PDA

View Full Version : I seem to be under trojan attack



FMluvswater
07-26-2004, 05:08 PM
all day long AVG has been telling me I've got one trojan or another to the point I'm starting to recognise the file names :rolleyes: . I've run Ad Aware several times today and always get rid of any objects it finds. I've updated my AVG, my firewall is working, I haven't downloaded anything all day ... I'm getting a little annoyed at removing the same damn trojans over and over again. I've gone into Add/remove programs and removed one of the programs that wasn't even supposed to be there cuz I certainly didn't download it. I've located the trojan infected files and manually deleted them and emptied recycle bin. How can I block the damn thing from coming back? Anybody have any suggestions? Thanks.

gramps
07-26-2004, 05:17 PM
I have the same problem with someone sending me the same virus 2 and 3 times a day. Norton keeps catchin' it but is still is a pain in the ass!!!!!!!!!!

FMluvswater
07-26-2004, 05:24 PM
Yeah that's great when the programs work and catch stuff. Something weird is happening though cuz it's AVG resident shield that warns me I have a trojan and tells me to run AVG. I do that and AVG claims no viruses were detected , all except once when it did find and move one to the vault but there have been several other times before that and since that when I've gotten these mixed messages of the resident shield warning me and the virus scanner finding nothing. :confused:

MRS FLYIN VEE
07-26-2004, 05:27 PM
Originally posted by FMluvswaterbabe
Yeah that's great when the programs work and catch stuff. Something weird is happening though cuz it's AVG resident shield that warns me I have a trojan and tells me to run AVG. I do that and AVG claims no viruses were detected , all except once when it did find and move one to the vault but there have been several other times before that and since that when I've gotten these mixed messages of the resident shield warning me and the virus scanner finding nothing. :confused:
ask Forensic about it.. he may beable to help you.. he's good at that stuff.. ;)

FMluvswater
07-26-2004, 05:30 PM
Originally posted by MRS FLYIN VEE
ask Forensic about it.. he may beable to help you.. he's good at that stuff.. ;)
yes he is :) I just might if this situation doesn't resolve after my current removal of trojans attempt.

MRS FLYIN VEE
07-26-2004, 05:32 PM
Originally posted by FMluvswaterbabe
yes he is :) I just might if this situation doesn't resolve after my current removal of trojans attempt.
good luck sweetie.. you didn't watch a sucide movie about osama did you.. it was out on friday..

Keithb87
07-26-2004, 05:35 PM
Why is it that a Trojan is a bad thing on the computer, but a good thing in the cooter????? :confused:

MagicMtnDan
07-26-2004, 05:38 PM
Just wait til you get your browser hijacked from one of those programs! They're incredibly stubborn and damned difficult to remove. It's way worse than any of the news services or Web sites are talking about!

FMluvswater
07-26-2004, 05:38 PM
Originally posted by MRS FLYIN VEE
good luck sweetie.. you didn't watch a sucide movie about osama did you.. it was out on friday..
Nope that topic would not interest me in the slightest and I'd already heard the warning about it's existence and threat. Thanks though. :)

FMluvswater
07-26-2004, 05:39 PM
Originally posted by MagicMtnDan
Just wait til you get your browser hijacked from one of those programs! They're incredibly stubborn and damned difficult to remove. It's way worse than any of the news services or Web sites are talking about!
Quite honestly I hope I never find out first hand. :(

MRS FLYIN VEE
07-26-2004, 05:39 PM
Originally posted by MagicMtnDan
Just wait til you get your browser hijacked from one of those programs! They're incredibly stubborn and damned difficult to remove. It's way worse than any of the news services or Web sites are talking about!
do you know how to remove it.. you seem to know alot about them.. ;)

572Daytona
07-26-2004, 05:57 PM
FM, download and run HiJack This http://www.download.com/HijackThis/3000-8022-10227352.html?tag=lst-0-6
And then email (I will send you a PM with my email address) me the log file and I can take a look and see if there is anything that shouldn't belong there. I find this to be the best thing for cleaning up trojans/spyware.

