Re: Trojan horse Downloader.Stubby.A

From: Mike Burgess (winhelp2002_at_spamthis.com)
Date: 12/04/03


Date: Wed, 3 Dec 2003 19:01:30 -0500

Bill,
>"I need to copy your canned description of what to do for use in some other
groups"
No problem ........

>"I'm not clear we have the expertise to handle the volume of requests we'd
get"
The generated log is too hard to read here, and way too long for here.

>"I still feel that ad-aware and spybot handle the majority of issues"
Yes they do but the problem is it sometimes takes several weeks to go from
"first detection" to adding to their database. During that period of time
some
of these trojans mutate or simply change one file, which requires a whole
new
set of detections.

Both Ad-Aware and SpyBot have had to add a "HijackThis" section to
their Forums just to deal with all these problems.

Then of course there the "Dell Support" problem! .........
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 12-01-03]
Please post replies to this Newsgroup, email address is invalid

--
"Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
news:%238Ph4VeuDHA.2168@TK2MSFTNGP10.phx.gbl...
> OK - that's clear, and I agree that the tool is outstandingly well written
> in terms of safe operation.  I need to copy your canned description of
what
> to do for use in some other groups, I think.
>
> What I'm not comfortable with doing is promoting responses to the use of
> this tool in this forum, I think.  (meaning on my part--not on yours!) I'm
> not clear we have the expertise to handle the volume of requests we'd get,
> and I still feel that ad-aware and spybot handle the majority of issues
> here--but I haven't kept a careful count, and since someone recommends
> ad-aware for nearly every post here, it's clear there isn't always a lot
of
> careful analysis behind that recommendation, nor always feedback about the
> result!
>
>
> "Mike Burgess" <winhelp2002@spamthis.com> wrote in message
> news:uMGlKBbuDHA.2508@TK2MSFTNGP12.phx.gbl...
> > Bill,
> > You are right that HT is a diagnostic tool.
> > However on the link I provided the OP, it states to run HT, then visit
> > their Forum, for expert assistance.
> >
> > When a user selects an option for HT to remove, it unloads any DLLs
> > and EXEs involved, then deletes the needed values, etc.
> >
> > It is an outstanding tool for spotting/removing Trojans, spyware\adware,
> > etc.
> > http://www.spywareinfo.com/~merijn/htlogtutorial.html
> >
> > As Ad-Aware and SpyBot S&D can no longer keep up with the increased
> > amount of (almost daily) threats, HT can be used "with assistance".
> >
> > Give it a try, as it *only* scans on the first run, HT does NOT remove
> > anything
> > unless the user selects a option. Note: HT automatically creates a
backup.
> >
> > Better yet, take a few minutes and read thru the postings at the SWI
Forum
> > or one of the many, many others, you'll be amazed at the amount of
> > infections!
> > http://forums.spywareinfo.com/ (server down at the moment)
> > http://forums.tomcoyote.org
> > http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi
> > http://boards.cexx.org/
> > http://www.computercops.biz/forums.html
> > ____________________________________________________________
> > Mike Burgess  [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
> > Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS
file
> > http://www.mvps.org/winhelp2002/hosts.htm [updated 12-01-03]
> > Please post replies to this Newsgroup, email address is invalid
> > --
> >
> > "Bill Sanderson" <Bill_Sanderson@msn.com.plugh.org> wrote in message
> > news:uIDdGgIuDHA.3116@tk2msftngp13.phx.gbl...
> > > Hey Mike - I should have tested HijackThis myself--but can you give a
> > simple
> > > explanation?
> > >
> > > I've been assuming that HijackThis is primarily a diagnostic tool.
I'm
> > > getting the feeling from this and similar posts that it is also an
> active
> > > removal tool--what's the story?
> > >
> > > "Mike Burgess" <winhelp2002@spamthis.com> wrote in message
> > > news:uIGJbaIuDHA.1996@TK2MSFTNGP12.phx.gbl...
> > > > MER-44,
> > > > "Downloader.Stubby.A" is fairly easy to get rid of ........
> > > (abetterinternet
> > > > parasite)
> > > > AVG will only identify the culprit .dll .......
> > > >
> > > > Dealing with Unwanted Spyware, Parasites, Toolbars and Search
Engines
> > > > http://mvps.org/winhelp2002/unwanted.htm
> > > > Note: make *sure* to follow-up with HijackThis!
> > > > ____________________________________________________________
> > > > Mike Burgess  [MVP Windows Shell\User]
> http://www.mvps.org/winhelp2002/
> > > > Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a
HOSTS
> > file
> > > > http://www.mvps.org/winhelp2002/hosts.htm [updated 12-01-03]
> > > > Please post replies to this Newsgroup, email address is invalid
> > > > --
> > > >
> > > > "MER-44" <anonymous@discussions.microsoft.com> wrote in message
> > > > news:060f01c3b882$2afdef10$a401280a@phx.gbl...
> > > > > I just got a trojan virus and can't get rid of it.  The
> > > > > norton anti-virus software that I have didn't pick it up
> > > > > but a recently downloaded version of AVG Anti-Virus 7.0
> > > > > did. I can't figure out how to get rid of it and would
> > > > > like some help. The trojan is "Trojan horse
> > > > > Downloader.Stubby.A ".  Thanks MER-44
> > > >
> > > >
> > >
> > >
> >
> >
>
>


Relevant Pages

  • Re: zzb.exe
    ... Here is a link to my message posted regarding hijackthis ... >Blocking Spyware, Adware, Parasites, Hijackers, Trojans, ... >Please post replies to this Newsgroup, ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: My Microsoft and Windows Security Questions
    ... -- Free version of Ad-Aware SE Personal,-- ... -Hijacker.TopConverting TAC rating 5 ... Compressed Disk - Skipped did yesterday OK ... > in Safe Mode) if you still have problems continue on with HijackThis. ...
    (microsoft.public.security)
  • Re: I picked up a trojan [Warning!]
    ... Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file ... Please post replies to this Newsgroup, ...
    (microsoft.public.security.virus)
  • Re: adware(flashtrack)
    ... spysweeper,bazooka and ad-aware but neither seems to remove this annoying ... Download Spybot and Adaware from the following locations and install them. ... Fixing enties with Hijackthis may leave behind unwanted files on your ... Tutorials and free support for the beginning computer user. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: oe6 reading mail showing as html raw source?
    ... 3rd party extensions not enabled. ... I run ad-aware, spybot and avg... ... When all else fails, HijackThis ...
    (microsoft.public.windows.inetexplorer.ie6_outlookexpress)