Author Topic: trojano attack-- cant remove  (Read 24421 times)

0 Members and 1 Guest are viewing this topic.

ika

  • Guest
trojano attack-- cant remove
« on: August 16, 2005, 01:36:19 PM »
Win32:Hoaxalarm-H [Adw]
Win32:Trojano-1581 [Trj]
Win32:Trojano-1487 [Trj]
Win32:Trojano-1371 [Trj]

this viruses i have on my PC, and each time i go online avast  alarm me and i try "delete" and "move to chest", and when in restar my computer, zhe virus in still there.

what to do??

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojano attack-- cant remove
« Reply #1 on: August 16, 2005, 01:49:12 PM »
Can you post the 'path' of the infected files?

I can make some suggestions (hope they can help in anyway...):

1. Have you tried to delete the temporary Internet files? To do this go to Internet explorer >Tools > Internet options > Delete files > Click delete all offline content (just to be sure) > click ok. It might take some time to delete them.

2. Disable (and enable it after) System Restore: Start > Control Panel > System > System restore > Disable > Click Apply > Enable it again > Click Ok

3. Schedule a boot-time scanning: Start avast! > Right click the skin > Schedule a boot-time scanning > Select for scanning archives > Boot
The best things in life are free.

ika

  • Guest
Re: trojano attack-- cant remove
« Reply #2 on: August 16, 2005, 02:02:48 PM »
and my task manager in unavailible,...

i have tryed, but its the same

path in in temporaly internet files, and in temp......

WinAntiVirus_Guy

  • Guest
Re: trojano attack-- cant remove
« Reply #3 on: August 16, 2005, 02:59:37 PM »
Hi!

http://download.winantivirus.com/files/Trial/1019/WinAntiVirus2005ProTrialSetup.exe here is trial of antivirus, download it, than press "Update" button. After it make a scan and remove all that files.
 Of course better to make scan in a Safe Mode.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojano attack-- cant remove
« Reply #4 on: August 16, 2005, 03:46:30 PM »
http://download.winantivirus.com/files/Trial/1019/WinAntiVirus2005ProTrialSetup.exe here is trial of antivirus, download it, than press "Update" button. After it make a scan and remove all that files.
Why do you suggest another antivirus program if avast! is detecting the virus?
If the user uses boot time scanning or scan with avast! at Safe Mode, won't it be the same?
Why does he/she need to use WinAntiVirus2005Pro?
The best things in life are free.

ika

  • Guest
Re: trojano attack-- cant remove
« Reply #5 on: August 16, 2005, 03:56:51 PM »
i try all what was writen here, but trojane is still on my computer. i tryen another virus scan and i get this report:


Scan Settings:
   Scan using the following antivirus database: standard
   Scan Archives: true
   Scan Mail Bases: true

Scan Target - Folders:
   C:\

Scan Statistics:
   Total number of scanned objects: 23839
   Number of viruses found: 3
   Number of infected objects: 9
   Number of suspicious objects: 0
   Duration of the scan process: 1133 sec

Infected Object Name - Virus Name
C:\Documents and Settings\iztok\Local Settings\Temp\1.qtdfmp   Infected: Trojan-Downloader.Win32.Small.bho
C:\Documents and Settings\iztok\Local Settings\Temp\5.qtdfmp   Infected: Trojan-Downloader.Win32.Small.awa
C:\lo-1348106783.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\lo-816829849.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\lo1587471485.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\WINDOWS\system32\kernels32.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\WINDOWS\system32\vxh8jkdq1.exe   Infected: Trojan-Downloader.Win32.Small.bho
C:\WINDOWS\system32\vxh8jkdq5.exe   Infected: Trojan-Downloader.Win32.Small.awa
C:\WINDOWS\system32\vxh8jkdq8.exe   Infected: Trojan-Downloader.Win32.Small.bho

Scan process completed.

toadbee

  • Guest
Re: trojano attack-- cant remove
« Reply #6 on: August 16, 2005, 05:58:15 PM »
Hey is that the same winantivirus that finally made the rogue and suspect antispyware list ??
http://www.spywarewarrior.com/rogue_anti-spyware.htm
Quote
aggressive advertising (1, 2, 3, 4); false positives work as goad to purchase; inappropriate collection of Personally Identifiable Information [A: 5-21-05 / U: 5-21-05]

Of course it is. Don't use it.

