Re: Do I have a worm OR virus...computer going very slow and ...



From: "writer" <writer@xxxxxxxxxxxxxxxxxxxxxxxxx>

| Dear David...
|
| wow...I ran McAfee and it took over 3 hours and it found over 21 things that
| it got rid of...that makes no sense since I have AVG (the free variety) and
| AD aware...and spy bot. I have the log of what it got rid of....but it also
| included a trojan. I am now scanning with Trend Micro but not sure I can stay
| up another 3 hours...
|
| I do not know how to scan in safe mode can you please tell me how to do that
| because how do you access files in safe mode?
|
| ...but it looks like I have cleared out alot of stuff...how many of these
| should I do? This is very tedius...and also I am wondering why there is a
| trojan with the firewall I have from windows xp running....?
|
| You have been a very big help so far...should I copy down what you sent to
| me to try incase this happens again? I was never able to figure out how to
| run the execute file that you wanted me to run? How does one run such a file?
| I had to find the file on my hard drive and then click on start...that seemed
| to work. Do I need to reboot after each run I have with group...so should I
| have run McAfee and then rebooted and then run Trend micro?
|
| hopefully you have some time to answer these questions...and still not
| sure how to do safe mode... here is my log...

Fitz as given you good follow-up directions so I'll just answer the other parts.

Are you saying you already had Ad-aware SE v1.06 and SpyBot S&D v1.4 ?

Earlier versions such Ad0-aware 6 and SpyBot S&D v1.3 should be replaced and updated the the
latest versions.

I am sorry that it takes so long but these tools are agressive and highly effective as the
McAfee HTML Log file indicates. It is far better to prevent the to fix. And you are seeing
both the side effect consequences and time consequences of poor prevention.

No one software does everthing. Your *best* defense will always be Safe Hex practices. If
you don't you chance being infected will the malware thay you have. When you are, you have
to use a myriad of tools to remove it all.

http://www.claymania.com/safe-hex.html

What was found on your PC was not good. Gain software such as Gator are know adware/spyware
and Gain makes *many* more.

However, what was also found was "Downloader-AGT" and what's worse, "PWS-Banker.gen.p
trojan".

The first is a Dowbloader Trojan that goes out and automatically downloads other malware.

PWS-Banker.gen.p trojan -- http://vil.nai.com/vil/content/v_132640.htm

http://vil.nai.com/vil/content/v_103059.htm

"Password Stealers may steal data from the hard drive.

This data might include:

CD Keys for various games
credit card details
your local username/password

It may also log keystrokes for login details for banking applications, for example while
Internet Explorer is open and connected to specific websites"



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


.



Relevant Pages

  • Re: Can not delete file
    ... do it in safe mode. ... trojan. ... booting up with an NTFS boot disk and hooking the hard drive to a ... and how can I get rid of it? ...
    (microsoft.public.windowsxp.general)
  • Re: Trojan horse Downloader.Rvp.D in system info folder
    ... Have you tried running in safe mode ?? ... >rid of the trojan horse that seems to have loged itself in there myself. ... >wanted but none of them seem to be accessing teh sys info folder where AVG ...
    (microsoft.public.security.virus)
  • Re: Ilomo trojan-regscan- how do I zap this thing?
    ... 64bit drivers for the computer internal hardware. ... may try triple boot with XPpro, ... gotten rid of it or not. ... the Trojan gets installed again and opens the ...
    (microsoft.public.win2000.general)
  • Re: Ilomo trojan-regscan- how do I zap this thing?
    ... gotten rid of it or not. ... and rings you find here and there about getting rid of this Trojan and you ... are no renamed Windows files on that server that will open it up as soon ... message saying they are in use and new temp files immediately appear with ...
    (microsoft.public.win2000.general)
  • Re: Ilomo trojan-regscan- how do I zap this thing?
    ... gotten rid of it or not. ... rings you find here and there about getting rid of this Trojan and you think ... renamed Windows files on that server that will open it up as soon as you ... message saying they are in use and new temp files immediately appear with ...
    (microsoft.public.win2000.general)