Author Topic: Trojan Horse removal  (Read 13927 times)

0 Members and 1 Guest are viewing this topic.

Offline arosegirl

  • Jr. Member
  • **
  • Posts: 63
Trojan Horse removal
« on: October 14, 2008, 03:00:31 AM »
I just paid Norton to remove 4 Trojan Horses; they only removed 2, help please!
Corinne, RavenCajun says clean me up!!!!

Offline Paddy

  • LandzDown Team
  • Hero Member
  • *****
  • Posts: 1376
Re: Trojan Horse removal
« Reply #1 on: October 14, 2008, 08:57:07 AM »
arosegirl, welcome to the forum I moved your topic here tho, I think I should have put in Hjt..

It will be a few hours before Corrine can get here so I will give you a start ..

Paddy... :thumbsup:

Please download ATF Cleaner by Atribune from http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25 .  Save it to your Desktop.

Run ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
  • Click Exit on the Main menu to close the program.
  • Shutdown/restart the computer.
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.


The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt

  • Please post contents of that file in your next reply.
Next


Please download HijackThis© from one of the following sites: 
•   http://www.thespykiller.co.uk/files/HJTsetup.exe
•   http://downloads.malwareremoval.com/HJTsetup.exe
•   http://security-central.us/downloads/HJTsetup.exe
At the download prompt, choose "Save" 
•   Navigate to the saved file and double-click the installer, HJTsetup.exe
•   By default, HijackThis will be installed on your computer at C:\Program Files\HijackThis, making an entry in the start menu and also providing a desktop shortcut
•   When the installation is complete, double-click the HijackThis icon on your desktop
•   Select "Scan"
•   When the scan is completed, select "Save log"
•   Select a name for this first log and a text file will be produced in Notepad.
•   Please UNcheck Word Wrap in Notepad (Click Format > UNcheck Word Wrap)
•   Copy the text file and paste it as a reply
•   Do NOT fix anything with HijackThis yet. Most of what is found is harmless or even required
•   Close HijackThis and Notepad


This is one race of people for whom psychoanalysis is of no use whatsoever - Sigmund Freud (about the Irish)

Never argue with a fool, they will lower you to their level and then beat you with experience.

Offline arosegirl

  • Jr. Member
  • **
  • Posts: 63
Re: Trojan Horse removal
« Reply #2 on: October 14, 2008, 02:14:00 PM »
I had tried the Malwarebytes, it didn't detect anything and the computer tech removed it from my system saying it wasn't a good thing to keep on my computer....neither are Trojans.
I have to leave the house for several hours.  Check in when I return, thank you!

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Trojan Horse removal
« Reply #3 on: October 14, 2008, 02:28:16 PM »
Hi, arosegirl.

The computer tech was wrong.  Malwarebytes is an excellent program, updated frequently with outstanding results.  It was developed by members of the security community.  My question, however, is why didn't the computer tech remove the trojans?

Since you do still have trojans on your computer, in order for us to assist you, we need to see the requested logs.  Please follow the posted instructions exactly as indicated above.

Thank you.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline R-C

  • Hero Member
  • *****
  • Posts: 2651
  • Laissez les bons temps rouler!
Re: Trojan Horse removal
« Reply #4 on: October 14, 2008, 04:44:14 PM »
she paid someone at Norton $99 and they still did not remove them.

arosegirl you will have to get the programs they tell you to so that they can get into your system and clean out all this infection it is the only way, these are all safe programs that are used on the help forum, with their guidance.
registered Linux user:476595
May inspiration fill your heart and hands, run down your legs onto your feet and cause Spontaneous Dancing! :dance:

Offline winchester73

  • Administrator
  • Hero Member
  • *****
  • Posts: 5125
  • Half a bubble off plumb
Re: Trojan Horse removal
« Reply #5 on: October 14, 2008, 06:10:23 PM »
I'm confused ...

Is this computer tech the person at Norton, or someone local who you have talked to since?  I'm trying to figure out "when" you were told that MBAM wasn't any good ... it sounds like you followed numbnuts advice and then someone looked at your computer, but you went the Norton route before all of this.

BTW, what is your operating system, and what steps exactly did the Norton person take you through?

Is there some sort of log that will tell us what was removed, and what wasn't ... and hopefully tell us the file path?
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member



Offline Eric the Red

  • ISO/IEC 27001:2005
  • Administrator
  • Hero Member
  • *****
  • Posts: 1611
  • Would somebody please pass me a beer!
Re: Trojan Horse removal
« Reply #6 on: October 14, 2008, 06:46:08 PM »
Hi arosegirl,

Welcome to the forum, here we will do our best to help you, and it isn't often that the experts here fail to clean a machine. There are a few pointers that may help you whilst you are here.....

