Computing.Net > Forums > Windows Me > trojen viruses keep coming back

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

trojen viruses keep coming back

Reply to Message Icon

Original Message
Name: ada1984
Date: November 24, 2004 at 16:55:38 Pacific
Subject: trojen viruses keep coming back
OS: Windows Me
CPU/Ram: N/A
Comment:

I don't get this. Some stupid website, No it was not a porn or warez website planted Trojen Viruses. And a dialer which dialed out without me knowing, to probably something that will end up showing on the bill. I use DSL but had the 56k modem hooked up to the jack. I run AVG Pro and Ad-ware Pro they get rid of everything and the computer is clean, but than a few minutes later everything to trojen horse viruese and dialers and adware is all back and planets in the system restore which I keep on dissabling. If it gets rid of all the viruses, I don't get how it comes back. I used cwsherdder and did not find anything...Let m e know....Adam


Report Offensive Message For Removal


Response Number 1
Name: capt
Date: November 24, 2004 at 20:55:14 Pacific
Reply: (edit)

What firewall do you use? When you turn system restore off, do you restart the computer and run all your scans before you turn it back on?


Report Offensive Follow Up For Removal

Response Number 2
Name: ada1984
Date: November 24, 2004 at 22:31:13 Pacific
Reply: (edit)

Yes I restart the computer after dissabling and enabling system restore. AVG deletes all the Trojen Viruses, and dialers and Ad-ware deletes all the mallware, hijacks Etc. I don't get how they come back. Does Internet Exporer send a signal to attacker's server and plants viruses to my computer, They come once every few mins to an hour, most of the time the same crap, and some different each time. What always happens is the porn dialer comes up and trys to connect, Avg finds it and deletes it, but comes back, I don't get it......Let me know.....


Report Offensive Follow Up For Removal

Response Number 3
Name: CrazyOne
Date: November 24, 2004 at 23:14:02 Pacific
Reply: (edit)

Adam,

As capt said/asked, do you use a firewall. If, and I do stress if, something is left on the computer. It will make "contact" as you said, and reinstall. Not the IE, per se, but, the trojan/virus/spyware/ect., ect.

What is being removed, by your AVG and AdAware? Names please, thanks.

Have you also cleaned your
c:\windows\temp (folder)
c:\windows\temporary internet files (folder)
c:\windows\cookies (folder)

Where does the AVG, say these things are, thanks.

Which IE version and updated versions, do you have. That's click the "Help" on the toolbar, and then "About Internet Explorer", thanks.

CrazyOne


Report Offensive Follow Up For Removal

Response Number 4
Name: ada1984
Date: November 25, 2004 at 02:53:53 Pacific
Reply: (edit)

Hello, I ended up formatting the hard drive and reinstalling windows. I don't have a firewall or know much about firewalls. Do they protect against viruses and ad-ware installing through a browser on a computer? I don't remember the names of the adware, I remember one was called Elite, which was a toolbar that kept on installing in Internet Explorer. The other was a trojen horse dialer that kept on popping up and dialing on it's own, others I can't remember. I don't pay attention except for getting rid of the junk. The Trojens were mostly in the WINDOWS directory. Adware was all over. I was using the version of Internet Explorer that comes with Windows ME. After reformatting I updated to the latest version. I think I'm going to start using netscape, from what I heard Netscape does not allow such files to be planted on a computer, I hope thats true.


I don't get why attackers plant such junk on peoples' computers. Like people are going to be intrested, expecially after it takes over their computer. Or it could be people getting a kick out of attacking peoples computers, Goes to show They have NO LIFE..


Report Offensive Follow Up For Removal

Response Number 5
Name: johnr
Date: November 25, 2004 at 03:32:58 Pacific
Reply: (edit)

A firewall stops your computer being accessed from outside, and stops programs already on your PC from accessing the internet without your knowledge (that's the way Trojans work). It's the same sort of minds which distribute viruses - it's the harmful graffiti of the PC world. Netscape/Firefox are certainly more secure than IE, but that's because they haven't been specifically targeted yet. You still need a firewall (Zone Alarm or Sygate are both free), regularly updated antivirus and Spyware tools (Spywareblaster, Adaware & Spybot as a minimum).

