Hello! Log in or Register   |  Help  |  Donate  |  Buy Shirts See all banner ads | Advertise on TheSamba.com  
TheSamba.com
 
Computer Help: Trojan Horse removal
Page: 1, 2  Next
Forum Index -> Off Topic Share: Facebook Twitter
Reply to topic
Print View
Quick sort: Show newest posts on top | Show oldest posts on top View previous topic :: View next topic  
Author Message
scott s
Samba Member


Joined: January 04, 2005
Posts: 1122
Location: Rock Hell, SC
scott s is offline 

PostPosted: Sat Feb 07, 2009 6:37 am    Post subject: Computer Help: Trojan Horse removal Reply with quote

My girlfriends laptop has picked up a Trojan Horse. It initially popped up as a dialog box pop-up that said something like "Threat detected, Zafi.B Win32.Zafi.B" and asked you to enable protection. It was configured to look like a Windows Security Center warning. When she clicked on "enable protection" it took her to a site that tried to sell her an anti-virus program. She did not buy anything and closed the window.
When she went to AVG to see if it had found the Trojan threat, AVG would no longer open or operate. She had to uninstall and reinstall the AVG software (the free version). Windows Defender found nothing. I had her install AdAware and it has found it and quarantined it several times.
If she tries to remove the program (either from AdAware or AVG, can't remember which), it tells her " Forceable removal could cause system instability or crash".
Anytime Resident Shield (AVG) finds it she can "heal" it and it sends it to the Virus Vault, where it shows up as "Trojan Horse Generic 12.BJFK". It has been found in at least two different paths to file.
It continues to pop up on start up. What is this file? How can we find it and remove it permanently without damaging her computer.
She's running WindowsXP on a 4 year old HP laptop. She's using MSN/Internet Explorer as her browser. She has the free versions of AVG, AdAware and Windows Defender, all recently installed and updated. AVG seems to find it most regularly.
HELP! This thing is annoying and sneaky...
_________________
Nothing screams "poor workmanship" like wrinkles in the duct tape.
Back to top
View user's profile Send private message Send e-mail Gallery Classifieds Feedback
Glenn Premium Member
Mr. 010


Joined: December 25, 2001
Posts: 76884
Location: Sneaking up behind you
Glenn is offline 

PostPosted: Sat Feb 07, 2009 6:40 am    Post subject: Reply with quote

Even after removing a virus, i've never seen a PC behave normally.

I suggest you backup her data, format the drive and reload. After 4 years the PC will run faster anyway.
_________________
Glenn
74 Beetle Specs | 74 Beetle Restoration | 2180cc Engine
"You may not get what you pay for, but you always pay for what you get"

Member #1009

#BlueSquare
Back to top
View user's profile Send private message Send e-mail Visit poster's website Gallery Classifieds Feedback
insanitize
Samba Member


Joined: December 01, 2003
Posts: 138
Location: Queens, NY
insanitize is offline 

PostPosted: Sat Feb 07, 2009 6:52 am    Post subject: Reply with quote

I used malwarebytes to remove this from my daughters and a few other pcs.
It is a free download from thier site.
malwarebyte.org
Back to top
View user's profile Send private message AIM Address Gallery Classifieds Feedback
myk648
Samba Member


Joined: November 12, 2002
Posts: 550
Location: Xenia, Ohio
myk648 is offline 

PostPosted: Sat Feb 07, 2009 6:59 am    Post subject: Reply with quote

I would wipe it clean and reload. Like Glenn said, after 4 years it will probably run better with a fresh start.
Back to top
View user's profile Send private message Send e-mail Gallery Classifieds Feedback
MrBreeze
Samba Hitman


Joined: October 06, 2002
Posts: 5535
Location: Lawn Guyland, Noo Yawk
MrBreeze is offline 

PostPosted: Sat Feb 07, 2009 7:02 am    Post subject: Reply with quote

I agree with both.....after 4 years a rebuild would be a good idea. I had this same virus and malwarebytes did the trick for me as well.
_________________
-=Rob

WTB: Bay Shore or Queensboro VW Frames

HBB 1984-2009
RW 1943-2011
ER 1964-2023
Back to top
View user's profile Send private message Gallery Classifieds Feedback
scott s
Samba Member