FMluvswater
07-26-2004, 06:03 PM
Thanks Daytona572. I did and I will. :) I really appreciate this. :)

gnarley
07-26-2004, 06:10 PM
Try this
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
I don't use virus protection and don't open email with attachments that I don't recognize or see the wrong file extensions at the end. I also don't go to websites with my default browser IE that could allow malicious code to execute; instead I use Mozilla Firefox if I suspect that the sight could be bad. Since I use IE I also installed the free MSN popup blocker and change the setting to disallow ALL popups. If you don't know who is sending you a message why bother reading it and wasting your time? Those are the ones that will more than likely send spam and add spyware to your system. Lastly be careful when you receive something from an address you know. That system may be infected and sending viruses out without the owner’s knowledge
If you pay attention you can have a healthy clean system and NEVER have problems. Don't forget to keep your operating system updated with current patches, it does help tremendously and update your patches for Outlook at the link below. If you use Outlook the updates will stop most of the older viruses from getting in.
http://office.microsoft.com/OfficeUpdate/default.aspx

FMluvswater
07-26-2004, 06:52 PM
Originally posted by gnarley
Try this
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
I don't use virus protection and don't open email with attachments that I don't recognize or see the wrong file extensions at the end. I also don't go to websites with my default browser IE that could allow malicious code to execute; instead I use Mozilla Firefox if I suspect that the sight could be bad. Since I use IE I also installed the free MSN popup blocker and change the setting to disallow ALL popups. If you don't know who is sending you a message why bother reading it and wasting your time? Those are the ones that will more than likely send spam and add spyware to your system. Lastly be careful when you receive something from an address you know. That system may be infected and sending viruses out without the owner’s knowledge
If you pay attention you can have a healthy clean system and NEVER have problems. Don't forget to keep your operating system updated with current patches, it does help tremendously and update your patches for Outlook at the link below. If you use Outlook the updates will stop most of the older viruses from getting in.
http://office.microsoft.com/OfficeUpdate/default.aspx
Thanks for the tips. :)
I tried that first link and got this error message ...
Control failed to load. Are you using Internet Explorer 4.0 or above?
I have 6.0. :confused:
I didn't see any patches for Outlook Express at the other link.
I appreciate your efforts to help me. :) Thanks.

Tom Brown
07-26-2004, 06:55 PM
I was hoping this thread was about sex. :(

572Daytona
07-26-2004, 06:56 PM
That's good advice about making sure you have all of the latest MS patches on. The office update site would have patches for Outlook, not Outlook Express. The IE and OE patches would be downloaded from the Windows update website:
http://v4.windowsupdate.microsoft.com/en/default.asp

572Daytona
07-26-2004, 07:02 PM
Originally posted by Tom Brown
I was hoping this thread was about sex. :(
You mean this kind of Trojan :D
http://www.carlsonspeed.com/~daytona/cart199.gif

WetWillie
07-26-2004, 07:09 PM
I have been suffering from and AD trojan. I spent $100 buying three programs and they all detected it and deleted it but it would come back the next time I rebooted. It has been a nightmare! I could not work as I kept getting popups. So I read and read and I found Adware Away. Its freeware and I ran it last night and Im back to normal. Here is the link. I cant recommend it enough!
http://www.adwareaway.com/
Good luck
Willie:)

Dr. Eagle
07-26-2004, 07:42 PM
I thought maybe Hooligin was over trying to tag you...

FMluvswater
07-26-2004, 07:42 PM
Originally posted by WetWillie
I have been suffering from and AD trojan. I spent $100 buying three programs and they all detected it and deleted it but it would come back the next time I rebooted. It has been a nightmare! I could not work as I kept getting popups. So I read and read and I found Adware Away. Its freeware and I ran it last night and Im back to normal. Here is the link. I cant recommend it enough!
http://www.adwareaway.com/
Good luck
Willie:)
Well thanks for the link anyway WetWillie :) ... I tried to install it but got error messages regarding failure to register .dll 's :confused:
Thank-you so much for all your help, Daytona572! :D The hijackthis program is fast and impressive. I really appreciated your suggestions of what to get rid of from the log list - I'd have never figured that part out! You rock! :cool:

MagicMtnDan
07-26-2004, 09:14 PM
In addition to an anti-virus program (I recommend Norton Anti-Virus), you MUST have Spybot and Adaware.
Go to www.download.com and look up both of those programs, download them and run them. And then run them daily. They won't guarantee you won't have problems but they'll protect your computer for the most part.

Spotondl
07-26-2004, 10:08 PM
You shouldn't run both Spybot AND adAware... There are some incompatabilities between the 2. My personal pref is Spybot. Keep in mind that running Spybot or adaware or even Norton does not immunize your system 100%. Common sense and a firewall are must haves.
If you are not running a router/firewall then at the very least run a software firewall like ZoneAlarm on your system...
Run one antivirus, one spyware app, and one firewall. Doubling up offers no more protection and can actually cause more harm than good via system compatibility conflicts...
Just my .02
Rich
Spot ON Data Lab

FMluvswater
07-26-2004, 10:18 PM
I have Zone Alarm firewall protection, AVG anti-virus protection and I have Ad-Aware. I also use Stinger. I have just downloaded Spybot and am trying it out right now. It let me know upfront about what the incompatibilities are with Ad Aware. Spybot is already finding stuff even though Ad-Aware just gave my puter a clean bill of health. :idea: I just might get rid of Ad-Aware.
I just want to say I appreciate everyone for their helpful tips and suggestions. :)

