The PuritanBoard  

Go Back   The PuritanBoard > General Forums > Computers & Technology

Computers & Technology Bible software, computer support questions and other helpful technology matters

Remember the Sabbath day, to keep it holy. Six days you shall labor and do all your work, but the seventh day is the Sabbath of the LORD your God.

» Online Users: 45
4 members and 41 guests
David, mvdm, Ruby, tabrooks
Most users ever online was 856, 07-06-2007 at 12:19 AM.
Closed Thread
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-05-2008, 09:44 PM
Archlute's Avatar
Puritanboard Senior
 
Join Date: Feb 2005
Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
Removing a Trojan Virus?

So, there has been a Trojan worm going around on Facebook. Google it, and you will see how it sets itself up. Anyway, my wife is not very "situationally aware" when it comes to computer safety, and it has now been downloaded onto our desktop PC (I'm writing this from my laptop).

How do you remove something like this? It only seems to be preventing her computer from accessing the Internet. It has been quarantined and removed several times by Windows Defender, but keeps on popping back up after it has supposedly been removed.

Advice on getting rid of it, and assessing the damage?
__________________
Adam J. Myer
Slated for the Jan. 10th Chaplains Basic Officer Leadership Course
Estacada Christian Church
Sandy, Oregon

Soli Deo Gloria
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #2 (permalink)  
Old 12-05-2008, 10:01 PM
turmeric's Avatar
Megerator
 
Join Date: Jan 2004
Location: Portland,OR
Posts: 10,723
Blog Entries: 1
Thanks: 1,738
Thanked 953 Times in 794 Posts
You may have to remove everything and re-install programs. This is a very persistent worm from what I can understand (which ain't much when it comes to computers) I'm going to warn my Facebook friends. Thanks for the heads-up!
__________________
The man who is disposed to think of his sin as a great calamity, rather than as a heinous crime, is not likely either to reverence God or to respect His law. - John Kennedy, 1873
Meg
Blog
Member, Intown Presbyterian Church,PCA, Portland, OR

Click to get: Board Rules -- Signature Requirements -- Suggestions?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #3 (permalink)  
Old 12-05-2008, 10:11 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
Ivan,

What are you trying to post? It is jibberish.

Adam, you may want to start with Hijack This.
__________________
Fred Greco
Senior Pastor, Christ Church PCA (Katy, TX)
Christ Church Blog

"The heart is the main thing in true religion...It is the hinge and turning-point in the condition of man's soul. If the heart is alive to God and quickened by the Spirit, the man is a living Christian. If the heart is dead and has not the Spirit, the man is dead before God." (J.C. Ryle)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #4 (permalink)  
Old 12-05-2008, 10:12 PM
Ivan's Avatar
Pastor
 
Join Date: Oct 2004
Location: Beloit, Wisconsin, USA
Posts: 10,161
Thanks: 1,467
Thanked 1,422 Times in 1,062 Posts
Sorry, Fred. Experimenting.
__________________
Ivan R. Schoen, B.A., M.A., M.L.I.S.
Pastor of Maranatha Baptist Church (SBC)
Poplar Grove, IL, USA

http://maranatha-sbc.org
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #5 (permalink)  
Old 12-05-2008, 10:17 PM
Archlute's Avatar
Puritanboard Senior
 
Join Date: Feb 2005
Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
I would, but it has shut down the ability of our browser to access the Internet.

We're going into safe mode, and searching through recent files, add ons, and currently running programs. I'm trying to figure out how to reveal the hidden ones though. I've also read that a system restore roll back might be able to disable it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #6 (permalink)  
Old 12-05-2008, 10:21 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
You should certainly do a System Restore. Can't really hurt.

You can download Hijack This and then either use a thumb drive (if so, use a old one) or burn to a CD. It can then be put onto the infected computer. Do not network the infected computer, and I would manually disconnect it from the internet until you think it is clean.

TrendSecure | TrendMicro™ HijackThis™ Overview

I believe that Hijack this allows you to delete files as it is rebooting, to avoid reimplanting of the trojan. Another good removal tool is Spybot, and also AdAware (both of which have a free version I believe)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #7 (permalink)  
Old 12-05-2008, 10:24 PM
Archlute's Avatar
Puritanboard Senior
 
Join Date: Feb 2005
Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
That is a great idea, Fred. I hadn't thought of using the laptop as a go between for that program. We've already done a manual disconnect, and the system restore is in process.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #8 (permalink)  
Old 12-05-2008, 10:29 PM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
OK. When the system restore is done, then run Windows Defender, your AntiVirus, and any other anti-malware programs. Hijack This is the best diagnostic tool there is.

