» Site Navigation | | | |  | 
12-05-2008, 09:44 PM
|  | Puritanboard Senior | | Join Date: Feb 2005 Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
| | | Removing a Trojan Virus?
So, there has been a Trojan worm going around on Facebook. Google it, and you will see how it sets itself up. Anyway, my wife is not very "situationally aware" when it comes to computer safety, and it has now been downloaded onto our desktop PC (I'm writing this from my laptop).
How do you remove something like this? It only seems to be preventing her computer from accessing the Internet. It has been quarantined and removed several times by Windows Defender, but keeps on popping back up after it has supposedly been removed.
Advice on getting rid of it, and assessing the damage?
__________________
Adam J. Myer
Slated for the Jan. 10th Chaplains Basic Officer Leadership Course
Estacada Christian Church
Sandy, Oregon Soli Deo Gloria | 
12-05-2008, 10:01 PM
|  | Megerator | | Join Date: Jan 2004 Location: Portland,OR
Posts: 10,723
Thanks: 1,738
Thanked 953 Times in 794 Posts
| | |
You may have to remove everything and re-install programs. This is a very persistent worm from what I can understand (which ain't much when it comes to computers) I'm going to warn my Facebook friends. Thanks for the heads-up!
| 
12-05-2008, 10:11 PM
|  | Vanilla Westminsterian | | Join Date: Oct 2002 Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
| | |
Ivan,
What are you trying to post? It is jibberish.
Adam, you may want to start with Hijack This.
__________________ Fred Greco
Senior Pastor, Christ Church PCA (Katy, TX) Christ Church Blog "The heart is the main thing in true religion...It is the hinge and turning-point in the condition of man's soul. If the heart is alive to God and quickened by the Spirit, the man is a living Christian. If the heart is dead and has not the Spirit, the man is dead before God." (J.C. Ryle) | 
12-05-2008, 10:12 PM
|  | Pastor | | Join Date: Oct 2004 Location: Beloit, Wisconsin, USA
Posts: 10,161
Thanks: 1,467
Thanked 1,422 Times in 1,062 Posts
| | |
Sorry, Fred. Experimenting.
__________________ Ivan R. Schoen, B.A., M.A., M.L.I.S.
Pastor of Maranatha Baptist Church (SBC)
Poplar Grove, IL, USA http://maranatha-sbc.org | 
12-05-2008, 10:17 PM
|  | Puritanboard Senior | | Join Date: Feb 2005 Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
| | |
I would, but it has shut down the ability of our browser to access the Internet.
We're going into safe mode, and searching through recent files, add ons, and currently running programs. I'm trying to figure out how to reveal the hidden ones though. I've also read that a system restore roll back might be able to disable it.
| 
12-05-2008, 10:21 PM
|  | Vanilla Westminsterian | | Join Date: Oct 2002 Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
| |
You should certainly do a System Restore. Can't really hurt.
You can download Hijack This and then either use a thumb drive (if so, use a old one) or burn to a CD. It can then be put onto the infected computer. Do not network the infected computer, and I would manually disconnect it from the internet until you think it is clean. TrendSecure | TrendMicro™ HijackThis™ Overview
I believe that Hijack this allows you to delete files as it is rebooting, to avoid reimplanting of the trojan. Another good removal tool is Spybot, and also AdAware (both of which have a free version I believe)
| 
12-05-2008, 10:24 PM
|  | Puritanboard Senior | | Join Date: Feb 2005 Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
| | |
That is a great idea, Fred. I hadn't thought of using the laptop as a go between for that program. We've already done a manual disconnect, and the system restore is in process.
| 
12-05-2008, 10:29 PM
|  | Vanilla Westminsterian | | Join Date: Oct 2002 Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
| |
OK. When the system restore is done, then run Windows Defender, your AntiVirus, and any other anti-malware programs. Hijack This is the best diagnostic tool there is.
As a last resort - you have a backup of your hard drive, right? (Hint, Hint: everyone should have backup software (Ghost, Acronis, etc.) running at least once a week) That way in a pinch, you can wipe the whole drive and restore to a point before the attack. | 
12-05-2008, 10:56 PM
|  | de-cool | | Join Date: Jun 2008 Location: Garden City Ga
Posts: 1,544
Thanks: 787
Thanked 481 Times in 207 Posts
| | |
hey... ummm I think I read this a little too late.. I opened a werid message from a guy I vaguely know on facebook... it was a video that was sent to a lot of people... I clicked the link and then closed it before the video could play... do you think I got infected? and if so when do you think I'll see signs?
__________________
Jessica Auner
Wife, Mother,
Garden City, Ga
Ephesus Church
(a Reformed Baptist church)
Hebrews 11:1 Now faith is the assurance of things hoped for, the conviction of things not seen.
| 
12-05-2008, 11:09 PM
|  | Puritanboard Senior | | Join Date: Feb 2005 Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
| | |
That is the way the virus works, but it also asks you to download a "necessary update" in order to watch the video. I believe that the virus connects with your computer when you accept the update. If you didn't do that, you may be safe.
| 
12-05-2008, 11:10 PM
|  | de-cool | | Join Date: Jun 2008 Location: Garden City Ga
Posts: 1,544
Thanks: 787
Thanked 481 Times in 207 Posts
| |   Praise GOD!!!!! thank you so much
| 
12-06-2008, 02:20 AM
|  | Puritanboard Senior | | Join Date: Feb 2005 Location: Sandy, Oregon
Posts: 2,063
Thanks: 453
Thanked 870 Times in 398 Posts
| | Quote:
Originally Posted by fredtgreco OK. When the system restore is done, then run Windows Defender, your AntiVirus, and any other anti-malware programs. Hijack This is the best diagnostic tool there is.
As a last resort - you have a backup of your hard drive, right? (Hint, Hint: everyone should have backup software (Ghost, Acronis, etc.) running at least once a week) That way in a pinch, you can wipe the whole drive and restore to a point before the attack.  | Thanks for the help, Fred. I think that the combo of the rollback and the "Hijack This" analysis/fix did the job. Our system returned to normal afterward. We ran several scans, and everything came up clean, so I hope that does it.
And, yes, I know that I should have an external hard drive running weekly - I had a good seminary friend give our class a lecture on this after he lost everything to a crash - but still have not gotten around to it. I keep a document/audio file backup on the D drive, and a thumb drive as well, but would have to reinstall everything else manually.
| 
12-06-2008, 09:10 AM
|  | Puritanboard Graduate | | Join Date: Feb 2008 Location: Michigan
Posts: 3,424
Thanks: 1,963
Thanked 1,062 Times in 600 Posts
| |
There's another virus out there that's killing laptops. It's called "Antivirus 2009." If it gets so far at all that you even see it on the screen, it has installed itself - and started rewriting all of your programs.
My husband's 6-year-old laptop got this virus on Thanksgiving Day and we couldn't do anything with it (it does not even allow you to get to your "Start" menu), so we took it to Best Buy. At the Geek Squad station there, they showed us a line there of 25 other laptops that had gotten infected, and for $200, they were cleaning them out. Ours, they said, was too old and we would be better off just getting a new one. This was on Thursday of this week. My husband is going to pick up his new laptop today. The Geek Squad told us that "all" the laptops are getting this virus... Our son, a chemical engineer who's extremely computer-savvy, has a laptop that also got infected, but as his is a relatively new one, he's going to get it cleaned. There are some horribly vicious viruses out there!
