Question:
My mum has got a trojan horse virus on her computer and cant get rid of it.?
Darlington
2007-09-02 10:32:53 UTC
I have run AVG Anti virus software and it has quarantined and deleted it but it keeps coming back. Is there anything else I can do to get rid of it before I resort to re installing windows?
Fourteen answers:
2007-09-02 10:48:40 UTC
You should use True Sword: http://www.securitystronghold.com/true_sword.html

Here are the reasons:

* This one can fix over quarter of a million malicious problems

* It's fast, especially with Windows XP

* That will never delete the file your system needs for proper work, while the other programs remove everything they found as a threat

* This program will NEVER piss you off with useless informational boxes.



Good Luck!!!
kendavi
2007-09-02 11:00:12 UTC
The best solution is to go to www.download.com and download "Spybot Search and Destroy". Save the .exe to your Desktop and when it has downloaded, select "Run". Follow the prompts to install it and at the end it will ask if you want to run the "Update". Run the "Update" first so it can get the latest tools, definitions etc. Now scan the PC with Spybot and it will detect the Trojan and you will be able to remove any virus' that are hooked to it. Another reason for it coming back is "System Restore". It appears that you have "System Restore " enabled thus any malicious program that has hooked itself and / or hidden itself deep in the Registry will keep coming back as you are not removing it. Try Spybot and if it reappears, which is unlikely, you need to "Disable" "System Restore" then run Spybot again. Once your System is clean, enable "System Restore" and create a clean "Restore" point. As for Reinstalling, don't! Windows only overwrites files when reinstalling and you could still have the problem. The only guaranteed way to clean a System is a total "Format" and you don't want to do that as you will lose everything that you haven't backed up externally. One final point, a "Trojan Horse" or "Backdoor Trojan" is NOT a virus. It is a small piece of software that exploits any open ports on your PC. It therefore creates holes for other malicious software to breach and install in your system. However, Trojans can also be used as a carrier of a virus. You have started the right procedure by trying to remove the Trojan (Exploit) first as it's the Trojan that allows Malware to infect the PC but you may have something else that is hidden deep in the registry. Run Spybot and you should be able to remove everything at once. Anything that cannot be removed after the scan can be removed on the next reboot. Therefore, if Spybot asks for permission to "Run" at "Start Up", give it permission as it will scan before the Malware can execute and can therefore remove it.



Spyware Dr, why do you want to cause more problems? There is no need to delete any of your E-Mails whatsoever, except for any that have been detected as being infected. Spybot will remove the infections but will not delete legitimate mail. As for disabling "System Restore", this should be done before any scan and not after. If you have completed a scan and cleaned your system before disabling "System Restore", your PC will be reinfected immediately as a copy of the infection is still in the system and it will execute immediately after the removal of the detected infection. You always, always, disable "System Restore" before scanning infected PCs and reactivate "System Restore" immediately after the PC has been cleaned of infection.



PS - If you need to get Ad-Aware, do NOT get the latest version as it has been full of bugs, has many corrupt files etc. etc. and is seriously problematic. Lavasoft have known about the problems since it's release and have ignored hundreds of users comments, on the Lavasoft site. They have had any months to sort the bugs out but think it is more sensible to waste time asking users silly questions such as "what OS are you using" etc. etc. Search for an older, more reliable, version of AdAware as the current version does not complete any scans and if you do get the chance to remove any AdWare etc. it doesn't do it. As for Zone Alarm, I would recommend that users pay for the upgrade to Zone Alarm Pro as it performs better and you have more control such as allowing / blocking individual components rather than whole programs etc.
Alex F
2007-09-02 18:14:29 UTC
Wow you have been getting a lot of answers!

What works for me all the time are these little freebies!

1. http://www.ewido.net/en/

This picked up a lot of trojans and more viruses that I didn't see before. Use the "scan your computer now and clean it for free" thing on the left hand side.

2. http://siri.urz.free.fr/Fix/SmitfraudFix_En.php

This is another program that helped me. Smit Fraud was very useful in restoring only the good things of my computer.

3. http://free.grisoft.com/filedir/inst/avg75free_484a1103.exe

Well this is just awesome! One of the best free things out there to download. It found things on my computer the first 2 couldn't!

4. Spybot- Search and Destroy 1.4

I've used spybot and helps with finding some things too. I don't have an adress for this one, but search it on google and you'll find it!

