Shoutbox

They exist: I've got a trojan... - Printable Version

-Shoutbox (https://shoutbox.menthix.net)
+-- Forum: MsgHelp Archive (/forumdisplay.php?fid=58)
+--- Forum: Skype & Technology (/forumdisplay.php?fid=9)
+---- Forum: Tech Talk (/forumdisplay.php?fid=17)
+----- Thread: They exist: I've got a trojan... (/showthread.php?tid=77976)

They exist: I've got a trojan... by Rolando on 10-04-2007 at 09:25 PM

:(


AVG identifies it as Trojan Lop.D  .... and every time it deletes it it appears again after a while and warns me and asks me to delete it again.. It's always a different dll (different names), but it's always in WINDOWS's System 32 folder..

It turned System Restore off.........

I've tried Trend Micro, AVG, NOD32 .... and it takes long to scan and it does detect it I guess, but it comes back.

I don't know what to do.....................................


advice, please?


RE: They exist: I've got a trojan... by Oxy on 10-04-2007 at 09:59 PM

quote:
Originally posted by toddy
quote:
Originally posted by alex
quote:
Originally posted by Eljay
quote:
Originally posted by alex
Get a Mac.


* alex runs

buy me a Mac kao, you bitch. =[
One condition. Win the lottery and give the money to me. Then I'll buy you one.
time to play the lottery was last week !
Guys, in isnt T&T.

but, the only thing i can suggest is a google search on the trojan name and any recently installed programs to see if anyone else has had a similar problem.
RE: They exist: I've got a trojan... by Menthix on 10-04-2007 at 10:01 PM

Did you install the Plus sponsor?


RE: They exist: I've got a trojan... by Rolando on 10-04-2007 at 10:21 PM

No, it has nothing to do with Plus!..


RE: They exist: I've got a trojan... by Jarrod on 10-04-2007 at 10:30 PM

use avast boot scan pwns trojans:p


RE: They exist: I've got a trojan... by spongeboy on 10-05-2007 at 02:53 AM

That's what happened to me once. I had to get my computer reformatted because the virus just wasn't going away.

[EDIT] Have you updated all of your virus scanners? As new viruses keep coming around you must update your Anti-Virus in order for them to remove them properly.


RE: They exist: I've got a trojan... by Jarrod on 10-05-2007 at 05:24 AM

you don't remove the whole virus with windows based virus scanners, because some of the virus is running and normally won't be shutdown (the ppl who write viruses know this:p) so you have to use some thing to remove the viruses before the get to execute any code, so download an av that supports boot time scanning or download a live os and use it's interface to remove the virus, i recomend using an os with a virus scanner so you don't miss any files..

i remove viruses all the time for my stupid friends using the following method

download bartpe builder (www.nu2.nu/pebuilder/)
download the avast extention (http://www.avast.com/eng/avast_bart_cd.html)
make an iso
boot off your burnt iso
depending on when you made your iso update the virus defs. or not
scan and remove infected files
reboot into windows

[edit: missing word]


RE: They exist: I've got a trojan... by NiteMare on 10-05-2007 at 05:58 AM

you could try Stinger


RE: RE: They exist: I've got a trojan... by rav0 on 10-05-2007 at 06:02 AM

quote:
Originally posted by q25
No, it has nothing to do with Plus!..

It might. Lop is the Messenger Plus sponsor program.

About your antivirus, with system restore off, start Windows in safe mode, then run a scan and attempt removal. You have a better chance at successfully removing it from safe mode.
RE: They exist: I've got a trojan... by Jarrod on 10-06-2007 at 03:05 PM

or remove the adware sponsor:p


RE: They exist: I've got a trojan... by Nathan on 10-06-2007 at 03:35 PM

All Virus's are ment to do is infect your computer. It is their mission to mess up your pc e.g delete, edit, rename files, mess up system settings etc.
The people who create them try to make it undeleteable so they will make it duplicate itself and place it all over your computer. So what happens is you AV will delete it, but there will be another one on your pc somewhere else. So it will carry on duplicating itself.
Hope this make sense :P


RE: They exist: I've got a trojan... by Lourix on 10-06-2007 at 04:33 PM

It is important to note that a virus or Trojan cannot be spread without a human action, (such as running an infected program) to keep it going.  People continue the spread of a computer virus, mostly unknowingly, by sharing infecting files or sending e-mails with viruses as attachments in the e-mail.

Can you post the name of the virus and the infected files.


RE: They exist: I've got a trojan... by absorbation on 10-06-2007 at 04:55 PM

Lop isn't a trojan, it's adware. Most anti-virus software miss-label what kind of danger a file is.