  • Remember the cover of the Hitchhiker's Guide to the Galaxy? Emblazoned on it are the words "Don't Panic!", the same holds true here
  • If there is something that you don't understand, please ask
  • Be sure to follow the directions that you are given to the letter
  • Don't go downloading system cleaners / antivirus / antimalware applications unless you have been asked to do so by one of our experts, some of the sparkly things on the 'net can be further Trojans!
  • Have fun! It takes time to analyse the information that you supply so feel free to have a look at some of the other boards here and join in some of the games whilst you are waiting
"The time to start running is around about the "e" in "Hey, you!" "
Proud member Since 2004 

The information I provide is provided "AS IS" without warranty, and confers no rights.

Offline arosegirl

  • Jr. Member
  • **
  • Posts: 63
Re: Trojan Horse removal
« Reply #7 on: October 14, 2008, 06:55:04 PM »
First I contacted Norton, I was connected to a guy called Midhun, probably in India. He took control of my computer working with it for over 3 hours.  He deleted all my cookies for one thing and a lot of my files he said were infected then told me my computer was free from Trojan Horses..the next day when Norton did a scan as it does every day it said 2 remained.  I emailed them twice and still have not heard back from him...this did cost me $99.  I then went to computer help and RavenCajun gave me your link. I have downloaded the Malware and it is doing a scan and I have the other recommeded one on my desktop as directed.  Charlene

Offline arosegirl

  • Jr. Member
  • **
  • Posts: 63
Re: Trojan Horse removal
« Reply #8 on: October 14, 2008, 07:06:06 PM »
I am will be back later as it takes Malware about 2 hours to scan. Charlene

Offline arosegirl

  • Jr. Member
  • **
  • Posts: 63
Re: Trojan Horse removal
« Reply #9 on: October 14, 2008, 09:39:35 PM »
Tell me how to post from notepad.  I can't copy and paste sooooo, I don't see a browse, how do you do it here? Charlene

Offline Paddy

  • LandzDown Team
  • Hero Member
  • *****
  • Posts: 1376
Re: Trojan Horse removal
« Reply #10 on: October 14, 2008, 10:42:15 PM »
Take your mouse, and place your cursor at the beginning of the text in notepad, then click and hold the left mouse button, while pulling your mouse over the text.

This should highlight the text in blue .

Now release the left mouse button.

Now, with the cursor over the highlighted blue text, right click the mouse for options, and select 'copy'.

Now hit reply button on the forum and over the empty replybox,on the forum, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Then hit the post button


Hope This Helps

Paddy..
This is one race of people for whom psychoanalysis is of no use whatsoever - Sigmund Freud (about the Irish)

Never argue with a fool, they will lower you to their level and then beat you with experience.

Offline winchester73

  • Administrator
  • Hero Member
  • *****
  • Posts: 5125
  • Half a bubble off plumb
Re: Trojan Horse removal
« Reply #11 on: October 14, 2008, 10:54:46 PM »
First I contacted Norton, I was connected to a guy called Midhun, probably in India. He took control of my computer working with it for over 3 hours.  He deleted all my cookies for one thing and a lot of my files he said were infected then told me my computer was free from Trojan Horses..the next day when Norton did a scan as it does every day it said 2 remained.  I emailed them twice and still have not heard back from him...this did cost me $99.  I then went to computer help and RavenCajun gave me your link. I have downloaded the Malware and it is doing a scan and I have the other recommeded one on my desktop as directed.  Charlene

Thanks for the explanation.  Did you notice whether the two remaining items were in the Norton quarantine, or some other quarantine folder, or did Norton report them as active?

Don't worry, we'll get you cleaned up.
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member



Offline arosegirl

  • Jr. Member
  • **
  • Posts: 63
Re: Trojan Horse removal
« Reply #12 on: October 14, 2008, 11:50:58 PM »
I tried doing what you told me but what I got was like symbols..not what you wanted.  I did a print screen and saved it in the beginning so I will try to tell you what You might need to know.
Registry keys infected: 1
Registry keys infected:  it tells me it is in quarantine.

But something is still wrong because of the problems I am having with my computer.


Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11542
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Trojan Horse removal
« Reply #13 on: October 15, 2008, 12:11:24 AM »
Hi, arosegirl.  Yes, we understand there is something still wrong with your computer but we cannot help without seeing what it is on your computer.  Please do the following:

Launch MBAM.  Click on the Logs tab.  Double-click the log with today's date.  When it opens in Notepad, click the following:

Edit > Select All > Edit > Copy

Then paste the results here as a reply (right-click in the reply box with your mouse and select paste).

After that, please post a HijackThis log. 


,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline winchester73

  • Administrator
  • Hero Member
  • *****
  • Posts: 5125
  • Half a bubble off plumb
Re: Trojan Horse removal
« Reply #14 on: October 15, 2008, 12:12:26 AM »
I think you are trying to take a screen shot of the problem, seeing the Paint Pro that you posted earlier ...

Are you comfortable using Windows Explorer to navigate manually to the MBAM log?  The path is C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt

You can follow numbnuts copy/paste instructions to put the log into this thread.

If you can't do this, let's see the HijackThis log first, and then we can go forwards or backwards ...


For anyone helping on this issue, I think this is the original thread (and what has been done to date):

http://ths.gardenweb.com/forums/load/comphelp/msg1016420623167.html?16
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member