TurtleWax

  • Guest
Re: trojano attack-- cant remove
« Reply #7 on: August 23, 2005, 06:55:38 AM »
Check out my How2 (sorta brute force malware removal)
http://www.sysinternals.com/Forum/forum_posts.asp?TID=966&PN=1

Then Get this tool !  It is great for stopping autorun programs from reloading.
http://www.sysinternals.com/Utilities/Autoruns.html
TurtleWax
i try all what was writen here, but trojane is still on my computer. i tryen another virus scan and i get this report:


Scan Settings:
   Scan using the following antivirus database: standard
   Scan Archives: true
   Scan Mail Bases: true

Scan Target - Folders:
   C:\

Scan Statistics:
   Total number of scanned objects: 23839
   Number of viruses found: 3
   Number of infected objects: 9
   Number of suspicious objects: 0
   Duration of the scan process: 1133 sec

Infected Object Name - Virus Name
C:\Documents and Settings\iztok\Local Settings\Temp\1.qtdfmp   Infected: Trojan-Downloader.Win32.Small.bho
C:\Documents and Settings\iztok\Local Settings\Temp\5.qtdfmp   Infected: Trojan-Downloader.Win32.Small.awa
C:\lo-1348106783.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\lo-816829849.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\lo1587471485.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\WINDOWS\system32\kernels32.exe   Infected: Trojan-Downloader.Win32.Small.bht
C:\WINDOWS\system32\vxh8jkdq1.exe   Infected: Trojan-Downloader.Win32.Small.bho
C:\WINDOWS\system32\vxh8jkdq5.exe   Infected: Trojan-Downloader.Win32.Small.awa
C:\WINDOWS\system32\vxh8jkdq8.exe   Infected: Trojan-Downloader.Win32.Small.bho

Scan process completed.


Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #8 on: November 29, 2005, 04:49:58 PM »
Hello to all!!

I have only Win32:Hoaxalarm-H [Adw] adwere in my copmpetuter, I do'not now what I do, I check a lot thing (registri, scan, rebootscan,....)
Avast do not clear them. whene it delete the *.tmp file from c:/windows/system32/1024/ on reboot is this file there ?? ???

I think this file was genereted from anather file wich one avast not found?

If somebody know how to delete this please write me!

Best regards from Boštjan - Slovenia
« Last Edit: November 29, 2005, 04:52:29 PM by Storzek »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojano attack-- cant remove
« Reply #9 on: November 29, 2005, 05:16:45 PM »
I think this file was genereted from anather file wich one avast not found?

Are you using Windows XP?
Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning
Select for scanning archives.
Boot.

Other option is scanning in SafeMode (repeatedly press F8 while booting): http://support.microsoft.com/default.aspx?scid=kb;en-us;315222
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: trojano attack-- cant remove
« Reply #10 on: November 30, 2005, 11:11:03 AM »
Hi ika,

Does this ring a bell. Look here:
http://www.viruslist.com/en/viruses/encyclopedia?virusid=87179.
A hoax virus is a virus that pops up a hoax and starts up through a change in the registry. The hoax gives the end-user the impression that he is infected.

greets,

polonus
« Last Edit: November 30, 2005, 11:12:44 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojano attack-- cant remove
« Reply #11 on: November 30, 2005, 12:09:07 PM »
A hoax virus is a virus that pops up a hoax and starts up through a change in the registry. The hoax gives the end-user the impression that he is infected.
Do you have a copy of it?
If it's a joke, let's joke... maybe some friend of us could laught at this...  ;D
The best things in life are free.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: trojano attack-- cant remove
« Reply #12 on: November 30, 2005, 04:19:48 PM »
A hoax virus is a virus that pops up a hoax and starts up through a change in the registry. The hoax gives the end-user the impression that he is infected.
Do you have a copy of it?
If it's a joke, let's joke... maybe some friend of us could laught at this...  ;D
I think he just has a copy of the image on the link that he gave.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojano attack-- cant remove
« Reply #13 on: November 30, 2005, 05:12:51 PM »
I think he just has a copy of the image on the link that he gave.
I see... but it would be nice to have it as a real joke  ;D
The best things in life are free.

Storzek

  • Guest
Re: trojano attack-- cant remove
« Reply #14 on: December 01, 2005, 07:46:53 AM »
Hello!

Yes I have windows XP but nothing of this do not work I chack anather forums, but nobudy do not know how to delete this addwere.

Best regards from, Bostjan, Slovenia