Trojans

Trojans

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trojans B.W. 09-01-2007
---> Re: Trojans Milo \(MSPSS\)09-02-2007
Posted by Leythos on September 2, 2007, 7:29 am
If you were  Registered and logged in, you could reply and use other advanced thread options
bwaller@aapt.net.auxxx says...
> You mean reformatting the hard drive?

Sort of, I mean deleting the partitions, rewriting the MBR, doing all of
this from a clean machine or from a BOOT CD.....

There really is no way to "Clean" a compromised machine, at best you can
only get the stuff YOU can find or stuff that someone else has
identified and written into a program to remove for you - and if you
consider that many newer malware are active for days and weeks before
they are detected...

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by Milo \(MSPSS\) on September 2, 2007, 12:37 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Reformating the Hard Drive should be the a last option, as a preventive
measure if you have some family members who love browsing the web give them
or make sure to make them understand and use a limited account, than
administrators - On limited account you still have a buffer zone ( you can
pretty much do what you regularly do but you cant install things directly,
which can make a difference if anyone in your familty or yourself was
mislead by things while browsing the web, quite common this guys who make
this "infections", use quite a lot the reverse psychology method in luring
browsers )

> You mean reformatting the hard drive?
>
> B.W.
>
>> bwaller@aapt.net.auxxx says...
>>> My question is, if one of these Trojans has been on my PC for a week
>>> before
>>> being detected what kind of damage may it have done to my computer.
>>
>> The amount and type of damage is unknown without having the PC before
>> you've "cleaned" it.
>>
>> A "cleaned" PC is only suspected of being Clean no matter what/how you
>> clean it. The only clean system, after a compromise, is a wiped and
>> rebuilt system.
>>
>> --
>>
>> Leythos
>> - Igitur qui desiderat pacem, praeparet bellum.
>> - Calling an illegal alien an "undocumented worker" is like calling a
>> drug dealer an "unlicensed pharmacist"
>> spam999free@rrohio.com (remove 999 for proper email address)
>
>


Posted by Leythos on September 4, 2007, 6:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options
4jpaca@mssupport.microsoft.com says...
> Reformating the Hard Drive should be the a last option, as a preventive
> measure if you have some family members who love browsing the web give them
> or make sure to make them understand and use a limited account, than
> administrators - On limited account you still have a buffer zone ( you can
> pretty much do what you regularly do but you cant install things directly,
> which can make a difference if anyone in your familty or yourself was
> mislead by things while browsing the web, quite common this guys who make
> this "infections", use quite a lot the reverse psychology method in luring
> browsers )

Actually, since you can't ensure that your drive is clean, even if you
use multiple anti-malware tools, formatting should be your first option
if you want a clean system.

Secondary options are only to make the machine clean enough to salvage
data from it before you format/wipe it.

If you take a typical machine that's been compromised by kids/ignorant
people browsing, loading P2P apps, and then the malware loading it's
friendly other malware, you have a machine with 20+ different malware on
it. Of those 20, you don't really know what they are doing, what they
have loaded, you don't know what unknown malware they've loaded.... So,
while you can clean it of all KNOWN malware you can't possibly be sure
you got it all.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by Milo \(MSPSS\) on September 2, 2007, 12:33 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sad to say there is no general design for W32 infection after effects, but
there are thing for sure ( quite common that manifest ) Slowdown in your
system, ad pop-ups, lockdowns on your options to open some parts of the
system ( access denied ), to the point it would say no internet connection -
but it still does. - This instances changes depending on such infections
some are as potent for 2 days or instantly some in the other hand takes a
month or more to manifest.

Rule of the thumb to avoid such ( be carefull what you click on - video
streaming sites ), and what you download in your system from music within
folders to actual applications which the company you dont know.

>I have had in the past on my laptop three different Trojans (all the WIN 32
>varieties). With the help of the experts from this very useful Newsgroup I
>have been able to remove them.
>
> As I have been unable to set up the free version of Avast to automatically
> perform a daily schedule to run a scan, I run a scan once a week manually.
>
> My question is, if one of these Trojans has been on my PC for a week
> before being detected what kind of damage may it have done to my computer.
> When I did a search to find out what kind of problems they may cause (so
> could not be on the look out for specific kinds of behaviours) I could not
> find any information. So once this has happened can you ever be certain
> your PC has not been compromised and is clean? The only change I seem to
> notice recently is a slight slow down in operation, but then it could be
> my imagination.
>
> TIA
>
> B.W.
>


Posted by B.W. on September 3, 2007, 3:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks to everyone for their replies to this query. I will take note of
what you have all advised and will be on the lookout for any suspicious
behaviour from these Trojans. I will also look at using Limited accounts.

B.W.


> Sad to say there is no general design for W32 infection after effects, but
> there are thing for sure ( quite common that manifest ) Slowdown in your
> system, ad pop-ups, lockdowns on your options to open some parts of the
> system ( access denied ), to the point it would say no internet
> connection - but it still does. - This instances changes depending on such
> infections some are as potent for 2 days or instantly some in the other
> hand takes a month or more to manifest.
>
> Rule of the thumb to avoid such ( be carefull what you click on - video
> streaming sites ), and what you download in your system from music within
> folders to actual applications which the company you dont know.
>
>>I have had in the past on my laptop three different Trojans (all the WIN
>>32 varieties). With the help of the experts from this very useful
>>Newsgroup I have been able to remove them.
>>
>> As I have been unable to set up the free version of Avast to
>> automatically perform a daily schedule to run a scan, I run a scan once a
>> week manually.
>>
>> My question is, if one of these Trojans has been on my PC for a week
>> before being detected what kind of damage may it have done to my
>> computer. When I did a search to find out what kind of problems they may
>> cause (so could not be on the look out for specific kinds of behaviours)
>> I could not find any information. So once this has happened can you ever
>> be certain your PC has not been compromised and is clean? The only
>> change I seem to notice recently is a slight slow down in operation, but
>> then it could be my imagination.
>>
>> TIA
>>
>> B.W.
>>
>



Similar ThreadsPosted
? about Trojans July 16, 2005, 7:14 am
TROJANS!!!! August 9, 2006, 10:36 am
Trojans SBI October 30, 2007, 10:18 am
Trojans(?) January 13, 2008, 3:34 pm
Re: Trojans? Spy-ware? Oh my! June 15, 2007, 7:01 pm
Re: Trojans? Spy-ware? Oh my! June 15, 2007, 8:09 pm
Trojans and TCP view January 24, 2008, 2:33 pm
The Cleaner finds RAS trojans, I can't find them on harddrive November 19, 2007, 2:52 am
Norton Enterprise AV - scan missing viruses, trojans, keyloggers, rootkits, etc??? April 12, 2007, 6:33 pm

The site map in XML format XML site map

Contact Us | Privacy Policy