Computing.Net > Forums > Security and Virus > worm/trojan problem?

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

worm/trojan problem?

Reply to Message Icon

Original Message
Name: JD
Date: September 20, 2002 at 23:37:50 Pacific
Subject: worm/trojan problem?
OS: Win ME
CPU/Ram: Pentium 300 mhz/64 megs
Comment:

I am having some very aggravating problem in which my isp dial up screen automatically chooses to pop up on the screen and insist on dialing up to connect all the time even when I reboot and start the computer. Whenever I click on cancel to close it and make it go away it always pops back up and starts to dial up automatically to connect. Nothing I've tried has helped to correct this. I've tried to uninstall the isp software so I could try reinstalling it, but it won't allow me to reinstall while that is open and running. I've tried using the WinME system restore, but that won't work. I have a firewall that I run when I'm connected and I also have an anti-virus program as well as an anti-trojan software program that I run. My AV software doesn't detect anything and the only thing my anti-trojan program has reported is when I do a scan it gives me an alert message in the results that says it has "...found that C:\Windows\Temp\A32-17.EXE is Win32.Hybris.B worm. Not restored." I also checked that folder and I could not find that file visible even when I chose the option to "show all hidden folders and files". I read that that worm is a worm that is spread via e-mail which apparrently intercepts outgoing e-mail. I use hotmail, which I've been getting a lot of junk and spam mail now. Now that though doesn't seem to me to be related to this other aggravating problem of mine in which my isp always tries to dial up all the time by itself, indicating trojan like activity. When I let it connect before, I got an alert from my firewall saying that my isp(AT&T) wanted permission to access the Internet. The alert identified my isp by name, however, before this problem my firewall would identify certain reconizable services relating to AT&T as wanting access, but never the name of the isp itself. I denied it access through the firewall, yet I was still able to get online. If that had really been my isp asking for access then it logically follows that I wouldn't have been able to get online after I denied it. There was another unrecognizable thing asking for access called "service.exe", which is residing within my "C:\Windows\System" folder. I denied that access as well. I couldn't get rid of that file from that folder because it says it is in use by the operating system. It used to be that my isp dial up screen would only pop up when I clicked on its icon or when I opened internet explorer it would pop up to dial up automatically, but now it does it all the time even when I want to stay offline. It doesn't go away. I'm getting this strange activity and I'm afraid I acquired some worm or trojan, something like that that someone might be using to remotely access my computer. Well, I know this was a long and drawn out posting. I hope someone can help me here. I'd appreciate it.


Report Offensive Message For Removal


Response Number 1
Name: capt
Date: September 21, 2002 at 07:00:42 Pacific
Reply: (edit)

The good news is that your problem is not damaging. It has made, or tried to make you a pest to your friends. If you go to the Trend Micro website your problem is listed in their virus definitions, and how to remove it from your system. You can also use their free on-line antivirus scan to make sure your system is clean. All the best!


Report Offensive Follow Up For Removal

Response Number 2
Name: Norm
Date: September 21, 2002 at 19:41:14 Pacific
Reply: (edit)

Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software