Spotondl
07-26-2004, 10:56 PM
You can try to run both AdAware and Spybot together and if you have no problems then go ahead and leave them installed.
Compatability issues are catch as catch can. Depends on the system involved, what other software is running, hardware configuration, etc. The possibilities are almost infinite.
It is VERY likely that you will not experience any problems running both. If you do have a problem with either program running then, if it were me, uninstall AdAware.
Again, just my .02:) :) :)

FMluvswater
07-26-2004, 11:06 PM
I like your .02 and I thank-you. :)

BiggusJimbus
07-26-2004, 11:08 PM
I effectively use Spybot and Adaware together w/o issues.
I've been completely pissed at this websearch toolbar bullshit. Finally had to grab hijackthis to clean that crap off.
Found a handy site in the process...
http://pchell.com/
Home of solutions to most of the maddening bullshit we have to deal with these days, cutting way down on trial and error time sinks.
Try it. No foolin'.

BiggusJimbus
07-26-2004, 11:13 PM
Every problem has a free solution.
Most problems are easy to solve, and programs like Hijack this keep an archive of anything mistakenly "fixed" for easy unfixing.
If some irritating thing has been grinding on you, you can find a fix for it there.

FMluvswater
07-26-2004, 11:14 PM
Thank-you very much! :cool: Added it to my favorites. :)

King on the River
07-26-2004, 11:21 PM
There is nothing you can do, Trojans can't loose. Thats why they are National Champions. You'll just have to get season tickets and tailgate with me.:D :D :D
Free4all
"LETS GO TROJANS"

bigq
07-26-2004, 11:34 PM
A lot of times you need to run the windows in "safe-mode" then run the anti- virus or the removal program. The reason is if the files are in use by the system it can not remove the bad files or repair them, same with the reg.
I don't run that ad ware stuff just firewall and i use Mozilla for the browser, (great pop up manager) at the very least i would say to switch to Netscape which is based off Mozilla and is recognized easily by web sites.
Some viruses can be very stubborn to remove, I have seen some doozies in the field.

FMluvswater
07-26-2004, 11:50 PM
I have tried other browsers and I don't adapt well. :o I get frustrated because I want them to behave like IE. I know some rudimentary troubleshooting for IE. Learning that much took some doing, and I just haven't got the patience to learn the ins and outs of a new browser. Even if it's more user friendly there's still a learning curve/adjustment period. ... yeah I know ... cheese please :rolleyes: :o
I do know about turning off system restore before getting rid of bad files but I only do this if files I know have been deleted, re-appear upon reboot.
Anyway, thank-you for offering your advice just the same. :)

Boozer
07-27-2004, 12:46 AM
For those who have not used the hijack thingy I HIGHLY recomend it. I just used it and was able to rid myself of a LOT of junk I didnt want like all the stupid tool bars and buttons that get installed so when u start up you have to wait 10 minutes while 50 bajillion things satart running. It eliminated all of them. Now my computer fires up nice and fast.

DOHARA
07-27-2004, 04:21 AM
I had this problem a few weeks ago too. Completely took over my computer at home and at work. I read alot about it on microsoft website and a couple xp groups on google. It got so bad I had to do a clean boot on both systems. One suggestion when you get a pop up asking you if you want to change you home page is to click on the x to close it. I heard when you click on the "no" button it is actually disguised and actually means "yes" and it installs itself on your computer and you keep clicking on "no" and it keeps loading itself deeper into system. These bastard's that create these things should be shot. They get paid like .20 cents on every hit your computer links onto one of the sites in the virus. It's becomming a serious issue. I now run spyware and use a firewall and haven't had any issues since then. I noticed also they are targeting website's kids use. I was trying to log my neice onto the disney channels website and I spelled it wrong and the next thing I know it asked if I wanted to change my home page and I shut down explorer and did a virus sweep and caught it before it took over again. Sorry for the long post, It just pisses me off these scumbags are doing this. I spent hours on the phone with microsoft and they couldn't find the problem.
Good luck.....

gramps
07-27-2004, 05:47 AM
the thing that I have found that works the best is to back up my data files then reinstall windows. It can be a bit of a pain but a reformat will get rid of the problems.

