Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I ran my weekly ad-aware scan, spy bot S&D and AVG anti virus scan. My question is this: The ad-aware and AVG virus scan found 3 files infected with the secthought.e trojan horse. The AVG anti virus program cannot clean the infected files. I have since put them into the VIRUS VAULT. I see that the path of these files are C:\Documents and Settings\OWNER\local settings\Temporary Internet Files\CONTENT.IE5\53PP55UR\install035[1].exe
All three files are slightly different at the end with their numbers.
I am just wondering if I can just delete these files from the AVG VIRUS VAULT without hurting my system since they are in the temporary internet file path.
Any help or thoughts would be greatly appreciated. Thanks, RonHello, I ran my weekly ad-aware scan, spy bot S&D and AVG anti virus scan. My question is this: The ad-aware and AVG virus scan found 3 files infected with the secthought.e trojan horse. The AVG anti

Download spywareblaster , it will remove the script prompts.
http://www.javacoolsoftware.com/spywareblaster.html

Johnw,
Thanks for the response. I will give the spyware blaster a try.
Do I need to restore the files from the virus vault prior to running spyware balster or just leave them in the vault?
Thanks again, RonHello, I ran my weekly ad-aware scan, spy bot S&D and AVG anti virus scan. My question is this: The ad-aware and AVG virus scan found 3 files infected with the secthought.e trojan horse. The AVG anti

Don't know for sure , I would leave them in the vault & then remove after installing Spyware Blaster .
=========================================
Remove Spyfiles by using these 6 programs .
Make sure you use the SpyBot/SpywareBlaster/Ad-aware/Bazooka/Swat It > Online > Update button regularly .SpyBot
http://beam.to/spybotsd
http://www.spybot.us/spybotsd13.exe
http://majorgeeks.com/download2471.html
1st step , Choose your Mode ( at the top of screen )
Mode > Advanced ( if you want to have more options )
Editor's Note: The Resident shield in version 1.3 has an issue allowing certain cookies (Specifically Double Click)when set to notify. If page loading becomes a problem, right click the icon in the Systray, select “Resident IE” and either uncheck “Use Resident in IE sessions” or check "Block all bad pages silently".
Once you have the program installed , open SpyBot and select the "Immunize" icon on the left & Click on Immunize , in the new page .
Permanently running bad download blocker for Internet Explorer .
Select > Block all bad pages silently & click Install .
Then check the box "lock hosts file read-only as protection against hijackers".
Select your download site .
Open Spybot Search and Destroy. After clicking the button that says "Search for Updates" & the check is finished , you will see 5 items near the top of the window, "Search for Updates", "Download Updates", UniDo(Europe), "Show Log" and "Help". Next to UniDo(Europe) you will see a "down" arrow. Click the "down" arrow and you will see download site choices (3 in Europe, 1 in USA and 1 in Australia). Right click on your selection to make it default .
A Beginner's Guide to Spybot
http://www.trincoll.edu/depts/cc/documentation/security/spyware/Spybot_guide.htmSpyBot lock host files greyed out
If it doesn't have a hosts file you cant lock it, so that tweak will be grayed out.
Have SpyBot install its hosts file.
http://www.zerosrealm.com/immunizing.php
Note: For those running in "Basic" mode ( version 1.2 ) you will NOT see this. You must be running in Advanced mode! To get in advanced mode, a really easy way is to go to Start >> All Programs >> Spybot Search and Destroy >> Spybot Search and Destroy (advanced). Click it. You are now in advanced mode.
Select your download site .
Open Spybot Search and Destroy. After clicking the button that says "Search for Updates" & the check is finished , you will see 5 items near the top of the window, "Search for Updates", "Download Updates", UniDo(Europe), "Show Log" and "Help". Next to UniDo(Europe) you will see a "down" arrow. Click the "down" arrow and you will see download site choices (3 in Europe, 1 in USA and 1 in Australia). Right click on your selection to make it default .SpywareBlaster
http://www.wilderssecurity.net/spywareblaster.html
SpywareBlaster doesn't scan and clean for spyware - it prevents it from ever being installed.
FreewareSpywareGuard
http://www.javacoolsoftware.com/spywareguard.html
SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method. An anti-virus program scans files before you open them and prevents execution if a virus is detected - SpywareGuard does the same thing, but for spyware! And you can easily have an anti-virus program running alongside SpywareGuard.Ad-aware
http://www.lavasoft.de/
http://www.lavasoftusa.com/
All software offered on this page is free* to download and use and compatible with Windows 98/ME/NT40, Windows 2000 and Windows XP Home and Professional.
Download sites .
http://download.com.com/3000-2144-10045910.html?part=69274&subj=dlpage&tag=button
http://majorgeeks.com/download.php?det=506Bazooka
http://www.webgrid.co.uk/security_2.html
http://www.winsite.com/bin/Info?17000000037943
http://www.kephyr.com/
Here is the current list of Bazooka fixes .
http://www.kephyr.com/spywarescanner/library/index.phtml?source=appvisit
Bazooka is freeware and Windows 95/98/ME/NT/2000/XP compatible
Click on the files found & you will be taken to a site that will show you how to remove , either with a program or manually .
It reports on all drives & partitions , so remember to check all these , when doing manual remove .
After the Download - It is important to remember that once the installation of Bazooka is completed , that you should update the File Signatures by clicking on the Update tab and check for an update .
Make sure you Update after installing & then regularly .Swat It
http://swatit.org/
Swat It is a Completely FREE program that scans your files for Trojans, Worms, Bots and other Hacker programs. Swat It can detect and remove over 4000 different Trojan programs plus variants. Swat It was recently independently tested against popular commercial scanning software and we were absolutely delighted by the results.
After the Download - It is important to remember that once the installation of Swat It is completed, that you should update the File Signatures by clicking on the Update tab and check for an update. All Product and File Signature Updates are Totally FREE, this means that you will never have to pay a single penny to get the very latest version of Swat It or to update the File Signatures.List of fake spyware removers
http://www.netrn.net/archives2/000550.html
Beware of SpyHunter
http://www.post-gazette.com/pg/03289/231446.stm

Johnw,
Thanks so much for your response and obvious wealth of information.I have downloaded the spyware blaster, spybot, spywareguard. I deleted those trojan infected files that I had in my virus vault.
Everything seems to be working fine. I may have to download that SWATIT program as well if I continue to get the trojans.
Do you think it is possible to have too much protection on the computer where some programs may repeat what others do?
I'll check back later today as right now I must get ready for church. Thanks again for all your help. It is greatly appreciated. Ron
Hello, I ran my weekly ad-aware scan, spy bot S&D and AVG anti virus scan. My question is this: The ad-aware and AVG virus scan found 3 files infected with the secthought.e trojan horse. The AVG anti

Hi Ron:
I also use the programs recommended by JohnW., good advice there for sure. If you keep getting trojans, rather than running for SWATIt every tiime, you might want ot consider that either your XP fireaal settins ned to be upgraded, ro you need to disable it, and download a good firewall:
Free Sygate firewall:
http://smb.sygate.com/products/spf_standard.htmI use that one, I am very satisfied with it. I used free Zone Alarm before and I like this one better--my preference for a lot of little reasons.
Also, if these troijans come back, it is probably going to be because they are in your system restore files--a common problem for us Me or Xp users. If that is the case go here:
http://download.nai.com/products/mcafee-avert/SystemHelpDocs/DisableSysRestore.htm
You will lose your restore dates but it is the only way to get bugs out of your system restore files, which cannot be moved to a vault.
When I have had bugs that were 'vaultable' I always made sure I had those vaulted files backed up before I deleted them from the vault, which is the safest thing to do.
Aslo I always run those scans and my updated AV and updated spybot and adaware from safe mode during a bug hunt, or even a suspected bug hunt. If they run clean in safe mode it is generally considered that you are clean. Running them from safe mode is relatively simple and risk-free.
If you are not aware of it--it helps to keep your TIF, %TEMP%, cookies and recycle bin clean, as well do your Disk Clean-up, Scan Disk, and defragmenter regularly.
As long as you are using Windows and IE, the first part of security is UPDATE and MAINTENANCE... update Windows, XP, IE, Outlook (even if you don't use Outlook--if it's there update it)., your AV, spybot, adaware (every three days), etc.
Here ae some free tools to check your browser integrity:
Jason’s Browser Security Test:
http://www.jasons-toolbox.com/BrowserSecurity/Gibson tests:
http://www.grc.com/default.htm
I use LeakTest, DCOMbobulator, ShieldsUp, and UnplugNprayThresher

Johnw and Thresher,
Thank you both for your very informative answers. You both have offered some great advice to this novice computer user.Thresher, you mention about the system restore files.
The files I had that were infected were temporary internet files according to the path file name.
Would you say they were safe to delete since when doing a clean up of the hard drive it gives amount of space to be freed up and most of that space is used by temp files?
Also they were recognized when I ran an ad-aware scan.
I then ran my updated AV scan and that also found them. I vaulted them from there and then posted my original question here.
I have since downloaded spybot, spyware blaster, spyware guard per Johnw advice and all seem to be working well.
I will have to keep you posted on any new events. Thanks again, Ron

Print these instructions and read first
Disconnect internet Access
Go to Programs\ Accessories\ system tools\ system restore\ System restore settings\ Clict turn off restore. ( The virus is also contained in the restore points Turning it off will delete all restore points thus deleting it from this location)
Go to Start/ Settings/ Control Panel/ Folder options/ View/ click on show hidden files and folders and display content of systen folders
Reboot your computer and rerun AVG
Go to the TEST RESULTS to find any virus located in this scan by choosing DETAIL
*** Go to Start and right click to open the menu -click Explore
Follow the path of each file, for exampleC:\Documents and Settings\*myusername*\Local Settings\Temporary Internet Files\Content.IES\HSPTJP57\install026[1].exe
you are looking for the file HSPTJP57 not the name of the virus.
once you've found it, just highlight this file and delete it. Do the same for the others...
OR, just go to the Start /Search /For Files or Folders option and type in the name of the file (NOT the name of the virus) but the actual name of the file - and delete the file from here
REBOOT your computer
Rerun AVG Go to Test Results to see if any are found. If so go back to the *** step and go thru each stem until clean test results.
Once clean Reboot
Go back and turn your System Restore back on.
Reconnect to the internet
YOU ARE CLEAN

![]() |
New MyDoom virus
|
norton antivirus pro 2004
|

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |