Question:
Where's the corrupt? > Hundreds of Trojans in #15 months.?
2007-05-12 15:46:20 UTC
So this is what I do I connect to the Internet w/ server.
It goes to Yahoo, I click on My Yahoo, than to Yahoo 360, or Yahoo Answers, and BAM.
(That fast). Trojans & Cookies gets threw my Internet Security.

I don't open any un-known, Emails & no, Bulk mail.

I've had, McAfee it happen.
Did an ..Upgrade in, McAfee same thing.
Had, Avast and the same thing.
Had, AVG and the same thing.
Eight answers:
2007-05-12 16:22:10 UTC
Are you using a firewall: you absolutely must use one.

Do you have open ports; close them.

Do you have exceptions: only allow ones you are certain are OK.



The three products you mentioned protect against viruses not spyware. You must have full time (active) spyware protection and full time (active) virus protection.



I strongly recommend you go through the following procedure to clean your computer and greatly reduce the chances of reinfection with malware. All products are free.

---------------------------------------------------------

Update your antivirus and run a full scan.



If you do not have full time (active) virus protection install:



AVG Antivirus 7.5 Free Edition

http://free.grisoft.com/freeweb.php/doc/avg-anti-virus-free/lng/us/tpl/v5

http://www.download.com/AVG-Anti-Virus-Free-Edition/3000-2239_4-10669237.html?tag=lst-0-1

or

Free antivirus - avast! 4 Home Edition

http://www.avast.com/eng/avast_4_home.html

or

AOL Active Virus Shield

http://www.activevirusshield.com/antivirus/freeav/index.adp

---------------------------------------------------------

Install Windows Defender (full time spyware protection)

Perform a full scan.

http://www.microsoft.com/athome/security/spyware/software/default.mspx

---------------------------------------------------------

Install the following five programs and run weekly or at least monthly. You need all five. They are not a substitute for full time spyware and virus protection. They will greatly increase your protection no matter what active virus and spyware protection you are using.



Ad-Aware SE Personal (update + full scan)

http://www.lavasoftusa.com/products/ad-aware_se_personal.php



Spybot Search & Destroy (update + immunize + scan)

Do not enable Tea Timer and SDHelper

After installation: update + scan + immunize

http://www.safer-networking.org/en/mirrors/index.html



SpywareBlaster: Update then open and click “enable all protection”.

http://www.javacoolsoftware.com/spywareblaster.html



SUPERAntiSpyware free version: (update + scan)

http://www.superantispyware.com/



CCleaner: Do not install toolbar option

Removes tracking cookies, unneeded files, history

In options.

Set to run when computer starts.

Place cookies you want to keep in save list

http://www.ccleaner.com/



Note if a scan detects a problem but is unable to remove the problem, start the computer in safe mode with the internet line disconnected and run a full scan.



In severe cases your system restore files will also be infected. In these cases you will need to turn off system restore to prevent malware hiding in the system restore files and reinfecting the computer during removal or during a future system restore. Turning off system restore deletes the system restore files.



Right click on "my computer"> Properties > System Restore Tab > Check box turn of system restore



After the malware is removed turn on system restore.

-------------------------------------------------------------

Run this time only



CWShredder: run

http://www.trendmicro.com/cwshredder/



Roguefix.bat

http://www.internetinspiration.co.uk/roguefix.htm#uninstall



Shoot The Messenger

http://www.grc.com/stm/shootthemessenger.htm



SmitFraudFix

http://www.geekstogo.com/forum/How_to_use_SmitFraudFix-t109268.html



Vundo Fix and VirtumundoBegone (if VundoFix does not work)

http://www.bleepingcomputer.com/forums/topic18610.html



VX2 tool for Ad-Aware and run tool (Install and run)

http://www.lavasoftusa.com/support/securitycenter/vx2_cleaner.php

----------------------------------------------------------------------

Additional run this time and monthly



Microsoft OneCare Live, run “full service scan”

Updates windows, virus and spyware scan, disk cleanup, disk fragmentation (if needed), backs up registry and then cleans registry, and checks for open firewall ports

http://onecare.live.com/site/en-us/default.htm



Malicious Software Removal Tool (run “full scan”)

http://www.microsoft.com/security/malwareremove/default.mspx

-------------------------------------------------------

Rootkit Removal Guide

http://safecomputing.umn.edu/guides/scan_unhackme.html



Rootkits Removers (Pick any 2 install and run a different one each month)



AVG Anti-Rootkit

http://www.grisoft.com/doc/products-avg-anti-rootkit-update-app-art/?ver=1.1.0.29



F-Secure BlackLight

http://www.f-secure.com/blacklight/



Sophos Anti-Rootkit

http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

----------------------------------------------------------

----------------------------------------------------------

Online Free Scanners:

Run Trend Micro, Kaspersky, and Panda Scan now.