Joined: January 04, 2005
Posts: 1122
Location: Rock Hell, SC
scott s is offline 

PostPosted: Sat Feb 07, 2009 7:17 am    Post subject: Reply with quote

Will do the Malware deal...
I know just enough about computers to really screw one up. Can you guys talk me through the formatting and rebuild/reboot process in a way that an idiot can understand and won't destroy her computer?
_________________
Nothing screams "poor workmanship" like wrinkles in the duct tape.
Back to top
View user's profile Send private message Send e-mail Gallery Classifieds Feedback
ChesterKV
Samba Member


Joined: February 07, 2005
Posts: 1725
Location: El Cerrito, CA
ChesterKV is offline 

PostPosted: Sat Feb 07, 2009 8:59 am    Post subject: Reply with quote

scott s wrote:
Will do the Malware deal...
I know just enough about computers to really screw one up. Can you guys talk me through the formatting and rebuild/reboot process in a way that an idiot can understand and won't destroy her computer?


You would be WAY better off helping your girlfriend to buy a new/used computer. I'm totally serious.



- Chester
_________________
1984 Wolfsburg 7-passenger stock sunroof
1992 Subaru Legacy EJ22 boxer motor installed.... van is now sold.... currently playing with a 1987 Toyota MR2 with 1.6 liter twin-cam motor. Better than the Subaru boxers....... I'm impressed. Well, okay, in an "apples and oranges" kind of way. Smile
Back to top
View user's profile Send private message Classifieds Feedback
scott s
Samba Member


Joined: January 04, 2005
Posts: 1122
Location: Rock Hell, SC
scott s is offline 

PostPosted: Sat Feb 07, 2009 9:35 am    Post subject: Reply with quote

Well, until that time....any advice on reload/reboot?

The Malware program found 11 items and removed them. So far, so good....
_________________
Nothing screams "poor workmanship" like wrinkles in the duct tape.
Back to top
View user's profile Send private message Send e-mail Gallery Classifieds Feedback
SkrapMetal
Samba Hornblaster


Joined: January 18, 2006
Posts: 2558
Location: Dallas, TX
SkrapMetal is offline 

PostPosted: Sat Feb 07, 2009 10:59 am    Post subject: Reply with quote

Before you start its a good idea to Download Ccleaner and run it. You can also run it in safe mode.

Download Spybot Search and destroy, then reboot computer into safe mode. Update and run spybot.

Another good program to have is HijackThis. There is actually a forum to post what it finds in case you don't know what you're doing.

Having AVG, spybot, and ad-aware, I've not had a problem with anything getting in.
_________________
oo9less since 2007
-72 Ghia-
Back to top
View user's profile Send private message Gallery Classifieds Feedback
90volts
Samba Member


Joined: August 10, 2005
Posts: 2637

90volts is offline 

PostPosted: Sat Feb 07, 2009 11:04 am    Post subject: Reply with quote

def vote for the reformat like Glenn and others said. PCs never seem to go back to normal even after removal... they touch so many files it messes something up that gets missed.

easiest way to format would be if you have the original system disk that came with the pc. put it in and run it and it should offer options, one of which will be to reformat.

best case for a computer that old would be get a new one if you can though. 4 years is a long time in comouter years. laptops for under 600 bucks and desktops for around 300.
Back to top
View user's profile Send private message Gallery Classifieds Feedback
realbugfanatic
Samba Member


Joined: May 03, 2006
Posts: 484
Location: SW Michigan
realbugfanatic is offline 

PostPosted: Sat Feb 07, 2009 5:44 pm    Post subject: Reply with quote

Before you do anything, go to this place & download the free version & run it. Stupid name but check them out on the web, they work wonders.

http://www.superantispyware.com
_________________
1973 Super
Back to top
View user's profile Send private message Gallery Classifieds Feedback
71Super4Rio
Samba Member


Joined: March 27, 2004
Posts: 76
Location: Hickory, NC
71Super4Rio is offline 

PostPosted: Sat Feb 07, 2009 9:21 pm    Post subject: Reply with quote

I used this for my daughter's laptop when she downloaded the same thing.

In case some links don't work, please paste them manually into the address bar of your browser.

Here you go!!!!....
1) Turn off System Restore (Using XP? Click on the link below:
http://support.microsoft.com/kb/310405

Using Vista? Click on the link below:
http://windowshelp.microsoft.com/Windows/en-US/Hel...mspx#ENBAC

2) Disable all Startup Items and go to Services Tab, put a check into "Hide all Microsoft Services" and then click disabled all and then "Apply, "Ok", "Exit without Restart" (and also uninstall wanted applications)

In case anybody would like to know how to enable/disable Startup Items or Services then click on the link below:
http://support.microsoft.com/kb/950093/en-us

3) Shut down the system & restart in Safe Mode, plain Safe Mode.