Happy virus finding and destroying!
2016-04-03 03:43:55 UTC
What are the virus's tell us then we might be able to help. Edit: Ignore all above, ok get AVG 8.0 reason: it's free and does a decent job. now run updates, now run a scan, also get spybot search and destroy and update and do a scan, then remove anything you got from the results from the scans ( this may mean going into the registry) hope this helps :)
2007-09-02 10:38:33 UTC
A PC needs 3 types of protection. Anti Virus, Anti Spyware, Firewall.

There is a guide on my PC help site on; What you need, Why you need it, Where to get it.

All are free.



http://www.phpbbserver.com/stevie19605/viewtopic.php?t=40&mforum=stevie19605
Kerov Rickardo
2007-09-02 10:44:40 UTC
here is how to delet any trojan manually:



1. diconnect your pc first from any connection to the internet

2.Restart the pc and press F8 to choose running on safe mode

3.If you don't know the location of the trojan or the macro ,use

any antitrojan programe :



I myself use avast antivirus protection and plzz make sure to

reinstall the antivirus programe when your pc on the safe mode



4. if all those didn't work then try the following programe:



Trojan Guarder Gold



http://www.download.com/3000-2239_4-10727072.html



and it's serial can be found on:



http://www.serials.ws

http://www.serials.tk

http://www.crackfind.com/

http://www.astalavista.com/



have fun and vote for me plz
James S
2007-09-02 10:42:46 UTC
Look up the name in quotes. There are tools on the internet specifically for removing trojans. Whats the name of it?



You can even look up Trojan Remover on Yahoo or Google and see what software is out there. Much of it free. For example:



http://www.softpile.com/Utilities/AntiVirus/Review_05395_index.html





Or go to a Norton or Macafee site and look it up and see what they advise.
techchick
2007-09-02 10:36:49 UTC
I Got A Virus Or Trojan!

http://forums.majorgeeks.com/showthread.php?t=27385



How to clean an infected computer

http://forum.grisoft.cz/freeforum/read.php?4,27725,backpage=
2007-09-02 10:42:20 UTC
Restore your computer to an earlier point it time (system restore) or return it to factory settings. That worked for my virus. Don't know what windows your on, but to restore mine (XP):



Start > Control Panel > Performance an Maintenance>(was top left in a seperate box labelled "see also")
2007-09-02 10:38:39 UTC
u need a trolan remover not virus software



ive been building comp rigs 4 12 yers now and never use virus protection and have never gotten a virus dont download junk or share videos
2007-09-02 11:11:53 UTC
VIRUS REMOVAL:



this is a realll P.I.A. !!!



THE 1ST PART YOU NEED TO DO offline:

run anti-virus program

run anti spyware program

shut down System Restore

clear cookies

clear temp files

clear history

clear pre-fetch folder

clear out ALL emails starting at 2-3 days ago or when you 1st knew you were infected in:

ALL folders

sent

trash

junk



bookmarks or favorites folder in I.E. or Firefox



as you can see,there's QUITE a bit of work ahead of you.



shut down System Restore:

virus/spyware can hide in your system restore points so we shall delete all previous restore links hiding places by turning system restore OFF.

later,when we finish,we'll turn it back on,set up a new [ CLEAN ] restore to work from in the future.

hopefully,lol,you'll never need it !



XP Home:



start

all programs

accessories

system tools

system restore

settings

drive [c]

settings

check the OFF link



VISTA:



start

control panel

performance and information tools

open disk clean up

select o.s. [c]

select more options

select system restore and shadow copies

select clean up



XP Home & Vista:

start

control panel

internet options

general

clear cookies

clear temp files

clear history

and set history days to keep to 0



clear temp files

not all your temp files will be romoved so easily,so we need to do this manually as well.

start

my computer [ or just computer in Vista ]

windows

temp

file

click each file and delete



Clear Pre-Fetch Files

start

my computer [ or just computer in Vista ]

windows

prefetch

file

select all

press delete key on keyboard



empty recycle bin



run anti-virus and anti-spyweare programs again



when your protection programs find any pirates,DELETE them,do NOT quarentine !!



should you NOT have ANY protection programs installed:

Avast--anti-virus

AD Aware--anti-spyware

Spyware Blaster--anti-spyware blocker

Rootkit Revealer--anti-rootkit

Arovax

PC Tools Firewall--firewall to replace MS's deficient firewall [ turn that sucker OOF ! ] and replace with above.



replace windows firewall with PC Tools firewall

install Arovax protection and choose protection for internet explore if you use it,firefox if you use that or opera if you use that

install spyware blaster and set for internet explorer and/or firefox protection



should you choose to install Firefox web browser [ and you SHOULD ]

here are some Firefox Security Extensions to install

CallingID Link Advisor

Finjan Secure Web Browing

No Script

Dr. Web

SafeDownloads

http://browseraddons.friendpages.com



now it's time to set up your new [ clean ] restore point



XP Home:



start

all programs

accessories

system tools

system restore

settings

drive [c]

settings

check the ON link



Vista:

start

control panel

back up and restore center

create restore point

create restore points on selected disks

select drive

click create

apply and ok



FINALLY....