Run a different one each month.



Trend Micro: HouseCall Free Scan (removes what it finds)

http://housecall.trendmicro.com/

BitDefender Online Scanner http://www.bitdefender.com/scan8/ie.html

Kaspersky Labs Online Scanner http://www.kaspersky.com/virusscanner

McAfee http://us.mcafee.com/root/mfs/default.asp?affid=294

Panda ActiveScan Free Online Scanner http://www.pandasoftware.com/products/activescan?

Symantic Online Scanner http://security.symantec.com/sscv6/ssc_eula.asp?langid=ie&venid=sym&plfid=23&pkj=ALUFRHYTINMHDKDCWLL&vc_scanstate=2

-------------------------------------------------------

Additional Information read:

http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview

http://wiki.castlecops.com/Malware_Prevention:_Prevent_Re-infection

http://www.castlecops.com/f67-Hijackthis_Spyware_Viruses_Worms_Trojans_Oh_My.html

http://aumha.org/a/quickfix.htm

http://aumha.org/secure.htm

http://aumha.org/a/parasite.php

http://www.castlecops.com/t102301-Hijackthis_Guidelines_Read_Before_Posting.html

http://www.techsupportforum.com/security-center/hijackthis-log-help/15968-please-read-before-posting-

http://forum.aumha.org/viewtopic.php?t=4075&sid=901703d08c2ace31389ffef2d84b6607
?
2016-08-24 14:03:06 UTC
2
?
2016-11-28 03:01:28 UTC
hi there with each and every of the haters!!?! USC isn't any different variety the different college application different than their using the horse precise now. Nebraska had their time, so did Miami. each and every of the assets you suggested above is beside the point. Sexual assult? are you extreme. for sure you have in no way been an athlete at a D1 college. Hell a suitable prep athlete at that. the only factor that even registers on right here is the Reggie Bush factor. What you fail to realize is that that had no longer something to do with USC. it became right into some unfavorable youngster and his kin wanting an improve on that destiny examine. regrettably Bush would be reasons why the USC dynasty ends. They dont cheat. Carrol is going as much as adult adult males and says "you could nicely be a starter in the NFL from our bench." (see Cassel and Lendale White)
cnsystemsaustralia
2007-05-13 05:01:50 UTC
One point everybody seems to be missing.

If you are only using your pc for internet , email , office work , graphics , video and music ( eg not playing games ) , then you have no reason not to change to Ubuntu or another version of Linux.

Apart from not needing to install all these antivirus , anti adware , anti trojan etc etc software , you are completely immune to these form of attacks and your pc will run faster than under Windows.



By all means, if you have to run AutoCAD for work , or are a heavy pc games player , then stick with Windows and install all the protection you can get your hands on.



But if you don't need it , why put up with the head-aches?
ashenshugar2005
2007-05-12 16:12:20 UTC
Try using a good firewall program like ZoneAlarm. But you should layer your AV solutions, try using two different ones, no single program can catch all viruses. The ZoneAlarm will effectively shutdown all ports that are not allowed stopping most trojans.
Fix My PC Mike
2007-05-12 16:10:24 UTC
You need antispyware as well and you should set your browser privacy settings to prompt for all cookies.



Hitman Pro will let you automatically install, update, and run in Safe Mode many of the best free and free-to-try antispyware programs all with one click, including Spybot Search & Destroy, Lavasoft Ad-Aware SE, SpywareBlaster, Ewido, and free trials of Webroot Spysweeper and PCTools SpywareDoctor. The free version of Spybot Search & Destroy allows autoupdates, but Hitman Pro helps in keeping the others up to date with one click.
2007-05-12 15:54:14 UTC
Happend to me this morning it was a bear to fix.
2007-05-12 22:50:28 UTC
Follow these steps and it will remove almost all viruses and malware/spyware from your computer. It will also make your computer run faster.

