TechSpot

Trojan popups coming often

By Frogshark40
Aug 29, 2008
  1. On my fathers computer, he told me of some of these fake anti-virus "buy me" programs coming up, so I scanned his computer and got rid of what was there. I installed Anti-Viri PE Classic and scanned, only 1 suspicious file but nothing apparently.

    He is having random popups from anti-viri saying that trojans are just coming in out of nowhere, hopefully someone can run through this.
     
  2. bomberman

    bomberman TS Rookie

    yea i had that problem too, a while back its Extremely annoying. Its the VUNDO.H trojan...
    here is a link that tells you how to deal with it

    www (dot) trendmicro.com/vinfo/uk/virusencyclo/default5.asp?VName=TROJ_VUNDO.H&VSect=Sn
     
  3. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    mbam removed some infections.

    AVG v7.5 antispyware is no longer being supported as far as I know> This means he isn't getting updates. You will need to be careful about upgrading though because AVG v8 has an antivirus program AND spyware program combined!

    The Java is out of date. Most current is v6u7. Updates here:
    http://www.java.com/en/download/manual.jsp

    Reopen HijackThis. Check the following:
    Check 'fix this' and close Hijack This> Reboot into Safe Mode:
    Control Panel> Add/Remove Programs> uninstall all earlier versions of Java.

    Boot into Normal mode. Please advise status of any pop-ups since Malwarebytes was run and removed entries. Run all security program scans updated, again. Decide about AVG- it doesn't do much good without update.
     
  4. Frogshark40

    Frogshark40 TS Rookie Topic Starter Posts: 47

    He did some online shopping aswell, eBay and stuff, any certain precautions I should take about that?
    So I'm guessing I remove the older versions after the first set of O2/4/6 then download the update.

    I can't understand to much about what you were trying to say about AVG, your saying I should remove it and get another program? Any recommendations?
     
  5. Frogshark40

    Frogshark40 TS Rookie Topic Starter Posts: 47

    Also, after I do all this stuff will all these popups end?
     
  6. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    The one you're using is out of date. Is it a free version or a paid version.

    Sorry, no guarantees. But it will be an improvement and hopefully the solution. I'd like to have you run SuperAntipsyware also. That is good for finding the Tracking Cookies. We can only work with what we're given.

    The full cleaning programs are here: http://www.techspot.com/vb/post645589-1.html
     
  7. Frogshark40

    Frogshark40 TS Rookie Topic Starter Posts: 47

    If this persists, with AntiVir popping up saying "Threat Detected!" would a system restore be the best bet?
     
  8. Frogshark40

    Frogshark40 TS Rookie Topic Starter Posts: 47

    AVG popup:

    While opening file: C:\System Volume info\_restoreID 368F2c5058b3-4595-af15-fa0ff9e8d258}\rp316\a0016274.exe

    Trojan horse sheur.bzvs

    Clicked heal.
    ----edit
    AntiVir came up

    C:\System volume info\...\a0016335.exe
    is the tr/dldr.agent.abnd trojan

    ----at the time i edit this, 1000 tracking cookies were detected
     
  9. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    NO! Never do a System Restore when malware is suspected and/or when you are cleaning malware. It is most likely that the infection will be in the restore points and anything removed will get right back into the system.

    C:\System Volume info\ is the system restore. The files are protected and spyware/adware programs don't remove the infections from them. That's why we clean then at the end. Please follow along with the Steps and the logs.

    When malware cleaning is done, we have you drop off all the old restore points.

    You need to post the logs from the programs you ran. 10000Tracking Cookies is impressive. It's also an indication that a lot of third party files are getting on the system
     
  10. strac27

    strac27 TS Rookie Posts: 22

    http://www.techspot.com/vb/topic111363.html try this I have made a topic of how I got rid of virus's like that and if you try all the stuff like I said on that topic the virus should be gone but if not tell us what you found.
     
  11. Bobbye

    Bobbye Helper on the Fringe Posts: 16,335   +36

    TechSpot has a full cleaning program set up for all malware, not just viruses. It has already been recommended:

    New malware cleaning instructions from TechSpot:

    http://www.techspot.com/vb/post645589-1.html

    It includes running the programs and posting the logs. Assistance is given to find and remove all the malware entries. ven the advanced users usually need help finding all the entries and require help in handling them.
     
  12. strac27

    strac27 TS Rookie Posts: 22

    kk and I just posted some stuff I do to make sure I have 0 virus's and malware and all that lot also it helped me get rid of most of my infections that stopped me from booting up and doing anything else lol that topic is for people that want to make sure 100% of their HDD is clean.
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...