RE: They exist: I've got a trojan... by Rolando on 10-06-2007 at 05:10 PM

You're all telling me stuff I already knew... I want to know how to get rid of it for once and for all..... not what it is, etc..


RE: They exist: I've got a trojan... by Jarrod on 10-06-2007 at 10:08 PM

quote:
Originally posted by xen0h
or remove the adware sponsor:p

use avast or bart PE
quote:
Originally posted by xen0h
you don't remove the whole virus with windows based virus scanners, because some of the virus is running and normally won't be shutdown (the ppl who write viruses know this:p) so you have to use some thing to remove the viruses before the get to execute any code, so download an av that supports boot time scanning or download a live os and use it's interface to remove the virus, i recomend using an os with a virus scanner so you don't miss any files..

i remove viruses all the time for my stupid friends using the following method

download bartpe builder (www.nu2.nu/pebuilder/)
download the avast extention (http://www.avast.com/eng/avast_bart_cd.html)
make an iso
boot off your burnt iso
depending on when you made your iso update the virus defs. or not
scan and remove infected files
reboot into windows


RE: They exist: I've got a trojan... by Dane on 10-06-2007 at 10:25 PM

Dane's Basic Virus Removing Procedure for Home Users:
Print this off for offline reference.

  • Turn off your computer.
  • Boot back up, but when you see the Windows Logo Screen, Enter safe mode (Hold F8 to get this option)
  • Log in as the affected user account (in Windows XP/Vista), Just ensure that you have administrative privileges.
  • Go to Start -> Run -> Type "msconfig" (in Windows XP), or press the Windows Logo Key + R (in Windows Vista)
  • Select "Selective Startup" on the General Tab, and then Press Apply/OK.  Select "Exit Without Restart".
  • Go to Start -> Run -> type "regedit" (in Windows XP), or press the Windows Logo Key + R (in Windows Vista)
  • Expand "HKEY_CURRENT_USER" -> "Software" -> "Microsoft" -> "Windows" -> "Current Version".
  • Select "Run" and on the right side, confirm that all the files you see are recognizeable.  Delete the ones that are not recognizeable.  If you see an EXE such as "fejgra.exe" or what appears to be random letters and ".exe", Delete that.  It is more than likely the virus.
  • Expand "HKEY_LOCAL_MACHINE" -> "Software" -> "Microsoft" -> "Windows" -> "Current Version".
  • Select "Run" and on the right side, confirm that all the files you see are recognizeable.  Delete the ones that are not recognizeable.  If you see an EXE such as "fejgra.exe" or what appears to be random letters and ".exe", Delete that.  It is more than likely the virus.
  • Go to "Start" -> "All Programs" -> "Startup" and Ensure any suspicious programs arent starting up from there.
  • When you have completed all of these tasks, reboot your computer.
  • Re-Run your Virus Scanner.  Or, if you want a third party opinion, Visit Symantec's Norton 2008 product line website.  It is the worlds most trusted antivirus solution.  There is a 15-day Trialware Option.
  • Remove any detections of viruses
  • Reboot your computer
  • Go to Start -> Run -> Type "msconfig" (in Windows XP), or press the Windows Logo Key + R (in Windows Vista)
  • Select "Normal Startup" on the General Tab, and then Press Apply/OK.  Select "Restart after Exit".

Let us know if this does it for you.
RE: They exist: I've got a trojan... by Jarrod on 10-06-2007 at 10:33 PM

send me your hard disk and i'll do it

quote:
Originally posted by xen0h


download bartpe builder (www.nu2.nu/pebuilder/)
download the avast extention (http://www.avast.com/eng/avast_bart_cd.html)
make an iso
boot off your burnt iso
depending on when you made your iso update the virus defs. or not
scan and remove infected files
reboot into windows

it has a regscanner as well and is worth knowing how to use

RE: They exist: I've got a trojan... by vikke on 10-06-2007 at 10:36 PM

It's the Messenger Plus! Sponsor program. To remove it, simply download and run this file:
http://cidhelp.com/new_uninstall.exe


RE: They exist: I've got a trojan... by NiteMare on 10-06-2007 at 10:44 PM

quote:
Originally posted by Dane
Boot back up, but when you see the Windows Logo Screen, Enter safe mode (Hold F8 to get this option)
its before the windows logo that you need to press F8
quote:
Originally posted by Dane


Select "Selective Startup" on the General Tab, and then Press Apply/OK.  Select "Exit Without Restart".
whats the point in that, selective start up is the exact same as normal start up unless you uncheck some of the options
if you want to stop things from loading when your computer starts, you need to uncheck "load start-up items"

RE: They exist: I've got a trojan... by Rolando on 10-06-2007 at 10:57 PM

It has nothing to do with Messenger Plus, like I stated. I've never installed the sponsor... well, maybe once when patch asked us to test it but that was a LONG time ago.  This started happening last week. Nothing to do with plus!'s sponsor..

As for the other things: Thanks, I'll try them now.


RE: They exist: I've got a trojan... by absorbation on 10-06-2007 at 11:35 PM

If the file is in your system restore section ignore it. It is just a bakcup of a file your anti-virus detects are dangerous, when it reality it has no power what-so-ever. Messing with system restore files is a bad idea :P.


RE: They exist: I've got a trojan... by Adeptus on 10-07-2007 at 05:25 AM

While some might argue against that, the best way to clean up a malware infection is clean format and fresh install of Windows.  That will get it every time. 

The removal by means of antivirus or antispyware software is simply not always effective.  I have experienced your problem, of crap coming back in a matter of days, before -- the ultimate solution has always been a clean format.


RE: They exist: I've got a trojan... by Jarrod on 10-07-2007 at 07:16 AM

did you use an interface other than windows?


RE: They exist: I've got a trojan... by NiteMare on 10-07-2007 at 08:03 AM

quote:
Originally posted by Adeptus
While some might argue against that, the best way to clean up a malware infection is clean format and fresh install of Windows.  That will get it every time.
curing the disease by killing the patiant, good idea, i really like to fit to keep my files intact first
RE: They exist: I've got a trojan... by Jarrod on 10-07-2007 at 09:23 AM

that's why my way should be given some thought:P


RE: They exist: I've got a trojan... by Lourix on 10-07-2007 at 12:08 PM

quote:
Originally posted by NiteMare
quote:
Originally posted by Adeptus
While some might argue against that, the best way to clean up a malware infection is clean format and fresh install of Windows.  That will get it every time.
curing the disease by killing the patiant, good idea, i really like to fit to keep my files intact first
True but sometimes for these things there's no cure.
RE: They exist: I've got a trojan... by Jarrod on 10-07-2007 at 01:58 PM

for this one there's an easy cure
remove lop tool
run that in safe mode
why'd we not find that earlier?
and

"True but sometimes for these things there's no cure. "
possible but not normally


did it die?


RE: They exist: I've got a trojan... by Rolando on 10-11-2007 at 02:18 AM

this still hasn't been solved.... Would it help identify the problem if I post the HijackThis log?


RE: RE: They exist: I've got a trojan... by Verte on 10-11-2007 at 01:44 PM

quote:
Originally posted by Adeptus
While some might argue against that, the best way to clean up a malware infection is clean format and fresh install of Windows.  That will get it every time. 

The removal by means of antivirus or antispyware software is simply not always effective.  I have experienced your problem, of crap coming back in a matter of days, before -- the ultimate solution has always been a clean format.


I have never formatted a machine [except when installing a new operating system with a different root file system type] but I guess it can't be too bad to start fresh sometimes.

Of course, you gloss over the possibility of BIOS-resident malware :) as difficult as it is to do right.

@q25: What was wrong with the lop removal tool?
RE: They exist: I've got a trojan... by absorbation on 10-11-2007 at 04:06 PM

You don't have a problem, the files are harmless and just being detected as dangerous because of their location and file name. They can't do anything do harm your computer, just relax and ignore it :P.


RE: They exist: I've got a trojan... by Eddie on 10-11-2007 at 04:45 PM

quote:
Originally posted by absorbation
You don't have a problem, the files are harmless and just being detected as dangerous because of their location and file name. They can't do anything do harm your computer, just relax and ignore it :P.
I found similair issues in my cousins system restore file today, tis no biggie and hasnt affected his computer since he got it like 12 months ago when it came up with the same problem.
RE: They exist: I've got a trojan... by absorbation on 10-11-2007 at 07:15 PM

The problem is constant with AVG, most anti-virus software go into panic mode and detect safe files as a threat. Remember how Messenger Plus! had issues with Windows Defender?


RE: They exist: I've got a trojan... by Rolando on 10-11-2007 at 07:59 PM

quote:
Originally posted by Verte
I have never formatted a machine [except when installing a new operating system with a different root file system type] but I guess it can't be too bad to start fresh sometimes.

Of course, you gloss over the possibility of BIOS-resident malware :) as difficult as it is to do right.

@q25: What was wrong with the lop removal tool?

it didn't find it, it said it was a different thing

quote:
Originally posted by absorbation
You don't have a problem, the files are harmless and just being detected as dangerous because of their location and file name. They can't do anything do harm your computer, just relax and ignore it (Smilie).

Yes I do, it opens pop-ups if I use IE (which i only do to check e-mails cause it's the default thing when I open messenger; no, don't tell me to use stuffplug to get it to open in ff).. it's very annoying :undecided: