PDA

View Full Version : Trojan problems, why?


Lorrae
08-09-2005, 10:51 AM
Hi Everyone,

I have a question about Trojans. I got my computer checked and fixed recently. Everything seemed good until the last few days. Microsoft antispyware found a browser trojan on my puter. It said it got rid of it. Yesterday Avg found a Dropper.Agent.8.B on my computer. It was in C:\WINDOWS/$NtServicePackUninstall$\cisvc.exe .. it said back up copy infected .. . no idea what that was about.

I went to trendy, re scanned and it no longer found the trojan. I am not sure what to do. I empty the avg isolation thingy, now worried I put it back on my puter.

I went to a site from here and it check my puter, all ports are tight and secure, the only problem is it pings back. No idea how to stop that. My firewall is the microsoft spy one, and I think the rogers/yahoo one.

This is frustrating because 3 months ago I got a trojan. I have had computers for years and nada til now. I have avg freeware on my p uter, spybot, and microsoft antispayware. I don't know why they are not stopping the trojans from hitting me or is it on my computer and hiding then roaming? I am not a surfer so no idea where I am getting them unless it is from the darn bulk stuff I get that I don't want in my outlook express emails that get sent to me from strangers I don't even know.

I have windows xp pro, amd +1900, 1gig ram, raedon 9600 vid card

Any suggestions would be appreciated and is there a way that I can stop my computer from pinging when it is pinged.. thankyou in advance for any solutions.. please keep it layman because I get lost in all the buttons to push and stuff.. wish I knew more and my mind computed a lot simpler.. thanks again :)

Digiital
08-09-2005, 11:01 AM
First boot into FAST MODE and do a virus scan. This will prevent most programs from running and give you a better chance at finding anything, AntiVirus and Spyware. I would also run Adaware(you can never have to many anti spyware programs).
If you want to try another VERY good Antivirus program get AVAST(it's free).

Second, if your running IE for oyur browser. STOP. Get something else. FireFox for example. IE is one of the biggest cut that just doesn't want to heal. Most cases it's not someone finding a hole in your firewall or a open port, it's just by visting a website and before you know it, your infected.

stan94
08-09-2005, 12:23 PM
download link for firefox webbrowser (use this to surf the net not IE)

http://www.mozilla.org/products/firefox/

link that explains how to get into safe mode in XP ( do all your scans in safe mode as Digiital mentioned)

http://www.computerhope.com/issues/chsafe.htm#02

get ad-aware if you dont already have it and do a scan with it

http://www.majorgeeks.com/Ad-Aware_SE_Personal_d506.html

Another suggestion dont use outlook for email unless it's absolutely necessary. Setup a free web-based email account at either Yahoo! or Hotmail. If your ISP provides you access to your email through a browser like IE or Firefox use that instead of outlook.

Most the of the trojans you are getting are probably through outlook attachments.

Digiital
08-09-2005, 12:34 PM
Another suggestion dont use outlook for email unless it's absolutely necessary. Setup a free web-based email account at either Yahoo! or Hotmail. If your ISP provides you access to your email through a browser like IE or Firefox use that instead of outlook.

Most the of the trojans you are getting are probably through outlook attachments.

Or get Thunderbird
http://www.mozilla.org/products/thunderbird/

As far as I know, AVG doesn't scan Emails unless it's Outlook, AVAST will scan it all. Emails doesn't matter the client. Scans as your surfing(webbrowsing), P2P, IM'ing.

frostyone
08-09-2005, 08:43 PM
Appears to be a false positive Lorrae.

From: "AVG Technical Support" <technicalsupport@grisoft.com>
To: <***************>
Sent: Tuesday, August 09, 2005 7:16 AM
Subject: Re: G#05271125 - False Positive? "Dropper.Agent.8.B"
Yesterday, we noticed a false alarm on file
>
> C:\Windows\System32\cisvc.exe
>
> This file was detected as a
>
> Dropper.Agent.8.B
---------

People are reporting false positives for Dropper.Agent.8.B in various cisvc files including
c:\windows\$NtServicePackUnistall$\cisvc.exe

http://forum.grisoft.cz/freeforum/read.php?4,45340,backpage=,sv=