.

•I know this procedure looks long, but much of this is explanatory text to help less experienced people.

•Please do not cheat by skipping any steps. You are only hurting yourself if you do. And you will waste more time. The goal is to get your PC fixed. Completing the steps in this generic guide may or may not resolve all of your malware problems, but in all cases it gets your PC into a known state to help make it easier for me to fix your problems. After completing all steps, if you still need help, please send a new question. You may have a problem trying to run steps in safe mode on user accounts that have limited priviledges. This will only be on Windows 2K, XP, & 2003 systems. Limited user accounts will not show when you boot into safe mode. You have two options, run the steps in normal boot mode which may not work to remove malware, or you can temporarily change the user account to an admin account and then complete the steps.

•0: Preliminary House Cleaning & Setup



Unistall Malware thru your computers Add?Remove program.

You MUST be sure that MSconfig is not being used to control Startups. Note: That some Window's OSs (like Win 2K) do not have MSconfig!

•MSConfig Startup Mode

Please go to Start > Run > type msconfig and click OK!

Select the General tab and select Normal Startup.

Thenclick Apply and OK and reboot PC before continuing.

Remain in this Normal Startup mode while your PC is being cleaned of malware.

1: Secondary House Cleaning



This second step of house cleaning may save a load of time later .

•Empty any quarantine folders for antivirus and antispyware applications. Make sure you do this. Logs could be huge otherwise. If you are a Symantec/Norton user make sure you empty their Norton Nprotect folder guarding the Recycle Bin. Empty your Recycle Bin

•Download and install CCCleaner

•MAKE SURE you download and avoid getting the Yahoo Toolbar version. I do not want you to install any unnecessary baggage.

•Also it is recommeded to login to all other User Accounts on the PC including the Administrator account which will only show when you boot in safe mode. Run CCleaner on each account. This can greatly reduce scan time and log sizes from the later scanning you will do below.

2: Enable viewing of hidden files, system files and file extensions



Some programs hide themselves by making their files invisible in normal Windows settings. Not doing this would allow file extensions commonly used by trojans and spyware to be hidden, for example a file ending in .exe or dll making manually finding it, if needed, difficult to impossible.





3: Do not use Multiple Antivirus Applications or Software Firewalls

•Antivirus: If you have multiple antivirus applications installed on your PC, please choose the one you prefer and uninstall all others. Do this now before continuing because you will only be asked to do it later if not done now. This does not mean online scanners. It is only referring to full antivirus applications like McAfee, Symantec, AVG, Avast, AntiVir, Kaspersky, etc.

•Firewall: Only use one software firewall. Running multiple software firewalls is unnecessary and using more than one software firewall on the same connection could cause issues with connectivity to the Internet or other unexpected behavior including excessive use of system resources which will slow down overall PC performance.

4: Downloading Tools



Download the following tools and save in your favorite download folder or create one, for example C:\Spyware Tools or C:\Downloads. ( It is not a good idea to download them to any folder within C:\Documents and Settings.) And then install, update, and configure as indicated below. Do not run the scans until later when indicated. Also DO NOT confuse the word download with the actual installation of the program. You should install all programs to their recommended (by the install program). default installation folders. First you download the files and then you install (if the program requires installation) the program. It is also a bad idea to download and save anything you need into any kind of Temp folder. Malware hides in Temp folders and standard cleaning practices will delete everything from Temp folders.



Download GetRunKey.Zip and ShowNew.Zip from the below links and extract all files from both ZIP files into a folder of their own. You can extract both ZIP files into the same folder. Like C:\MGTools While these tools will run from your Desktop, i strongly recommend that you DO NOT extract them to your Desktop. Please install them where recommended. Do not run the scans yet!!!





SpyBot - Search & Destroy

•PLEASE leave all settings at default!!!! Install, do the search for updates now and get any updates, then fix the below problem with Spybot default products. If you get an error message about "bad checksum" when trying to update, just choose a different server location. Also look for the Immunize feature in Spybot and use it. Do not use the Teatimer function. It can be a resource hog and also makes removal of certain problems more difficult. Make sure you leave the SDhelper ( IE bad download blocker) checked to install (this is the default).

