trojan news..

From: Ben Yarnold (Beope_at_bigpond.com)
Date: 04/05/05

  • Next message: Ben Yarnold: "miracle is needed!"
    Date: Tue, 05 Apr 2005 03:37:50 GMT
    
    

    i have done a scan with the sysclean in normal windows bcoz i couldn't
    restart in safemode. im running xp sp2 i was pressing f8 while starting
    didn't work... the scan found nothing on the system..??? i already have ad
    aware and do regular scans. i don't dl crap of the net i don't know how i
    got it. when i did my first scan with AVG antivirus said that the file
    hijackthis.exe was infected. that file was from a trusted source for fixing
    malware and the like. mayb a false negative? why do i have 2 turn sytem
    restore off? it said that the restore points would b deleted so i opted not
    2. the scan with sysclean said that access was denied to alot of files with
    diffent extensions. since then i have created a admin user then changed my
    user 2 limited. and was planning 2 use the admin user 4 office type stuff
    and my limited 4 everything else. was this the rite thing 2 do? thanx for
    help but still need it....plz!!
    "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
    news:s5J3e.1459$1r6.1121@trnddc02...
    > From: "Ben Yarnold" <Beope@bigpond.com>
    >
    > | i have done a virus scan as normal and found out that i have a trojan
    > horse
    > | backdoor small.28.ao. it has been 'healed' by my av AVG but don't know
    > how
    > | it got there. i have been using kerio firewall is this prog alrite? is
    > there
    > | a better freeware program around? it has almost expired can i get a
    > crack
    > | for it? i am using latest spybot ad aware AVG and kerio. but these
    > things
    > | are expiring!!! ne suggestions on another program or maintaining my
    > current
    > | setup welcome.
    > |
    >
    > We are assuming it is an infector at the root of the problem...
    >
    > Dump the contents of the IE Temporary Internet Folder cache (TIF)
    >
    > start --> settings --> control panel --> internet options --> delete files
    >
    > 1) Download the Sysclean Front End utility ( SYSCLEAN_FE ) in
    > "Procedure 1"
    > at the following URL, SYSCLEAN_FE automates the download and
    > execution process of the Trend Sysclean Package.
    > http://www.ik-cs.com/got-a-virus.htm
    >
    > Direct URL:
    > http://www.ik-cs.com/programs/virtools/Sysclean_FE.exe
    >
    > Execute; SYSCLEAN_FE.EXE
    > Choose; Unzip
    > Choose; Close
    >
    > Execute; c:\sysclean\SYSCLEAN_FE.BAT
    > { or Double-click on 'SYSCLEAN_FE Link' in c:\sysclean }
    >
    > When you get to the Sysclean Front End menu, hit 'e' or '3' to
    > exit.
    >
    > 2) Download and install Ad-aware SE (free personal version v1.05)
    > http://www.lavasoftusa.com/
    > 3) Update Adaware with the latest definitions then exit the software.
    > 4) If you are using WinME or WinXP, disable System Restore
    > http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
    > 5) Reboot your PC into Safe Mode and shutdown as many applications as
    > possible
    > 6) Using the Trend Sysclean and Ad-aware SE utilities, perform a Full
    > Scan of your
    > platform and clean/delete any infectors found
    > 7) Restart your PC and perform a "final" Full Scan of your platform
    > using both Trend
    > Sysclean and Ad-aware SE
    > 8) If you are using WinME or WinXP, re-enable System Restore and
    > re-apply any
    > System Restore preferences, (e.g. HD space to use suggested 400 ~
    > 600MB),
    > 9) Reboot your PC.
    > 10) If you are using WinME or WinXP, create a new Restore point
    >
    > * * * Please report back your results * * *
    >
    >
    > --
    > Dave
    > http://www.claymania.com/removal-trojan-adware.html
    > http://www.ik-cs.com/got-a-virus.htm
    >
    >


  • Next message: Ben Yarnold: "miracle is needed!"

    Relevant Pages

    • Re: What is Backdoor.Winbach as reported by eTrust Pest Patrol scan?
      ... do not use prior restore points. ... First thing is to run a cleanup on your current system. ... "Michael" wrote ... I suggest you get & run SYSCLEAN from Trendmicro. ...
      (microsoft.public.windowsxp.help_and_support)
    • Re: trojan news..
      ... | i have done a scan with the sysclean in normal windows bcoz i couldn't ... Trend Micro - Free online virus Scan ... Panda ActiveScan - Free online scanner ...
      (alt.computer.security)
    • Re: why all the services turn off by itself.
      ... Then updated my windows, updated my scanners, Spybot1.4, Ad-aware 1.06, run ... The Sysclean in Safe mode clear the last nasties INF.Dloader.M and so I ... were disabled as I cant even use the Restore Point What is causing this. ... Read and understand "Cleaning a Compromised System" ...
      (microsoft.public.windowsxp.general)
    • Re: Virus?
      ... Sysclean is a broad-spectrum ... Dave ... |>| even disable sys restore or create files on the "C" ... |>|>3) Reboot your PC into Safe Mode ...
      (microsoft.public.security.virus)
    • Re: Attn: Rock
      ... > Status: Free memory ... > I did download TM's sysclean and I ran it in safemode ...
      (microsoft.public.windowsxp.general)