As a last resort - you have a backup of your hard drive, right? (Hint, Hint: everyone should have backup software (Ghost, Acronis, etc.) running at least once a week) That way in a pinch, you can wipe the whole drive and restore to a point before the attack.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #9 (permalink)  
Old 12-05-2008, 10:56 PM
Honor's Avatar
de-cool
 
Join Date: Jun 2008
Location: Garden City Ga
Posts: 1,544
Thanks: 787
Thanked 481 Times in 207 Posts
hey... ummm I think I read this a little too late.. I opened a werid message from a guy I vaguely know on facebook... it was a video that was sent to a lot of people... I clicked the link and then closed it before the video could play... do you think I got infected? and if so when do you think I'll see signs?
__________________
Jessica Auner
Wife, Mother,
Garden City, Ga
Ephesus Church
(a Reformed Baptist church)

Hebrews 11:1 Now faith is the assurance of things hoped for, the conviction of things not seen.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #10 (permalink)  
Old 12-05-2008, 11:09 PM
Archlute's Avatar
Puritanboard Senior
 
Join Date: Feb 2005
Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
That is the way the virus works, but it also asks you to download a "necessary update" in order to watch the video. I believe that the virus connects with your computer when you accept the update. If you didn't do that, you may be safe.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #11 (permalink)  
Old 12-05-2008, 11:10 PM
Honor's Avatar
de-cool
 
Join Date: Jun 2008
Location: Garden City Ga
Posts: 1,544
Thanks: 787
Thanked 481 Times in 207 Posts
Praise GOD!!!!! thank you so much
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #12 (permalink)  
Old 12-06-2008, 02:20 AM
Archlute's Avatar
Puritanboard Senior
 
Join Date: Feb 2005
Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
Quote:
Originally Posted by fredtgreco View Post
OK. When the system restore is done, then run Windows Defender, your AntiVirus, and any other anti-malware programs. Hijack This is the best diagnostic tool there is.

As a last resort - you have a backup of your hard drive, right? (Hint, Hint: everyone should have backup software (Ghost, Acronis, etc.) running at least once a week) That way in a pinch, you can wipe the whole drive and restore to a point before the attack.
Thanks for the help, Fred. I think that the combo of the rollback and the "Hijack This" analysis/fix did the job. Our system returned to normal afterward. We ran several scans, and everything came up clean, so I hope that does it.

And, yes, I know that I should have an external hard drive running weekly - I had a good seminary friend give our class a lecture on this after he lost everything to a crash - but still have not gotten around to it. I keep a document/audio file backup on the D drive, and a thumb drive as well, but would have to reinstall everything else manually.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #13 (permalink)  
Old 12-06-2008, 09:10 AM
Galatians220's Avatar
Puritanboard Graduate
 
Join Date: Feb 2008
Location: Michigan
Posts: 3,424
Thanks: 1,963
Thanked 1,062 Times in 600 Posts
There's another virus out there that's killing laptops. It's called "Antivirus 2009." If it gets so far at all that you even see it on the screen, it has installed itself - and started rewriting all of your programs.

My husband's 6-year-old laptop got this virus on Thanksgiving Day and we couldn't do anything with it (it does not even allow you to get to your "Start" menu), so we took it to Best Buy. At the Geek Squad station there, they showed us a line there of 25 other laptops that had gotten infected, and for $200, they were cleaning them out. Ours, they said, was too old and we would be better off just getting a new one. This was on Thursday of this week. My husband is going to pick up his new laptop today. The Geek Squad told us that "all" the laptops are getting this virus... Our son, a chemical engineer who's extremely computer-savvy, has a laptop that also got infected, but as his is a relatively new one, he's going to get it cleaned.

There are some horribly vicious viruses out there!

Margaret
__________________
Margaret
Free Church of Scotland [Continuing]
Michigan

"The LORD thy God in the midst of thee is mighty;
he will save, he will rejoice over thee with joy; he will rest in his love, he will joy over thee with singing." Zephaniah 3:17
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #14 (permalink)  
Old 12-06-2008, 10:19 AM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
Margaret,

I never trust the Geek squad. Here are a couple of links that show how to remove Antivirus 2009. Your husband may want to try it, if only to make it easier to get his files:

Antivirus2009 (Antivirus 2009) Removal Instructions - MS Windows Vista Compatible Software

Is antivirus 2009 a threat? - Yahoo! Answers

Bleeping Computer and MajorGeeks are good sites with forums that usually have advice about this.

Here is another post that I have not had time to peruse yet, but seems to have a working (if more complex) solution:
How to remove the family of rouge anti-malware programs with names similar to “Antivirus 2008 XP” (Update: works on a wide variety of other types of malware as well) « The Technosopher
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #15 (permalink)  
Old 12-06-2008, 10:25 AM
Galatians220's Avatar
Puritanboard Graduate
 
Join Date: Feb 2008
Location: Michigan
Posts: 3,424
Thanks: 1,963
Thanked 1,062 Times in 600 Posts
Quote:
Originally Posted by fredtgreco View Post
Margaret,

I never trust the Geek squad. Here are a couple of links that show how to remove Antivirus 2009. Your husband may want to try it, if only to make it easier to get his files:

Antivirus2009 (Antivirus 2009) Removal Instructions - MS Windows Vista Compatible Software

Is antivirus 2009 a threat? - Yahoo! Answers

Bleeping Computer and MajorGeeks are good sites with forums that usually have advice about this.