MagicMtnDan
07-27-2004, 06:18 AM
Originally posted by FMluvswaterbabe
I have Zone Alarm firewall protection, AVG anti-virus protection and I have Ad-Aware. I also use Stinger. I have just downloaded Spybot and am trying it out right now. It let me know upfront about what the incompatibilities are with Ad Aware. Spybot is already finding stuff even though Ad-Aware just gave my puter a clean bill of health. :idea: I just might get rid of Ad-Aware.
I just want to say I appreciate everyone for their helpful tips and suggestions. :)
Just a note: Spybot and AdAware do different things - they aren't the same and you can (should) run them.
AVG is free and you get what you pay for. It's a good free program but I strongly recommend you spend a few bucks (around $30) for Norton Anti-Virus. You'll get their updates and they'll keep you protected over the coming months.

91nordic29
07-27-2004, 06:33 AM
i think my browser has been hijacked. i keep getting this damn "shopnav" thing. (i am not that computer - wise). will hijackthis fix it?

BiggusJimbus
07-27-2004, 07:19 AM
AVG is free and you get what you pay for. It's a good free program but I strongly recommend you spend a few bucks (around $30) for Norton Anti-Virus. You'll get their updates and they'll keep you protected over the coming months. [/B][/QUOTE]
Sorry Dan, but I have to disagree on Norton. The latest version has caused many people I know no end of trouble, particularly in conjunction with the Internet Safety crap that they offer. It's also a damn nuisance to rid yourself of once you determine that it doesn't work for you.
I have used AVG for at least two years now without ever having been victimized by any of the "Hot, New" viruses. AVG appear to happen at about the same rate as Norton. I expect my luck will run out one day, but I can equally say that if I had been running Norton, that could be true. I certainly know that I had to pull Norton off my work computer as I couldn't stand the performance it exacted on it. (note: Be careful not to get in the doghouse with your IT folks. They have a job to do and may not like the companies policies, but they have to adhere to them for good reasons).
You are correct about AdAware and Spybot. Different animals. You need them both.
HiJack this can be a dangerous program if you aren't careful in it's use. However, there are good instructions for using it. Bottom line...Back up your data frequently and there is little you can't recover from.
Good Luck everybody.

BiggusJimbus
07-27-2004, 07:24 AM
Ha. That's kind of funny.
The first thing somebody needs help on I can't find reference to.
Is there any identifier other than ShopNav? Is it a toolbar or a webpage hijack?
Any details?

572Daytona
07-27-2004, 07:26 AM
Originally posted by 91nordic29
i think my browser has been hijacked. i keep getting this damn "shopnav" thing. (i am not that computer - wise). will hijackthis fix it?
HijackThis can fix it, after you run the scan, check and fix entries containing the following:
Anything with www.shopnav.com in it
and
any entries with SNHelper.dll, IEHelper.dll or SearchHook.dll

BiggusJimbus
07-27-2004, 07:29 AM
Instruction on removal...
http://www.spy-bot.net/ShopNav.asp
The registry editing is easy to do as described.
The other steps can be done as stated or you can use Hijack this, find the same items and click the fix box.
HiJackthis can be found here...
http://www.download.com/HijackThis/3000-8022_4-10227352.html
I try and use download.com whenever possible to get these tools, as some assholes will actually direct your efforts to get the necessary tools to fix problems to sites that will, in fact, cause them. Always start looking for fixes on sites you trust.
Good Luck.

91nordic29
07-27-2004, 07:31 AM
i think it is a page hijack.
i will try hijack this. i hope i dont screw up as out IT guy is on vacation in canada of all places! (teeheehee;) )

BiggusJimbus
07-27-2004, 07:31 AM
And for god's sake and your own sanity, kill anything that says WinTools or it will plague you forever. Delete any WinTools folders on your pc and deleting your host file are a good idea.

BiggusJimbus
07-27-2004, 07:32 AM
If you break it, you can easily undo your changes.
If you stick to things that are clearly suspect, you will be OK.

572Daytona
07-27-2004, 07:36 AM
Mrs. 91nordic, if you are a little gunshy about what to delete, you can send me a PM with the HijackThis log copy and pasted in and I can take a look and give you my opinion as to what can be safely deleted.

BiggusJimbus
07-27-2004, 07:39 AM
Good Suggestion.
Nice idea Mr. Dayona. Very Helpful.
You can post it here as well. It might help to educate others trying to reclaim their browsers.

572Daytona
07-27-2004, 07:53 AM
Posting it here will work as well, it safe to assume that anything that could be removed from her machine could be removed from others as well.

91nordic29
07-27-2004, 08:36 AM
i'll give 'er a go!

91nordic29
07-27-2004, 09:08 AM
sure seems to be taking awhile to download. is this normal? (15 mins)

572Daytona
07-27-2004, 09:46 AM
It's a pretty small app, so it shouldn't take very long to download. Here is a direct link to the vendor download, it may work better:
http://209.133.47.12/~merijn/files/HijackThis.exe