•Fixing SpyBot's Ignore Products Bug: Please run SpyBot and get into the Advanced mode by selecting Mode and then Advanced mode. Then select Settings and the in the left column select Ignore Products. In the right window pane make sure the All products tab is selected. Then in that window, right click your mouse and choose "Deselect all". Now exit Spybot. We will run a scan later.

Now if running Windows XP, 2K or NT do the below. If you have Windows 95, 98, or ME skip to Downloads for Older Windows OS below. CounterSpy and AVG Antispyware will no longer run on the older Windows's OS.



CounterSpy



•If you had previously used a CounterSpy trial, you may not be able to run it again. If this is the case, then run the below AVG Antispyware Removal procedure and attach the log later.

AVG Anti-Spyware

•Only run the AVG Anti-Spyware procedure if you could not run CounterSpy. You do not need to run both of these.

Note: If you are using an older Windows OS you may not be able to run some of the above tools! So if you are running Windows 95, 98, or ME run SUPERAntiSpyware and save a log from it so you can attach it. This step is not required if you are running Windows XP, 2K or NT) HOWEVER, no matter what OS you are running, if you could not run CounterSpy or AVG Antispyware then run SuperAntiSpyware.





5: Cleaning Malware





Important Note Before continuing with the below scans:



The best method to remove malware is to do it after booting in Safe Mode with no connection to the internet possible and no browsers running. Booting in safe mode is important because best results are achieved since safe mode disables most drivers and running programs. If you cannot boot in safe mode due to the malware problem then run the scans in normal boot mode but make sure you tell us later in any messages you post.



Thus you will need to print or save these instructons locally in a text file so you can refer to them while offline. Do this before continuing!

•Reboot into safe mode

•Physically unplug your cable to the internet (even if you have dial-up, unplug modem)

•Shut down ALL unrequired applications including browsers

•Run Ccleaner with the default options to clean out temporary files. Only use the Default Scan on the Windows Tab and select Run Cleaner. Do not run any other options from other tabs.

•Run Spybot Search & Destroy and allow it to fix all that it finds. Make sure you use the Immunize feature and use the SDHelper function but do not use Teatimer.

•For Windows XP, 2K and NT users

•Run CounterSpy - Make sure you have it Quarantine all detections! Also attach the log from CounterSpy later if you still have problems. To get the log after scanning. Click View -> Spyware Scan -> View Spyware Scan History. Next click on the scan you want to view, then click view full details of scan. Right-click anywhere in the window that just opened, click on Select All, right-click again select Copy. Now open notepad and right-click anywhere in notepad and select Paste. Now Save As CounterSpy.txt. If you could not run CounterSpy for any reason, run the steps in the following link for AVG Antispyware Running AVG Anti-Spyware and allow it to fix all that it finds. Save the log as requested and attach it later if you still have problems and have to post a message requesting support.

•For Windows 95, 98 and ME users

•you should now run SuperAntiSpyware

6A: Online Virus And Trojan Scanning



Please run the below two online scanning tools and make sure you save and attach the logs later to any request for help that you post. From step 5 you should already be in safe mode but you will need to reconnect your cable now and possibly reboot and choose Safe Mode with Networking Support. If you cannot connect in safe mode for any reason (like dial-up users), run the online scanners in normal boot mode. You will need to use Internet Explorer to run these online scans. Also MAKE SURE YOU HAVE THE LATEST SUN JAVA Version installed by checking against the below link which normally has the most current version. This may help prevent some problems in trying to get these online scanners to run. Before installing the current version, you should uninstall all previous versions first!!!!





*** MAKE SURE YOU RUN BITDEFENDER BEFORE PANDA ACTIVE SCAN ***

*** But if Bitdefender cannot be run then run PandaActiveScan anyway ***





Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. Once Bitdefender completes the scan:



Click-on the Detected Problems tab. When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that i can easily view later while reviewing your log. All i have to do is rename the file to bdscan.html.



If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to me.



Panda ActiveScan It will only fix certain viruses and trojans. Most items found will not be fixed. When it finishes the scan click on See Report . Then in the next window click Save Report. The default report name is Activescan.txt. Just save it where you can find it so you can attach to your message when you begin a thread with a request for help. If you have any problems trying to get a PandaActiveScan log,If you use Avast antivirus and it gives you and error like below when trying to use Panda, just disable Avast while your run the scan. The error is a false positive. See the below link for more info.

Do the following and see what happens......


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...