4) Download and run Trojan Remover from the link given below:
http://www.gur.in/j/index.php?option=com_docman&Itemid=58&task=doc_download&gid=29

In case Trojan Remover won't be able to access/ remove some files, it will give you the option to fix issue at next reboot, so remember to check that option

5) Download & run MalwareBytes from the link given below:
http://www.gur.in/j/index.php?option=com_docman&Itemid=58&task=doc_download&gid=97

6) Download and run CCleaner from the link give below and run the regfix part of it for sure and fix all issues and I would run the cleaner part as well just to ensure MalwareBytes finishes fast.
http://www.filehippo.com/download/file/5be3ada3bcf...8d1e5907d/

7) Repeat Step 4-6

Cool Reboot to Normal Mode

9) Repeat Step 4-6

10) Run Avira Antivir from www.free.av.com and will take care of most of the Trojan Droppers left in the system

11) Run CCleaner again and that will remove the Startup Item for that as well in case its left

12) Run Avira Antivir a couple of times more just to be sure

13) Reboot the machine and remove all Tools that you downloaded and installed, I would keep Avira & remove the rest

14) Reboot the machine and run Disk Cleanup from "Accessories" > "System Tools" and un-check compress old files and Office Setup files (If using any MS Office Programs) and Delete all others

15) Enable System Restore & create Restore Point manually

16) For future, install a good Internet Security Application which has a good Real-Time protections module and never use Multiple Internet Security Applications (I use Avira Antivir Premium
_________________
Aut Inveniam Viam Aut Faciam - "I shall either find a way or make one"

"It takes many years and experiance for a man to get comfortable in his own skin."
Back to top
View user's profile Send private message Send e-mail Facebook Gallery Classifieds Feedback
ArmedGeek
Samba Member


Joined: May 13, 2008
Posts: 47
Location: Mont Belvieu, Texas
ArmedGeek is offline 

PostPosted: Sat Feb 07, 2009 9:43 pm    Post subject: Reply with quote

O.M.G. Generally not a good idea to ask computer advice of a bunch of car guys.

Glenn is right tho. reformat/reinstall. that is the *only* way. Once a machine has been infected it cannot be trusted.

And about half of the suggested "fixes" are crapware/adware thats damn near as bad as the malware itself.
_________________
1973 Std Beetle
"Work is punishment for failing to procrastinate effectively."
Back to top
View user's profile Send private message Yahoo Messenger Classifieds Feedback
SkrapMetal
Samba Hornblaster


Joined: January 18, 2006
Posts: 2558
Location: Dallas, TX
SkrapMetal is offline 

PostPosted: Sun Feb 08, 2009 8:47 am    Post subject: Reply with quote

ArmedGeek wrote:
O.M.G. Generally not a good idea to ask computer advice of a bunch of car guys.


Why not? Working on a computer is similar to working on the car, without the grease and oil.

I'm a technician, and I've found that hiring assistants with some automotive knowledge have more of a clue as to what they're doing.
_________________
oo9less since 2007
-72 Ghia-
Back to top
View user's profile Send private message Gallery Classifieds Feedback
Russ Wolfe
Samba Member


Joined: October 08, 2004
Posts: 25187
Location: Central Iowa
Russ Wolfe is offline 

PostPosted: Sun Feb 08, 2009 8:56 am    Post subject: Reply with quote

How about just installing Linux, and then never run online as "root".
No more virus's or malware.
If you do have a problem, it is with just one user, not they whole system.
All the software is free, and does not cost 100's of dollars.
_________________
Society is like stew. If you don't keep it stirred up, you end up with a lot of scum on the top!--Edward Abbey

Gary: OK. Ima poop.
Back to top
View user's profile Send private message Visit poster's website Gallery Classifieds Feedback
VWSwap
Samba Sublime Fan


Joined: April 22, 2003
Posts: 1125
Location: Nor Kizzle
VWSwap is offline 

PostPosted: Sun Feb 08, 2009 10:47 am    Post subject: Reply with quote

Welcome to the world of tapping the "F8" key when booting the computer.

Reformat it and re-install all of the software. All existing files and documents should be intact, but who knows.

