Computing.Net > Forums > Security and Virus > Trojans, etc....

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Trojans, etc....

Reply to Message Icon

Name: Jodie Edroff
Date: June 7, 2005 at 15:21:15 Pacific
OS: Windows ME
CPU/Ram: 1GHz/256MB PC 133 SDRAM
Comment:

Hello Everyone,
It has been awhile since my last visit, but here I am again needing help.
I switched from my NAV(2002)to the antivirus that my internet provider provides, which is F-Secure. Reason being, I had to do a system restore because the Adobe Acrobat Reader I was attemting to download screrwed up my computer with some malicious code. Anyway, after the system restore, my NAV data engine went could not be found. I tried undoing the system restore, but NAV was no longer usable.
My computer has been acting strange ever since - F-Secure is a real resource hog.......
Anyway, when I looked under its Firewall under "Services" I found these:
Description: Acid Shivers
In Use: Yes
Rule Name: Deny & alert about malicious inbound probe

Description: Back Orifice RAT
In Use: Yes
Rule Name: Deny & alert about malicious inbound probe.
There were other trojans listed, but not as "In Use", so I don't know what to think about those.
Also, while I was surfing the web today, F-Secure popped up and said that "trojan.downloader.JS.IstBar.j" had been found in my computer system, so I told it to remove it for me. End result, nothing happened to it. And I don't know where to find it either.....
I am sorry this is so long, but I almost forgot to mention that a little black crow looking thing has showed up on the right side of my taskbar with the sound controls.... I have no idea what program/application that is a part of, but I don't think it has anything to do with F-Secure or any other program I knowingly installed on my computer :o(
If anyone can offer some insight in these matters, it would be kindly appreciated.
Thanks again,
Jodie



Sponsored Link
Ads by Google

Response Number 1
Name: suspect52732
Date: June 8, 2005 at 10:59:25 Pacific
Reply:

Ok I will yet again run through the basics of securing a pc. Please take the time to read this as I will spend some time writing it.

First off, a note about the programs/virus/spyware thats appearing. Back Orifice was create many a years ago, it was (i think) one of the original remote administration tool (hence name, RAT) It is used to remotly control a computer. This program is ancient now, as is its competitor, NetBus. Some script kiddies still try to utilize them but they are a million years old in PC years, and ANY antivirus should pick them up, if it doesnt pick it up, then the anti-virus is garbage because these programs are so old.

Ok, second part, the trojan.downloader.JS.IstBar.j is a javascript exploit that was created to exploit internet explorer, you will fall victim to this if your pc is not up-to-date. So, your obviously not keeping up on windows updates. Basically, it is written for a website, and will overflow something in IE and allow a program to be installed in your computer. In this case a trojan downloader. This programs job is to dial home, find a whole list of nasty programs and download/install them to your machine. The worst part about this program is that it can change rapidly. Because it can download anything it wants, it can also install anything it wants. This one in paticular is extremly difficult to remove. Follow everything I say below and you should be ok.


First off update windows, there is no reason at all not to. This is essential to prevent further security flaws. Keep it up-to-date! To update windows goto start button-->control panel-->then click windows update.


Ok once updates are done, you will need to install some programs to secure your pc, and if your lucky you can still get rid of those nasty programs.


Download, install, update, and run the following programs. All are free and are available from www.freeware.com


AdAware

SpyBot search and destroy

AVG Antivirus

Zone Alarm firewall

SpyWare Blaster

Microsoft AntiSpyware (have to get this from microsoft website, google search for it, it will come up)

These programs should locate a bunch of spyware and garbage on your pc. Once you have downloaded them, installed them, updated them, and ran them, you can then download this tool also from freeware.com

Startup Control Panel

It installs to the control panel. To locate it after install goto start button-->control panel-->startup icon.

Disable everything that you dont recognize, this program will prevent other programs from booting when your pc starts.

Then simply reboot, and you should be good to go. Let me know if you need additional help, or if this works for you. Good luck :)


PS I reccommend you get rid of that F-Secure after installing this stuff.



0

Response Number 2
Name: Jodie Edroff
Date: July 26, 2005 at 10:44:07 Pacific
Reply:

Thanks for taking the time to reply to my post. I really appreciate it :o)
I had the opportunity to wipe my system clean and put a different OS on my computer - I had lots of corrupted files.
I now have XP & think it's awsome!
I got rid of F-Secure and now have AVG 7.0. I do not have Spybot Search & Destroy,ZoneAlarm,Spyware Blaster,or Microsoft AntiSpyware yet, but will go check them out for sure!
Thanks again for your help. It was very nice of you ;oD


0

Sponsored Link
Ads by Google
Reply to Message Icon

Related Posts

See More


Firefox security hole IE vulnerability.What el...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Trojans, etc....

Best Virus, Trojan etc scanners www.computing.net/answers/security/best-virus-trojan-etc-scanners/4943.html

Dyfica.H trojan ????? www.computing.net/answers/security/dyficah-trojan-/8839.html

Please help! viruses, trojans, etc www.computing.net/answers/security/please-help-viruses-trojans-etc/21131.html