"I know that I'm mad - I've always been mad..."


Report Offensive Follow Up For Removal


Response Number 6
Name: CrazyOne
Date: November 25, 2004 at 04:12:25 Pacific
Reply: (edit)

Adam,

In your settings, of IE. Tools, Internet Options, Advanced (Tab)

Uncheck;
Enable Install On Demand

Turn off/disable these things, ok.

Tools, Internet Options, Security (Tab), Custom Level (button)

Now, disable all of the "ActiveX controls and plug-ins"

^^^Will need to enable some, to use the update site.

Java permisions, set to "High safety"

Installation of desktop items;
disable

Scripting, you should disable the.....

I guess, if your going to use an alternate browser, no need to go through all of this.

Good Luck,
CrazyOne

p.s. YES, and the security updates for the OS, browser, and any other program you're running. SHOULD/Must be installed.


Report Offensive Follow Up For Removal

Response Number 7
Name: ada1984
Date: November 25, 2004 at 05:46:53 Pacific
Reply: (edit)

I did some changes in the settings of the Internet Explorer. I downloaded ZonerAlarm. When it's running, I have to retype the user and passwords to log into forums, e-mail Etc. each visit. Is there a setting in ZonerAlarm to have it not load at windows startup, and use only when I go into un trusted sites? or how do most people run the program? Let me know....adam



Report Offensive Follow Up For Removal

Response Number 8
Name: ada1984
Date: November 25, 2004 at 05:48:30 Pacific
Reply: (edit)

I forgot to say I'm using the Trial version. If it's a good program, I'll buy it.......Adam


Report Offensive Follow Up For Removal

Response Number 9
Name: Adriel
Date: November 25, 2004 at 21:44:40 Pacific
Reply: (edit)

I Have the same problem as you, I run the antivirus and first it said remove then when I run again came back so I decide to find the file that was TEMP\Installer2.exe I did deleted I run it again now it said that is RESTORE\0012574.CPY and now it can't be remove even by my self named in both(Dopper Delf.3.L)Trojan. And now I can't make a Recovery check point either using the Recovery Disc I got to do it Manual a process that it takes me like a part of a day and I don't have time to safe all my programs in CD's. I need another way to get rid of this, without lossing all my saved programs.

thanks


Report Offensive Follow Up For Removal

Response Number 10
Name: ada1984
Date: November 26, 2004 at 01:55:51 Pacific
Reply: (edit)

Looks like you have a virus in the restore, to get of that, you right mouse click on my computer, click performance tab, click on, file system, click on troubleshooting, check box, disable system restore and that will delete everyting. Your computer will have to restart. do the same to enable it again....Adam


Report Offensive Follow Up For Removal

Response Number 11
Name: capt
Date: November 26, 2004 at 08:38:42 Pacific
Reply: (edit)

Adam, if you want to store your login passwords you need to set your privacy settings for cookies lower. I personally do not use the privacy feature of Zone Alarm pro. It is not one of the features of the free version. I think some people go a little overboard about tracking cookies, but you can control the ones for your trusted sites. You need the firewall turned on anytime you are connected to the internet. One study showed that you will be infected by a worm/trojan within 20 minutes if you are not protected by a firewall. My personal experience while installing XP was that I was infected in less than 3 minutes. Zone Alarm has a forum on how to set things up.


Report Offensive Follow Up For Removal

Response Number 12
Name: Adriel
Date: November 26, 2004 at 09:29:49 Pacific
Reply: (edit)

Alright Adam I did exactly all what you said. But I run the antivirus again and said "Virus detected" and this time he did remove the virus but what happends if he comes back ? also I try the Mcafee free scan and he didn't detected also the restore enable him self back.


Report Offensive Follow Up For Removal

Response Number 13
Name: Adriel
Date: November 26, 2004 at 09:46:23 Pacific
Reply: (edit)

I also forgot to said that my screen sometimes goes on blue with Error:0028:c02544A1 File Name: VXDLDR(OS)+00000EF9.


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows Me Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software