Trojan

All your computer hardware and software questions in here please.

Moderator: Moderators

User avatar
brushmate
Senior Member
Posts: 395
Joined: Tue Jan 08, 2008 8:41 pm
Location: Colne Lancs
Has thanked: 1 time
Been thanked: 3 times

Trojan

Post by brushmate »

HI any one had problems with Trojan dns changer having real problems, ::b ::b
User avatar
dave.m
Deceased 07-06-2012 R.I.P
Posts: 4989
Joined: Tue Jun 09, 2009 4:30 pm
Location: A Yorky in Lancashire
Has thanked: 13 times
Been thanked: 318 times

Post by dave.m »

Please download Malwarebytes AntiMalware and save to your desktop. It is free.


Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to the following:

o Update Malwarebytes' Anti-Malware
o Launch Malwarebytes' Anti-Malware

Then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. The rogue application should now be gone.

Post back.

dave
User avatar
thescruff
Senior Member
Posts: 49685
Joined: Mon Mar 10, 2008 12:46 am
Location: Bath
Has thanked: 360 times
Been thanked: 3735 times

Post by thescruff »

Interesting program Dave.

I down loaded it and ran it as per the instructions :shock:

250 infections including 2 Trojan vundo and 1 trojan agent.

So much for AVG :roll:
User avatar
dave.m
Deceased 07-06-2012 R.I.P
Posts: 4989
Joined: Tue Jun 09, 2009 4:30 pm
Location: A Yorky in Lancashire
Has thanked: 13 times
Been thanked: 318 times

Post by dave.m »

In the list I made up of free software, I included AVG but since they came out with the new version v8.0 it has had some very bad press and lots of people are switching to Avast, which comes out top of all the freeware in some tests.

Personally I have
Comodo Internet Suite (Firewall and Antivirus)
Spyware Blaster
MBAM
SuperAntiSpyware
and WinPatrol just snapping at the heels of anything that wants to change the registry etc.

Never have any problems other than tracking cookies.
I have a writeup about having SAS and MBAM as back-room boys, think I will post it on here.

dave

Almost forgot,

As you had trojans etc, now that you are clean, purge your system restore points and then set a new one so that you don't accidentally revert back to a time when you were infected without thinking.
If you want instructions to purge and reset, post vback with which ever system you use, Vista or XP.

dave
User avatar
thescruff
Senior Member
Posts: 49685
Joined: Mon Mar 10, 2008 12:46 am
Location: Bath
Has thanked: 360 times
Been thanked: 3735 times

Post by thescruff »

I have AVG 8 point something and not impressed, I definitely think it slows the computer down.

On the other laptop I have uninstalled it, and tried to install Avira, but it keeps shutting off in protection mode ::b I don't think it's fully installed.
User avatar
dave.m
Deceased 07-06-2012 R.I.P
Posts: 4989
Joined: Tue Jun 09, 2009 4:30 pm
Location: A Yorky in Lancashire
Has thanked: 13 times
Been thanked: 318 times

Post by dave.m »

Give Avast a try, lots swear by it.
Or use the Comodo AV.
What firewall do you have at the moment? Comodo comes out tops of the free ones, but you can just install the Comodo AV if you wish.
Links are on my other thread.

Remember abouit the system restore.
dave :wink:

Sorry, Brushmate, we seem to have pinched your thread.

How are you getting on with MBAM?

Post back if you cleared it and the also what operating system you have, Vista or XP.

dave
User avatar
thescruff
Senior Member
Posts: 49685
Joined: Mon Mar 10, 2008 12:46 am
Location: Bath
Has thanked: 360 times
Been thanked: 3735 times

Post by thescruff »

I'll do the system restore later.

Don't know whats on the laptop, probably don't have a firewall.

XP home.
gday2uk
Senior Member
Posts: 235
Joined: Fri May 11, 2007 6:42 am
Location: Sunny IOW
Has thanked: 0
Been thanked: 0

Post by gday2uk »

dave.m wrote:Personally I have
Comodo Internet Suite (Firewall and Antivirus)
Spyware Blaster
MBAM
SuperAntiSpyware
and WinPatrol just snapping at the heels of anything that wants to change the registry etc.
Damn, you must surf some dodgy sites to need all that :wink:
gas4you
Senior Member
Posts: 7203
Joined: Mon Apr 13, 2009 7:03 pm
Has thanked: 419 times
Been thanked: 900 times

Post by gas4you »

Just installed and run it on my PC. Found 2 instances of trojan.agent.

Can you schedule it to run automatically, or is this a feature only in the 'purchase' version?
Dave
User avatar
dave.m
Deceased 07-06-2012 R.I.P
Posts: 4989
Joined: Tue Jun 09, 2009 4:30 pm
Location: A Yorky in Lancashire
Has thanked: 13 times
Been thanked: 318 times

Post by dave.m »

Dave,
The free version does not have a schedule scan facility but once a week is not really much trouble to update and scan.

A tip is to right click the shortcut icon on your desktop and rename it "MBAM" and the two numbers of the date of your scan so that you can tell at a glance when you last ran it. For example, if you scanned today:
MBAM 11

Always remember that if it finds and removes any trojans etc, once your computer is running well again, purge your system restore points and set a new one to prevent accidentally reverting back to a contaminated point.

As for gday, I think I have the very minimum security required to venture onto the WWW. One damned good firewall, one antivirus and one realtime antispyware (ALL FREE). The other two are because no one is 100% safe on the web and it is best to have some backup because no matter how good your front line defense is, it is only as good as the latest definitions that it has of viruses etc.

Remember the best security program is Common Sense, DO NOT open any attachment in an email that you do not know who sent it or were not expecting it even if you know the sender.

dave
:wink:
User avatar
thescruff
Senior Member
Posts: 49685
Joined: Mon Mar 10, 2008 12:46 am
Location: Bath
Has thanked: 360 times
Been thanked: 3735 times

Post by thescruff »

I installed Comodo, and it wouldn't let me connect to the internet. ::b so uninstalled that. :cussing:
gas4you
Senior Member
Posts: 7203
Joined: Mon Apr 13, 2009 7:03 pm
Has thanked: 419 times
Been thanked: 900 times

Post by gas4you »

dave.m wrote:Dave,
The free version does not have a schedule scan facility but once a week is not really much trouble to update and scan.
Ok thanks.

Yes I agree it is no problem, it's just that I have my other spyware and AV scheduled to run every night at about 2:00 am. :wink:
Dave
User avatar
dave.m
Deceased 07-06-2012 R.I.P
Posts: 4989
Joined: Tue Jun 09, 2009 4:30 pm
Location: A Yorky in Lancashire
Has thanked: 13 times
Been thanked: 318 times

Post by dave.m »

thescruff wrote:I installed Comodo, and it wouldn't let me connect to the internet. ::b so uninstalled that. :cussing:
Did you get any error messages?

As you have uninstalled it, it is not much use trying to work through what was wrong.

It may have been caused by your Windows Firewall or other firewall still running. But too late to find out now.

dave
User avatar
brushmate
Senior Member
Posts: 395
Joined: Tue Jan 08, 2008 8:41 pm
Location: Colne Lancs
Has thanked: 1 time
Been thanked: 3 times

Post by brushmate »

Hi Dave
installed and ran malware bytes, found 4 trojan dns changers. Deleted the 4 rebooted surfed the net for 10 mins ran scan again and they were back. My daughter downloaded full version and set it up to run in the background and they are still appearing ? ::b ::b
User avatar
dave.m
Deceased 07-06-2012 R.I.P
Posts: 4989
Joined: Tue Jun 09, 2009 4:30 pm
Location: A Yorky in Lancashire
Has thanked: 13 times
Been thanked: 318 times

Post by dave.m »

Brushmate,

As MBAM is not removing the Trojan, try this.

1st thing to do is clear out all your temporary files, tool of choice is ATF Cleaner, it is free and you do not have to install it. Download and instructions here
Do NOT run it yet.

Download SuperAntiSpyware (the free version) to your desktop and then double click the .exe icon to install it.
Then click Run and follow the Wizard.
Select English (US) as the language.
Let it check for updates.
Click to let it protect your IE Home page. This stops rogue software taking over your browser and redirecting you when you try to go onto the web.

Click Scan when it offers to scan your computer.
Select “Perform Quick Scan” -> Next

Quick scan time is about 7 - 9 minutes dependant upon how many Hard Drives and how many programs and files you have.

Once it has run, let it remove all that it finds.

Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.



Reboot into Safe Mode by tapping F8 after the BIOS has loaded.
The Windows Advanced Options Menu appears.
Ensure that the Safe mode option is selected.
Press Enter. The computer then begins to start in Safe mode.


Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
NB. It's normal after running ATF cleaner that the PC will be slower to boot the first time.


Start Superantispyware.

Hit - Scan Your Computer - button

Click on the drive(s) you want to scan. Put a check in - Perform Complete Scan, then next

it will scan now. When scan have finished, put a checkmark with all items it found. Next, after cleaning, let it Reboot.

If this clears your trojan problem, post back and we will then purge your system restore points.

dave
Post Reply

Return to “Computers”