSer.qm attacks on the network device of the installed system. It intends to disable the network device. After succeeding in its attack it then outputs alert messages that are in Russian language and asking the user to send the unlock code through SMS to the given contact in the message. Thus, the user of the infected system is expected to no internet connectivity or for worst can even have the Denial of Services Attack.

  5. #5
    Join Date
    Apr 2008
    Posts
    3,424

    Use Avast Anti virus to run a Boot Scan

    My recommendation is that you install Avast Anti virus. The Kaspersky anti virus seems not efficient and secure as it cannot detect and delete the malicious content completely. The Boot Time Scan of Avast is very vital feature that schedules a boot-time scan to detect and take care of any malicious content before even the operating system is loaded.

  6. #6
    Join Date
    Jan 2006
    Posts
    4,221

    Reinstall Operating System

    The trojan has made way to your Windows Registry. This will enable the trojan to be executed every time the system is booted. Thus even if the trojan gets deleted, it will re-occur on rebooting. In such circumstances it would be beneficial that you make a backup of the required data and re-install Windows by formatting the Windows drive.

Similar Threads

  1. How to remove Trojan: win32/fakesysdef and trojan@winnt/alureon.s.
    By Barnard in forum Networking & Security
    Replies: 8
    Last Post: 28-08-2011, 09:50 AM
  2. Replies: 4
    Last Post: 26-06-2011, 10:35 PM
  3. Replies: 3
    Last Post: 13-07-2010, 04:49 PM
  4. W32/DNSChanger.FUBV trojan displaying unknown websites
    By Jarini in forum Networking & Security
    Replies: 5
    Last Post: 22-01-2010, 10:53 PM
  5. TrojanClicker:Win32/Vbadult.A displaying absurd popups
    By KAMANA in forum Networking & Security
    Replies: 3
    Last Post: 10-12-2009, 01:10 AM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,752,103,184.13809 seconds with 16 queries