PDA

View Full Version : Omg Help Virus!



hAppy
07-23-2004, 11:09 AM
Help!
I got a "trojan backdoor" virus. I scanned for the virus with 2 different Anti-Viruses and they can't seem to pick it up. For the last 2/3 days I been getting a message popup for my AVG anti virus saying "You have a trojan backdoor, scan virus!" So I scan, and I find nothing. My computer is starting to restart out of nowhere now and then. HELP ME@!! AHHH
This is a new computer, my other computer got murdered by a virus, now I can't lose my NEW computer :cry:

Mighty Mike
07-23-2004, 01:26 PM
I had the same problem a couple months ago. My Norton program told me I downloaded a virus, but when i ran a system scan on my computer, no viruses came up. Try re-booting your computer in Safe Mode and scan your computer again with Norton Anti-Virus. I did it this way and Norton found 3 viruses on my computer.

Also....you could try the System Restore feature in your Windows XP; to restore your system back to where it was before the virus attack. I heard this may work too. Good Luck!!

Stix
07-23-2004, 01:39 PM
Before your run a scan, you generally have to turn of system restore mode; viruses in the system restore area of the HD can't be removed even if detected. Of course if you something goes wrong during the virus removal, you can't turn back the clock either. As stated in the post above, run this in safe mode and MAKE SURE YOUR VIRUS DEFINITIONS ARE UP TO DATE! If that doesn't work, try finding a virus removal tool; a good place to look is www.symantec.com

hAppy
07-23-2004, 01:46 PM
Before your run a scan, you generally have to turn of system restore mode; viruses in the system restore area of the HD can't be removed even if detected. Of course if you something goes wrong during the virus removal, you can't turn back the clock either. As stated in the post above, run this in safe mode and MAKE SURE YOUR VIRUS DEFINITIONS ARE UP TO DATE! If that doesn't work, try finding a virus removal tool; a good place to look is www.symantec.com
Where to turn off system restore mode? And how do I get to safe mode?
What do you mean something goes wrong? I am a computer noob, and something should go wrong if I work on it...

Thanks!

Mighty Mike
07-23-2004, 07:42 PM
Stix brought up some points i forgot to mention. First and foremost, make sure your virus definitions are up to date. And yes...you do have to disable system restore before you get into SAFE MODE and re-scan your computer.

Try the Restore feature on XP and see if you can get your computer back to where it was before the attack.

OR

Follow these steps to get rid of virus.

1. Update Virus Definitions

2. Disable "System Restore" [start] [settings] [control panel] [system] Click system restore tab and check the "Turn Off System Restore" box. Click OK.

3. Shut down computer

4. Turn computer back on and hit the F8 button while computer is booting up.

5. Hightlight the "Safe Mode" Option and press ENTER

6. Re-Scan your computer and hopefully you'll find your virus. If this doens't work, then go to Option 3...contact Cphillip or Miscue. :)

penguinpunk555
07-23-2004, 08:54 PM
Stop looking at porn....


Buy mags.

hAppy
07-23-2004, 09:00 PM
Thanks Mighty Mike.

penguinpunk555 - Interesting thought. It's not porn, I leave my computer on all day, and I dl almost a CD album daily. :confused: I know that porn on kazaa is a virus deathtrap anyways ;)

anonymousbill123
07-23-2004, 09:29 PM
I seriously hope that the safe mode thing or the update of your virus scan works because trojans generally cannot be destroyed. And try shutting down your computer when your done if you have a type of internet that has you always connected because once your connected to the internet you are vulnerable to any for of virus even if you dont have any program running that requires the internet. And if you use Microsoft Internet Explorer try to use something else because it is the least safest browser available. Only use it if you know a site is safe and something on the site does not work with other browsers.

good luck.

I had to get my computer resetted to when i first got it twice because of viruses. :(

dave_p
07-23-2004, 09:54 PM
1: download zonealarm
2: install zonealarm
3: when the trojan tries to access the internet or open a port zonealarm will notify you
4: take note of the name of the program trying to phone home
5: delete all instances of the file, related registry entries and entries in config.sys or autoexec.bat

or go to grc.com and run the shields up scan, find the port the trojan is listening on. look it up by port number and find an extraction tool.

or open a dos box and do a netstat -a, look for any listening services that do not seem to belong there or have high port numbers.

to survive on the net you must be a ninja :ninja:

1ofkind
07-23-2004, 10:04 PM
penguinpunk555 Stop looking at porn....



Buy mags....


What if he can't afford a mag?

hAppy
07-23-2004, 11:46 PM
1: download zonealarm
2: install zonealarm
3: when the trojan tries to access the internet or open a port zonealarm will notify you
4: take note of the name of the program trying to phone home
5: delete all instances of the file, related registry entries and entries in config.sys or autoexec.bat

or go to grc.com and run the shields up scan, find the port the trojan is listening on. look it up by port number and find an extraction tool.

or open a dos box and do a netstat -a, look for any listening services that do not seem to belong there or have high port numbers.

to survive on the net you must be a ninja :ninja:
Dang I barely understood that. I am a computer noob once again. So I should install zonalarm? Why do I need to delete the other stuff? Thanks for info

Koosh
07-24-2004, 12:27 AM
EVERYONE I know who uses AVG said that they get this too... They said its just an adware program and you can ignore it...

It comes up like twice a day with me, and I have yet to pick up anything on a scan. I just keep clicking until it goes away.

Jeremizzle
07-24-2004, 12:34 AM
I'd just backup everything you want to keep then re-format your hard drive. That will always work.

hAppy
07-24-2004, 12:37 AM
EVERYONE I know who uses AVG said that they get this too... They said its just an adware program and you can ignore it...

It comes up like twice a day with me, and I have yet to pick up anything on a scan. I just keep clicking until it goes away.
That's one of those "thats very comforting, thank you". I did notice this happened to my last comp which I installed this program to. It did go away... than it died a few months after. Completely dead.... yep.... Sony Vaio :cry:

Bluestrike_2
07-24-2004, 06:47 PM
Two options here IMO.

Either switch to Linux or get a mac.

Either way, Windows is very, very insecure. Over 50,000 virii for windows, a handfull(forget exact number) for linux, 500 and some for the pre-X Mac OS(of which all but 28 were due to Microsoft programs), and 0 for Mac OS X.

Or, you can backup your important files and just re-format the HD, like someone else said. Then, system reinstall.

xmetal2001
07-24-2004, 07:00 PM
I'll bet money(not really) that this is the solution...Same thing happened to me with avg.

Whats happening is its finding a trojan saved in your system restore backup files, so it isn't being found by a normal scan.

Simple solution.

Goto Control Panel, System, and then click on the system restore tab.

Check "Turn off system restore on all drives", wait until its finished deleting all your restore files and then uncheck the box to turn it back on.

virus
07-24-2004, 07:14 PM
i didnt do it

no one saw me do it

ya cant prove anything

and thats my story, i'm stickin to it




sorry i couldnt resist :D :cheers:

Stix
07-25-2004, 07:48 PM
If you decide to reformat make sure you get the format tool that's specific to your HD that turns everything into a 0; some of the trojan's will survive a regular format.

insanity415
07-25-2004, 08:31 PM
a few months ago i had AVG tell me i had a virus but every time i ran it it would freeze up when i tried to remove it. the problem was it was just an ad thing in my temp files and somehow it couldn't get there :confused: , i dont know thats just the explanation i got. i ran adaware on a custom mode where it would search EVERYTHING and it went away then. i dont know if you have the same problem though.

try searching for the name of the trojan on google and see if you can find a website that tells you how to remove it