TROJAN HORSE - I need a nerd
Goto page 1, 2  Next
 
Post new topic   Reply to topic    Couchtripper Forum Index -> Tech news, tips and help
View previous topic :: View next topic  
Author Message
cori



Joined: 30 Apr 2006

PostPosted: Fri May 11, 2007 8:45 pm    Post subject: TROJAN HORSE - I need a nerd Reply with quote

I have a trojan horse, short of having to bring the pc to a fix-it shop for quite a few quid I was hoping someone has a suggestion that I can do myself.

HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Back to top
View user's profile Send private message
faceless
admin


Joined: 25 Apr 2006

PostPosted: Fri May 11, 2007 8:52 pm    Post subject: Reply with quote

how do you know it's a trojan? If you're sure it is and you have the name of it then you should be able to do a search for information on google on how to remove it.
Back to top
View user's profile Send private message Send e-mail
cori



Joined: 30 Apr 2006

PostPosted: Fri May 11, 2007 9:02 pm    Post subject: Reply with quote

It was identified by a norton scan, but damn I can't remember the name, I installed this software "the cleaner" which I found through google to get rid of the sucker, however my system is running slower than a snails pace. I hope you're the nerd that can help, I'll gladly send you your allowance for the pub.
Back to top
View user's profile Send private message
cori



Joined: 30 Apr 2006

PostPosted: Fri May 11, 2007 9:08 pm    Post subject: Reply with quote

Forgot to mention I also loaded and ran spy doctor
Back to top
View user's profile Send private message
faceless
admin


Joined: 25 Apr 2006

PostPosted: Fri May 11, 2007 9:12 pm    Post subject: Reply with quote

If you can do that scan again and find out the name that would help more than anything...

but to find out what's making things go slowly, press ctrl-alt-delete at the same time and then when you get the window popping-up, click on "task-manager". Then you'll see 4 tabs, click on "processes" and then "CPU". Look at the list that's showing and you'll see the program that's hogging everything as it will show that's it using something like 99%. Post the name of that process and that will also help to sort you out...
Back to top
View user's profile Send private message Send e-mail
6ULDV8



Joined: 30 Apr 2006
Location: USA

PostPosted: Fri May 11, 2007 9:29 pm    Post subject: Reply with quote

Dump Norton anti speed (I mean anti virus) as soon as possible...

Norton was great up to about 3 years ago & now it's just a systems hog with very little in the way of protection...
I mean c'mon, you got a trojan whilst using it right.

Kaspersky anti virus is what I use myself (Pro version) & once set up right it's great...
Most ppl I know will say to use NOD32 as it's free & is pretty streamlined too.

As for the trojan etc...

First start by removing the spyware crud you installed (both of them), no offence but most of those programs do more harm than good.

Pop along to PCPITSTOP & use their virus scan, if you have anything on your PC it will not only detect it but will also give you links / help in removing it.
PCPITSTOP.COM is a trusted site... never did me any harm in the many years of use.

Ohhh also... Norton has a habit of showing certain applications & even web media as trojans Sad

Post a screen shot of the 'trojan' (in nortons window) if you can... it would help.
Back to top
View user's profile Send private message MSN Messenger
cori



Joined: 30 Apr 2006

PostPosted: Fri May 11, 2007 10:18 pm    Post subject: Reply with quote

Face, in following your directions I see alot of shite, in particular the following; svchost.exe, lsass.exe, CCSETMGR.exe, PDUDServ.exe, explorer.exe, Magickey.exe. Idon't understand how to Post, and does 6ULD also have the answer. I will not send you your pub dosh until all is sorted as I don't want to have my card compromised, LOL
Back to top
View user's profile Send private message
til661



Joined: 11 Feb 2007

PostPosted: Fri May 11, 2007 10:26 pm    Post subject: Reply with quote

none of those exe files are trojans inherently. pdudserv. is power dvd, ccsetmgr.exe is norton. and the rest are all system processes. It is possible they could be compromised though so it would be best for you to visit the site 6uldv8 recommended
Back to top
View user's profile Send private message
faceless
admin


Joined: 25 Apr 2006

PostPosted: Fri May 11, 2007 10:37 pm    Post subject: Reply with quote

cori - give that site 6uldv8 mentioned a shot and see if that sorts you.

www.pcpitstop.com

there's also http://housecall.antivirus.com
Back to top
View user's profile Send private message Send e-mail
cori



Joined: 30 Apr 2006

PostPosted: Fri May 11, 2007 11:49 pm    Post subject: Reply with quote

Guys I'm going for it, film at eleven
Back to top
View user's profile Send private message
6ULDV8



Joined: 30 Apr 2006
Location: USA

PostPosted: Sat May 12, 2007 12:12 am    Post subject: Reply with quote

Good news Cori...

Seriously dump Norton...

I have a slew of programs I can upload to help with the pesky stuff your dealing with (Including Kaspersky) if you need em.
Back to top
View user's profile Send private message MSN Messenger
major.tom
Macho Business Donkey Wrestler


Joined: 21 Jan 2007
Location: BC, Canada

PostPosted: Sat May 12, 2007 1:10 am    Post subject: Reply with quote

There are a couple other useful programs out there for finding trojans -- Lavasoft AdAware and Spybot Search & Destroy.

Here's what *I* do when I suspect a system is infected:
- run CodeStuff Starter (my preference) to see what programs run automatically when booting windows
- look for anything suspicious; you can tell by a) the folder where it is located (eg. random-looking folder names under c:\windows\system32 or under c:\documents and settings -- no programs should be located here) b) the program name, and c) a little knowledge of what hardware and software is in your system.
- with any suspicious-looking files, open windows explorer and go to the folder where the file is located, right-click and select properties. Pay attention to the creation dates (to see if it coincides with when you think the problem started) company and version information. Anything listed as Microsoft might not be. The best way to tell is to compare it to other program files under c:\windows, as M$ is pretty consistent. Trojans sometimes try to pass themselves off as M$, but leave the version as 1.0.0.
- If you find any that don't look right after this inspection, disable them in CodeStuff Starter and reboot your machine.

Once everything seems to be "normal" and you're satisfied that the system is working, you can delete/rename the files you disabled.

Good luck!
Back to top
View user's profile Send private message
cori



Joined: 30 Apr 2006

PostPosted: Fri May 18, 2007 6:32 pm    Post subject: Reply with quote

Okay to make a long story short over several days I tried quite a bit of your more than helpful suggestions, did alot of googling and finally after installing a combo of spyware detector & max registry, found a trojan identified as vundo, apparently it's some kind of advertising bug? I have run these programs for several days and it seems thaat I'm clean. Will pay a bill today online and track to make sure that's the only transaction that goes through. Hopefully, I'm in good shape, should it work fine that'll be a couple three pints sent to Face from all who helped out!
Back to top
View user's profile Send private message
major.tom
Macho Business Donkey Wrestler


Joined: 21 Jan 2007
Location: BC, Canada

PostPosted: Sat May 19, 2007 12:56 am    Post subject: Reply with quote

Congratulations on your success. Hopefully it's gone for good.

Another suggestion is that you can run a program called "Active Ports" to see what programs are connecting over the internet. Many trojans will chat back to their owner and wait for instructions (ie. "Listening").
Back to top
View user's profile Send private message
cori



Joined: 30 Apr 2006

PostPosted: Sun May 20, 2007 6:28 pm    Post subject: Reply with quote

I'm on that right now Major, cheers!!
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Couchtripper Forum Index -> Tech news, tips and help All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Couchtripper - 2005-2015