SECURE COMPUTER:



NEVER !! :



open an email from:

anyone you do NOT know/trust

anyone purporting to be/from:



Microsoft

your bank

your creditors

your goverment

your financial company/ies

even your lawyer/s or church UNLESS you have a prior agreement with them

online petetion

contains attachment/s



SAFE EMAIL SET UP:



YAHOO:

open options link on your email page

select spam

Spam Protection



Choose the tools you'll use to protect your mail account from spam. Not sure what tools you need? Take a look at our Setup Guide for help.

Spam Filter

SpamGuard is ON



For messages SpamGuard identifies as Spam:

Immediately delete these messages upon receipt. (Note: If you choose this option, you will not be able to review the messages before they are deleted.)

When I mark a message as Spam, in addition to deleting the message:

Add the sender's email address to my blocked addresses list

Image Blocking

Block images in messages that SpamGuard thinks are spam

[ possible but 1 or the other ]

Block all images until I've had a chance to look it over



Block Addresses



Block addresses from which you don't want to receive mail.

Add Block

Enter email address (or domain) to block:



GMAIL:

Gmail has an EXCELLENT spam filter,learn to trust it.

Spam Filtering is automatic,unlikeYahoo.

Gmail offers a secound way to protect your inbox by using filters.

1st,you need to create labels [ folders ] to store your filtered email in.

then create the label filter.



SETTINGS:FILTERS:

Create a new filter

Create a Filter

Choose search criteria - Specify the criteria you'd like to use for determining what to do with a message as it arrives. Use "Test Search" to see which messages would have been filtered using these criteria.

From: Has the words:

To: Doesn't have:

Subject: Has attachment



after you fill the above out,you go to label [ folder ] selection.



MSN HOTMAIL:



on your email page,select options then more options

Junk e-mail

Filters and reporting

Safe and blocked senders



choose from these choices:

Safe and blocked senders

Safe senders

Manage who is allowed to send you e-mail. Messages from safe senders will not be sent to the junk e-mail folder.



Safe mailing lists

Manage which mailing lists are sent to your account. Messages to safe mailing lists will not be sent to the junk e-mail folder.



Blocked senders

Manage who is blocked from sending you e-mail. Messages from blocked senders are automatically deleted.



WINDOWS LIVE MAIL:

JUNK E-mail

Options:

safe list only

permanently delete suspected junk e-mail



Safe Senders:

add e-mail addresses to your safe list here

check:

also trust my Windows Contacts

automatically add people i e-mail to the safe senders list



Blocked Senders:

add senders addresses here to create a blocked address list



International:



Blocked Encoding List:



choose the language pack you do NOT want downloaded into your inbox here



Phishing:



check:

protect me from potential Phising emails

move phishing emails to junk

apply & ok



Windows Live Mail has 2 other options:

Tools

message rules

mail

condiotions:

where you choose:

from

to

subject

content and more



Message:

junk e-mail

add to:

safe senders

blocked senders



Web Browsers:



Internet Explorer:

XP Home & Vista:



start

control panel

internet options

general

history:

clear history

set days to keep to 0



Privacy:

advanced

override

First-party Cookies:

Accept

Always allow session cookies

Third-party [ spyware ] Cookies

Block

ok



Content:

content advisor

Enable

ratings:

set content you do NOT want permitted



Approved Sites:

add websites that ARE allowed ALWAYS here



apply & ok



Advanced:

Phishing Filter

enable



Security:

for Internet--Trusted Sites--Restricted Sites

custom

Enable Protected Mode

Custom Level:

XP Home:

Active X:

uncheck each active x control marked:

unsafe

unsigned



Vista:

be sure Active X controls and plugins is marked disable

as well as Automatic prompting for Active X controls

and download unsigned Active X controls

and Intialize and script Active X conttrols not marked as safe



XP & VISTA:



Access data sources across domains-disable

Allow scripting of Internet Explorer web browser control

disable



Allow script-initiated windows without size or position

disable



Allow websites to open windows without address or status bars

disable



Don't prompt for client certificate selection when none exist



Navigate sub-frames across different domains

disable



Use Phishing filter

enable



Allow status bar updates via script

disable



now for your Restricted Zone,EVERYTHING should be disabled EXCEPT:

Pop up blocker

Phishing Filter



[internet,trusted,restricted]

download signed-PROMPT

auto-prompt-DISABLE

binary & script-ENABLE

download UNsigned-DISABLE

download UNsafe-DISABLE

run active x-ENABLE

download SAFE -ENABLE



Spy Sites



Stop Web Sites from installing Spyware, Sleazeware and Cookies on your PC



SpySites includes a database of over 4,600

known Spy/Sleaze sites and guides you

through the simple process of including them in

Internet Explorer's Restricted Zone and setting policies

to prevent them from performing intrusive acts on your PC.

By setting the policies for the Restricted

sites zone to a very high level of security,

you can be assured that any web sites added

to the Restricted sites zone cannot do

certain things which could compromise your privacy

and security such as installing and/or running:

Spysites

http://camtech2000.net/Pages/SpySites_Program.html#SpySitesFree



Pre-Fetch File Cleaing



pre-fetch files are "cached" or stored copies of files/websites you visit each session

after a period of time,these files hog up a LOT of disk space

for this reason,i advocate the deletion weekly of those space hogs

some claim that windows will automatically remove files older than 7 days

I have found MY pc does NOT perform this task so I do it manually

what happens is,when you go to a website,your pc looks into your pre-fetch file/folder

to see if that website is "cached",stored there FIRST

this gives you a faster website load,BUT,you get the "cached" version and NOT the NEWEST version

unless you have "check for newest version" cheched in internet options

it may take that website 1/2 a second longer to load

but,you'll get the newest version loading each time



as added security,spyware removers often miss these files,so delete them manually.



My Computer,disk drive [c],windows,pre-fetch,view,select all,select delete



same situation with Temp files:

Temp File Folder



i use Disk Clean to clean up extraneous files i no longer need

however,everytime i use Disk Clean,it DOESN'T clean out Temp Files!

solution?

My Computer,local disk drive [c],windows,temp

you can safely delete each temp file there.

i leave the most current [that day] alone.

also,do not delete any FOLDER there

folders have a folder icon,leave alone

[ Vista,it's Computer ]



Firefox Web Browser:

tools

options

content

check block pop ups



load images automatically:

exceptions:

enter those websites addresses that show up on pop ups that appear AFTER you close a browser window

also add those same urls to

Privacy

Cookies

Exceptions



there are a number of kewl Security add on firefox extensions i use and they are:

CallingID link advisor

Dr. Web [ link checker ]

Finjan Secure Web Browsing

No Script

SafeDownload

http://browseraddons.friendpages.com



IF you follow all the above suggestions,you'll not have the Fort Knox of computers,but Dammed close !
Danny D
2007-09-02 10:53:51 UTC
if comp will boot up and you can get to programs try using the restore points getting to an earlier time if you can guess when it happened. doesn't always work but its worth a try
2007-09-02 11:01:48 UTC
Help is here!



Programs that should help.



AVG Anti-Virus: http://free.grisoft.com/filedir/inst/avg75free_484a1103.exe

Kaspersky Anti-Virus: http://www.kaspersky.com/anti-virus_trial (Only Trial)

Avast!: http://www.avast.com/eng/avast_4_home.html



Also download



AVG Anti-Spyware: http://free.grisoft.com/filedir/inst/avgas-setup-7.5.1.43.exe

AVG Anti-Rootkit: http://free.grisoft.com/filedir/beta/avgarkt/avgarkt-setup-1.1.0.42.exe

ZoneAlarm free: http://downloads.pcworld.com/pub/new/privacy___security/firewalls/zaSetup_en.exe



Firewalls



Comodo free: http://download.comodo.com/cpf/download/setups/release/CFP_Setup_English_2.4.18.184.exe



Ad-Ware remover:



Ad-aware: http://dw.com.com/redir?edId=3&siteId=4&oId=3000-2144_4-10731194&ontId=2144_4&lop=link&tag=tdw_dltext
Fed-up
2007-09-02 10:40:31 UTC
Try this program, it has a free download trial version. Works well removing trojans.

http://www.misec.net/trojanhunter/


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...