Here is another post that I have not had time to peruse yet, but seems to have a working (if more complex) solution:
How to remove the family of rouge anti-malware programs with names similar to “Antivirus 2008 XP” (Update: works on a wide variety of other types of malware as well) « The Technosopher
Thanks, Pastor -- but it's too late now... He's over at Best Buy picking up the carcass of his Dell and the new Compaq with his data having been transferred. That 6-year-old laptop was on its last legs, anyhow, maybe.

For future reference, as I have a 4-year-old desktop, and for others here, I would like to know what makes the Geek Squad not trustworthy. It was his decision (not mine - heh, heh) to go there...

Again, thanks!

Margaret
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #16 (permalink)  
Old 12-06-2008, 10:42 AM
fredtgreco's Avatar
Vanilla Westminsterian
 
Join Date: Oct 2002
Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
Quote:
Originally Posted by Galatians220 View Post
Quote:
Originally Posted by fredtgreco View Post
Margaret,

I never trust the Geek squad. Here are a couple of links that show how to remove Antivirus 2009. Your husband may want to try it, if only to make it easier to get his files:

Antivirus2009 (Antivirus 2009) Removal Instructions - MS Windows Vista Compatible Software

Is antivirus 2009 a threat? - Yahoo! Answers

Bleeping Computer and MajorGeeks are good sites with forums that usually have advice about this.

Here is another post that I have not had time to peruse yet, but seems to have a working (if more complex) solution:
How to remove the family of rouge anti-malware programs with names similar to “Antivirus 2008 XP” (Update: works on a wide variety of other types of malware as well) « The Technosopher
Thanks, Pastor -- but it's too late now... He's over at Best Buy picking up the carcass of his Dell and the new Compaq with his data having been transferred. That 6-year-old laptop was on its last legs, anyhow, maybe.

For future reference, as I have a 4-year-old desktop, and for others here, I would like to know what makes the Geek Squad not trustworthy. It was his decision (not mine - heh, heh) to go there...

Again, thanks!

Margaret
I don't think not trustworthy is the word - and I realize that it was my "misspeaking" that caused that. I have just found that they are no smarter than instructions you can find online (or a good computer geek friend) and they are expensive.

But then again, I pay people to do things around my house (like change out a ceiling fan) that I have no knowledge of absolutely no interest to learn how to do, and I am sure that many here can do!

If the laptop was 6 years old, you really have not lost much. That is really old in computer years.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
The Following User Says Thank You to fredtgreco For This Useful Post:
Galatians220 (12-06-2008)
  #17 (permalink)  
Old 12-06-2008, 11:06 AM
Galatians220's Avatar
Puritanboard Graduate
 
Join Date: Feb 2008
Location: Michigan
Posts: 3,424
Thanks: 1,963
Thanked 1,062 Times in 600 Posts
Quote:
Originally Posted by fredtgreco View Post

But then again, I pay people to do things around my house (like change out a ceiling fan) that I have no knowledge of absolutely no interest to learn how to do, and I am sure that many here can do!

If the laptop was 6 years old, you really have not lost much. That is really old in computer years.
Hey - change a ceiling fan??? That's definitely, without a doubt, a job for a professional! No way would I do that myself! I am not being facetious; I'm serious. One needs that done right so that no annoying noises emanate from it during operation...

Yeah, I think he did get as much as he could out of that laptop. I'm glad to see it gone; it was an irritant to me... (Just the way that it was acquired.) I'm going invoke the "don't diss your spouse" clause that's necessary to being a good Christian wife -- and shut up now...

Thanks.

Margaret
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
  #18 (permalink)  
Old 12-06-2008, 11:15 AM
PactumServa72's Avatar
Puritanboard Freshman
 
Join Date: May 2008
Location: Currently reside in Knoxville TN
Posts: 318
Thanks: 104
Thanked 103 Times in 62 Posts
The best piggy-back trojan remover that i know of is Hijack This. For everything else i use Spybot and Ad-Aware.

**Pastor Greco beat me to it, so I second his recommendations**
__________________
Flavio
Particular Baptist, 1644er
Visiting churches
Bond servant of my Lord Jesus
Husband to Hanna, father to Nathan, Chloe, Caleb, & Lily

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
The Following User Says Thank You to PactumServa72 For This Useful Post:
Galatians220 (12-06-2008)
  #19 (permalink)  
Old 12-06-2008, 11:58 AM
turmeric's Avatar
Megerator
 
Join Date: Jan 2004
Location: Portland,OR
Posts: 10,723
Blog Entries: 1
Thanks: 1,738
Thanked 953 Times in 794 Posts
If you see this on a macbook, I read a forum that says to use Finder to find all the .exe files that go with it, drag them to the trashcan, and empty the trash.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Powered by vBadvanced CMPS v3.2.0

All times are GMT -5. The time now is 05:19 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.
Copyright © 2002-2008 PuritanBoard.com
Hosted by WebsiteMaven - helping ministries with web hosting advice, reviews, and design.
67 Westminster Abbey © Confessional Presbyterian Presses - used with permission.
Add Our Custom Button to your Google Toolbar

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69