Margaret
__________________
Margaret
Free Church of Scotland [Continuing]
Michigan "The LORD thy God in the midst of thee is mighty; he will save, he will rejoice over thee with joy; he will rest in his love, he will joy over thee with singing." Zephaniah 3:17 | 
12-06-2008, 10:25 AM
|  | Puritanboard Graduate | | Join Date: Feb 2008 Location: Michigan
Posts: 3,424
Thanks: 1,963
Thanked 1,062 Times in 600 Posts
| | Quote:
Originally Posted by fredtgreco | Thanks, Pastor -- but it's too late now...  He's over at Best Buy picking up the carcass of his Dell and the new Compaq with his data having been transferred. That 6-year-old laptop was on its last legs, anyhow, maybe.
For future reference, as I have a 4-year-old desktop, and for others here, I would like to know what makes the Geek Squad not trustworthy. It was his decision (not mine - heh, heh) to go there...
Again, thanks!
Margaret
| 
12-06-2008, 10:42 AM
|  | Vanilla Westminsterian | | Join Date: Oct 2002 Location: Katy, Texas
Posts: 10,519
Thanks: 334
Thanked 3,501 Times in 1,412 Posts
| | Quote:
Originally Posted by Galatians220 Quote:
Originally Posted by fredtgreco | Thanks, Pastor -- but it's too late now...  He's over at Best Buy picking up the carcass of his Dell and the new Compaq with his data having been transferred. That 6-year-old laptop was on its last legs, anyhow, maybe.
For future reference, as I have a 4-year-old desktop, and for others here, I would like to know what makes the Geek Squad not trustworthy. It was his decision (not mine - heh, heh) to go there...
Again, thanks!
Margaret | I don't think not trustworthy is the word - and I realize that it was my "misspeaking" that caused that. I have just found that they are no smarter than instructions you can find online (or a good computer geek friend) and they are expensive.
But then again, I pay people to do things around my house (like change out a ceiling fan) that I have no knowledge of absolutely no interest to learn how to do, and I am sure that many here can do!
If the laptop was 6 years old, you really have not lost much. That is really old in computer years.
| | The Following User Says Thank You to fredtgreco For This Useful Post: | | 
12-06-2008, 11:06 AM
|  | Puritanboard Graduate | | Join Date: Feb 2008 Location: Michigan
Posts: 3,424
Thanks: 1,963
Thanked 1,062 Times in 600 Posts
| | Quote:
Originally Posted by fredtgreco
But then again, I pay people to do things around my house (like change out a ceiling fan) that I have no knowledge of absolutely no interest to learn how to do, and I am sure that many here can do!
If the laptop was 6 years old, you really have not lost much. That is really old in computer years. | Hey - change a ceiling fan??? That's definitely, without a doubt, a job for a professional! No way would I do that myself!  I am not being facetious; I'm serious. One needs that done right so that no annoying noises emanate from it during operation...
Yeah, I think he did get as much as he could out of that laptop. I'm glad to see it gone; it was an irritant to me... (Just the way that it was acquired.) I'm going invoke the "don't diss your spouse" clause that's necessary to being a good Christian wife -- and shut up now...
Thanks.
Margaret
| 
12-06-2008, 11:15 AM
|  | Puritanboard Freshman | | Join Date: May 2008 Location: Currently reside in Knoxville TN
Posts: 318
Thanks: 104
Thanked 103 Times in 62 Posts
| |
The best piggy-back trojan remover that i know of is Hijack This. For everything else i use Spybot and Ad-Aware.
**Pastor Greco beat me to it, so I second his recommendations**
__________________ Flavio
Particular Baptist, 1644er
Visiting churches
Bond servant of my Lord Jesus
Husband to Hanna, father to Nathan, Chloe, Caleb, & Lily | | The Following User Says Thank You to PactumServa72 For This Useful Post: | | 
12-06-2008, 11:58 AM
|  | Megerator | | Join Date: Jan 2004 Location: Portland,OR
Posts: 10,723
Thanks: 1,738
Thanked 953 Times in 794 Posts
| | |
If you see this on a macbook, I read a forum that says to use Finder to find all the .exe files that go with it, drag them to the trashcan, and empty the trash.
|  | | Thread Tools | | | | Display Modes | Linear Mode |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | |