Trojan Horse help please

F

Fitzy_bhoy

AVG has reported various virus' and trojans on my system.
They are as follows

Win32/parite
worm/sddrop
downloader/esepor.k

Despite updating twice in the past few days I still cannot rid my system of
them.

I have download trojan hunter and trojan remover which does not detect them.

The files affected are in the c:\system volume information folder which i
cannot find to delete the infected files.

Also winlogon.exe is being attacked, which trojan hunter finds as a
suspicious file but does not do anything with.

Can anyone help, I have just installed broadband and i am paranoid about
someone doing something to my system.

Thanks
 
L

Lisa

My antivirus software had me delete them. After you do the virus scan it
had me delete them.
 
M

Mara

My antivirus software had me delete them. After you do the virus scan it
had me delete them.

You're replying to the wrong poster. I suggest you read the links that have
already been supplied to you.

And you're using what OS, and what antivirus software? The OP names two
anti-trojan programs, which aren't necessarily the same thing as an antivirus
program. What if he has another that isn't the same as yours? What if you're not
running the same OS? My mind-reading experts are off today; they can't read your
mind to see what you're running. And it DOES make a difference. A BIG one.

Here:

http://www.dickalba.demon.co.uk/usenet/guide/guide.html
http://www.duke.edu/eng169s2/group4/alok/English/map.htm
http://www.uwasa.fi/~ts/http/quote.html
http://www.faqs.org/faqs/net-abuse-faq/munging-address/
http://www.newsreaders.com/guide/netiquette.html

http://www.ezine.com/netiquette.html
http://www.dtcc.edu/cs/rfc1855.html
http://www.gwr.arizona.edu/overcoming3.htm

Go do some reading before you post again.

"You'll help _everyone_ (tine) out, by doing that, along with yourself."

<snip>
 
B

Beauregard T. Shagnasty

Quoth the raven named Fitzy_bhoy:
Can anyone help, I have just installed broadband and i am paranoid
about someone doing something to my system.

Do you have a firewall?

If not, this could be the source of your troubles...
 
L

Lisa

you people need to get some manners and grow up
Mara said:
You're replying to the wrong poster. I suggest you read the links that have
already been supplied to you.

And you're using what OS, and what antivirus software? The OP names two
anti-trojan programs, which aren't necessarily the same thing as an antivirus
program. What if he has another that isn't the same as yours? What if you're not
running the same OS? My mind-reading experts are off today; they can't read your
mind to see what you're running. And it DOES make a difference. A BIG one.

Here:

http://www.dickalba.demon.co.uk/usenet/guide/guide.html
http://www.duke.edu/eng169s2/group4/alok/English/map.htm
http://www.uwasa.fi/~ts/http/quote.html
http://www.faqs.org/faqs/net-abuse-faq/munging-address/
http://www.newsreaders.com/guide/netiquette.html

http://www.ezine.com/netiquette.html
http://www.dtcc.edu/cs/rfc1855.html
http://www.gwr.arizona.edu/overcoming3.htm

Go do some reading before you post again.

"You'll help _everyone_ (tine) out, by doing that, along with yourself."


<snip>
 
@

@}-}-------Rosee

You people? It seems you are the one having the problem with constructive
criticism, so YOU need to "get some manners and grow up" <sic>...

you people need to get some manners and grow up
"Mara" wrote...

<schnippen>
 
F

Fitzy_bhoy

Beauregard T. Shagnasty said:
Quoth the raven named Fitzy_bhoy:


Do you have a firewall?

If not, this could be the source of your troubles...
Yep got one built into my router. all my ports are invisible. I flushed to
system restore points and i am recieving no more messages so it seems to
have helped.

Thanks to all who answered
 
D

DE

Fitzy_bhoy said:
AVG has reported various virus' and trojans on my system.
They are as follows

Win32/parite
worm/sddrop
downloader/esepor.k

Despite updating twice in the past few days I still cannot rid my system of
them.

I have download trojan hunter and trojan remover which does not detect them.

The files affected are in the c:\system volume information folder which i
cannot find to delete the infected files.

Also winlogon.exe is being attacked, which trojan hunter finds as a
suspicious file but does not do anything with.

Can anyone help, I have just installed broadband and i am paranoid about
someone doing something to my system.

Thanks

BUY SOME DECENT ANTI-VIRUS SOFTWARE. If you can afford broadband, you are
WAY late on spending the lousy 15 bucks to protect your system and stop
infecting half the world!

And learn to NOT OPEN EMAIL ATTACHMENTS, no matter how cute they look.

You need decent AV software, which will then enable you to clean up the
infected files. I don't know what you mean by "winlogon.exe is being
attacked" -- "attacked"??? -- but winlogon *can* be a trojan.

In any case, you should DISCONNECT from the internet and clean up your
system before re-connecting, so that you don't infect half the world.
Have you even notified your friends (what ones you might have left) and
contacts that you are infected?

It takes some pretty SLOPPY computing and no sense of responsibility to
get infected with THREE trojans like this. Go out and GET ANTI-VIRUS
software, download the latest defs for it, re-scan your system and have it
quarantine all infected files that it can't repair. This will likely
leave your system unusable since you've got at least 3 infections going,
but it's probably best if you reload from scratch anyway since you've now
destroyed some good part of your own data as well as passing along this
stuff to others.

Geez, Win32/Parite is THREE YEARS OLD, how dense do you have to be to run
without any AV software in this day & age? IAC it's likely damaged a
bunch of your programs by now -- which IMO you deserve for being so
irresponsible -- but here's the info on removal:
http://securityresponse.symantec.com/avcenter/venc/data/w32.pinfi.html

Sddrop is "only" a year old and lets a hacker do whatever they want to
your system:
http://securityresponse.symantec.com/avcenter/venc/data/w32.kwbot.f.worm.html
" 4. Waits for commands that the hacker transmits using IRC. The
commands allow the hacker to perform any of the following actions:
* Deliver system and network information to the hacker.
* Manage the self installation.
* Download and execute files.
* Perform Denial of Service (DoS) attacks.
* Replicate across file-sharing networks, such as KaZaA and iMesh."
So I guess you don't mind your computer being used in DoS attacks and
having some stranger execute whatever they want on it.

And esepor.k is only a few months old, and you probably ENJOY the pop-up
porn ads.

As for whatever's going on with your WINLOGON, perhaps it's some variant
of this:
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100990
which means that if you've done any credit-card buying on the internet,
someone now likely has all your information.


Happy computing! I bet you're REAL happy you saved spending $15 on a
decent AV program now!


BTW, if you take the same approach with your home as you do with your
computer: please post your home address here along with the times you'll
be out, leave the front door wide open and please leave all your valuables
out where we don't have to look for them.
 
T

Thund3rstruck_N0i

Lisa spilled my beer when they jumped on the table and proclaimed in
you people need to get some manners and grow up

Asking for the needed information is needing manners and growing up?

<Plonk>

NOI
 
H

Harold The Rock

AVG may not be clearing up the infected files in your system volume
information folder which, under XP, is a hidden system folder. If you
are running XP then change your folder options to show hidden and
system files. AVG should then check the hidden fles and folders and
move any infected files to the virus vault or heal them as applicable.

Hope this helps.
 
B

Beauregard T. Shagnasty

Quoth the raven named Fitzy_bhoy:
Yep got one built into my router. all my ports are invisible. I
flushed to system restore points and i am recieving no more
messages so it seems to have helped.

Since it seems you don't practice safe hex, I would still recommend a
software firewall behind that router. It will tell you when any
program wants to send something *out*. Your router firewall blocks
incoming only.

Be careful and attentive about what you allow out.
 
K

kurt wismer

Beauregard T. Shagnasty wrote:
[snip]
Your router firewall blocks incoming only.

usually true for the cheaper routers whose sole firewall technology is
network address translation, but not true for all of them (some have
the ability to set incoming and outgoing filter rules)...
 
K

kurt wismer

Harold said:
AVG may not be clearing up the infected files in your system volume
information folder which, under XP, is a hidden system folder. If you
are running XP then change your folder options to show hidden and
system files. AVG should then check the hidden fles and folders and
move any infected files to the virus vault or heal them as applicable.

close, but...

under xp "system volume information" is where the system restore
folders are kept, and their contents are protected by the operating
system... there is no way to access them directly, the only way to get
a virus out of there is to purge your restore points...
 
B

Beauregard T. Shagnasty

Quoth the raven named kurt wismer:
Beauregard T. Shagnasty wrote: [snip]
Your router firewall blocks incoming only.

usually true for the cheaper routers whose sole firewall technology
is network address translation, but not true for all of them (some
have the ability to set incoming and outgoing filter rules)...

Yes, that's true. Thanks for reminding me. Most folks I converse with
have the cheap ones. Heh, even me. <g>
 
M

Mara

On Mon, 02 Feb 2004 04:35:44 GMT, Lisa wrote:

<snipped>

Would you like some cheese to go with that whine? :)

Very well - I've posted many clues below, each of which would have helped you a
great deal, and your response to it, as to other posts, was one of childish
whining, without, of course, making the first effort to help yourself. Since you
seem determined to dive into the bin headfirst, I'll open the door for you.

"Fore!!1!"

<snip>
 
T

Thund3rstruck_N0i

Mara spilled my beer when they jumped on the table and proclaimed in
Would you like some cheese to go with that whine? :)

Very well - I've posted many clues below, each of which would have helped
you a great deal, and your response to it, as to other posts, was one of
childish whining, without, of course, making the first effort to help
yourself. Since you seem determined to dive into the bin headfirst, I'll
open the door for you.

"Fore!!1!"

Here <Hands handi-wipe> You got something on your shoe. :)

NOI
 
M

Mara

Mara said:
On Mon, 02 Feb 2004 04:35:44 GMT, Lisa wrote:

<snipped>

Would you like some cheese to go with that whine? :)

Very well - I've posted many clues below

Ah, a most noble display of charity. And the most noble of those
displays are always made by those who have so little to give.
 
H

Harold The Rock

I disagree as I run XP and sometimes AVG reports a virus in the system
restore directory. I manually delete the infected file. It has never
affected the system restore and XP has continued to function OK. It
catches up with the restore points.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top