Trojans can be a real bitch, and getting rid of them is sometimes impossible.
_________________
Like us on Facebook! http://www.facebook.com/MotherLodeVWClub
Camping & lodging information in Calaveras County is at http://www.gocalaveras.com
Back to top
View user's profile Send private message Gallery Classifieds Feedback
JiI
Samba Member


Joined: February 18, 2006
Posts: 1844
Location: Michigan
JiI is offline 

PostPosted: Mon Feb 09, 2009 9:09 pm    Post subject: Reply with quote

I have something adding all kinds of bookmarks/ favorites to my list. Insurance, porn, surveys, ads, shopping stuff etc... Any way I can stop that?
Jeff
Back to top
View user's profile Send private message Send e-mail Gallery Classifieds Feedback
dlandvw3
Samba Member


Joined: June 22, 2006
Posts: 106
Location: Warner Robins, GA
dlandvw3 is offline 

PostPosted: Mon Feb 09, 2009 9:42 pm    Post subject: Reply with quote

Reformatting is not really necessary. If you stick to good, legit, programs, that aren't trying to sell you something, they work wonders. Malwarebytes.org program Malwarebytes Anti-Malware is fantastic, and free, truly free, not shareware, and it's run by a great group of tech geeks who really know their stuff.

Another user mentioned Avira. www.avira.com That's another fantastic resource.

The free programs available on both of those websites are better than any commercially available programs out there, and they aren't bloated with crapware or whatever someone else called it.

On the Avira website, if you'll click on downloads, then down under tools, there are several really good specific removal tools that work for most trojans out there. It has a nice free registry repair tool, a very good rescue cd in case you can't boot into windows. It's a linux based repair cd that runs antimalware program on the computer. I've used it many times to fix pc's that most would think unrepairable. There's also a really good bootsektor removal kit, etc.

I use these every day, I remove viruses every day, and they both work.
_________________
We don't believe any VW is too far gone to be saved, and we feel the same about people...no one is too far gone to be saved

http://www.facebook.com/bugs4christ
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger Facebook Gallery Classifieds Feedback
realbugfanatic
Samba Member


Joined: May 03, 2006
Posts: 484
Location: SW Michigan
realbugfanatic is offline 

PostPosted: Tue Feb 10, 2009 5:42 am    Post subject: Reply with quote

JiI wrote:
I have something adding all kinds of bookmarks/ favorites to my list. Insurance, porn, surveys, ads, shopping stuff etc... Any way I can stop that?
Jeff


ArmedGeek wrote:
O.M.G. Generally not a good idea to ask computer advice of a bunch of car guys.

Glenn is right tho. reformat/reinstall. that is the *only* way. Once a machine has been infected it cannot be trusted.

And about half of the suggested "fixes" are crapware/adware thats damn near as bad as the malware itself.


I'm tellin ya, I've been down this road a few times. You guys can keep guessing on what might or might not work, whether you need to reformat or not, and download some crap that's only marginally better than your current problem. But for those 'in the know', they download the free version of superantispyware. Like I said, stupid name, but once you use it you'll be able to put the box of Kleenex away.

http://www.superantispyware.com
_________________
1973 Super
Back to top
View user's profile Send private message Gallery Classifieds Feedback
Behemoth
Samba Member


Joined: September 02, 2003
Posts: 389
Location: Lenoir NC
Behemoth is offline 

PostPosted: Tue Feb 10, 2009 6:23 am    Post subject: Reply with quote

Some pretty good advice given here from reformatting to Malwarebytes but the most pertinent I saw was the the turning off of the system restore as it'll hold everything you're trying to get rid of no matter what you run. Just be sure to turn it back on after everything is working right again.
_________________
63SunNotch...."Don't qoute me on it but I am pretty good when it comes to tits.
Been sucking on them since I was a baby. "
vdubmax..."I thought we were friends. I will be by to drop off your recently fucked up parts next weekend fool"
Back to top
View user's profile Send private message Gallery Classifieds Feedback
Display posts from previous:   
Reply to topic    Forum Index -> Off Topic All times are Mountain Standard Time/Pacific Daylight Savings Time
Page: 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

About | Help! | Advertise | Donate | Premium Membership | Privacy/Terms of Use | Contact Us | Site Map
Copyright © 1996-2023, Everett Barnes. All Rights Reserved.
Not affiliated with or sponsored by Volkswagen of America | Forum powered by phpBB
Links to eBay or other vendor sites may be affiliate links where the site receives compensation.