User Name
Password

Go Back   Planetarion Forums > Non Planetarion Discussions > General Discussions
Register FAQ Members List Calendar Arcade Today's Posts

Reply
Thread Tools Display Modes
Unread 21 Aug 2004, 23:06   #1
Sunday8pm
Banned
 
Join Date: Jul 2004
Posts: 2,442
Sunday8pm is an unknown quantity at this point
[Viruses/Trojans] Help me find out some stuff

Ok I've trawled google a bit (perhaps my search terms are poor) and I've trawled the horridly unavigatible Norton site...

However I've been unable to uncover any further info on a trojan called Download.swizzor

Now I ask here cause it turns out one of my gf's friends has got this virus on her pc, I headed over last night spent all night UPDATING The system... (she hadn't got ONE xp patch since XP came out..) Applying AVG and SS&D and managed to heal all 4 infected files found.... I just want to make certain that it's gone for good or if it's buried somewhere in the boot that will shove it back on the system with every reboot etc...

Feel free to ask questions and give advice...
Sunday8pm is offline   Reply With Quote
Unread 21 Aug 2004, 23:36   #2
Leshy
Mr. Blobby
 
Leshy's Avatar
 
Join Date: Nov 2000
Location: Belgium
Posts: 8,271
Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.
Re: [Viruses/Trojans] Help me find out some stuff

Reboot the system and scan again.

If it's not there, it's gone.

Genius++;
__________________
http://www.leshy.net
Leshy is offline   Reply With Quote
Unread 21 Aug 2004, 23:38   #3
Nadval
m00
 
Nadval's Avatar
 
Join Date: Jun 2001
Location: uk, Nottingham
Posts: 252
Nadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant futureNadval has a brilliant future
Re: [Viruses/Trojans] Help me find out some stuff

Leshy with his infinate logic speaking there...
Nadval is offline   Reply With Quote
Unread 21 Aug 2004, 23:56   #4
Leshy
Mr. Blobby
 
Leshy's Avatar
 
Join Date: Nov 2000
Location: Belgium
Posts: 8,271
Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.
Re: [Viruses/Trojans] Help me find out some stuff

My logic is only surpassed by my penis size!
__________________
http://www.leshy.net
Leshy is offline   Reply With Quote
Unread 22 Aug 2004, 00:25   #5
Superpig #1
^ ^ Clearly Stolen ^ ^
 
Superpig #1's Avatar
 
Join Date: Aug 2002
Location: Exeter
Posts: 753
Superpig #1 is infamous around these parts
Re: [Viruses/Trojans] Help me find out some stuff

Then your logic is crap.
__________________
This is a stick - |
This a squiggly line - S
This is a hole - o
This is a man in a wheelchair - &

and that was my sig.
Superpig #1 is offline   Reply With Quote
Unread 22 Aug 2004, 00:27   #6
Demon Dave
Insanity Prawn Boy!
 
Demon Dave's Avatar
 
Join Date: Dec 2001
Location: In a bush where you can't find me
Posts: 2,474
Demon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriendDemon Dave needs a job and a girlfriend
Re: [Viruses/Trojans] Help me find out some stuff

i had that virus, nasty little bugger it was too. i know i've asked this before, but no-one has ever given me an answer: does anyone here know anything about a virus called Java/Byte.Verifyer (or something similar) that ONLY ever appears when an Ad-Aware scan is run and NEVER comes up on an AVG scan?
__________________
They shall not grow old, as we who are left grow old:
Age shall not weary them, nor the years condemn.
At the going down of the sun and in the morning
We shall remember them.
Demon Dave is offline   Reply With Quote
Unread 22 Aug 2004, 03:03   #7
JetLinus
Friendly geek of GD :-/
 
JetLinus's Avatar
 
Join Date: Nov 2000
Location: On my metal roid
Posts: 923
JetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud of
Arrow Re: [Viruses/Trojans] Help me find out some stuff

Quote:
Originally Posted by Demon Dave
i had that virus, nasty little bugger it was too. i know i've asked this before, but no-one has ever given me an answer: does anyone here know anything about a virus called Java/Byte.Verifyer (or something similar) that ONLY ever appears when an Ad-Aware scan is run and NEVER comes up on an AVG scan?
I've come across it. My anti-vir realtime guard actually warned me, when it was accessed in my temporary internet files folder.
It didn't spread from there, and apparently it's not that dangerous I'd say. Seems like a web-only thingy, that could harm you if you didn't have Windows / IE patches, a virus scanner and a firewall.
WHY it didn't come up with your antivirus? Well, maybe it's crap or has different signature files, that don't even classify this thing as virus....

I also know that sometimes it's "illegal" for some kind of virus scanners to ban dialers or ad-ware, as they're "commercial programs".




@sunday:
Have you disabled the automatic Windows system restore? [alt] + [pause], system restore, disable for all drives. Then reboot. Scan. Reboot to safe mode to be really sure. Scan.
Reboot. Turn system restore back on.

Also, load a specific removal tool for this virus.

If you got the exact virus name, google should do the trick.


And: wrong forum.
__________________
[»] Entropy increases! :-/
JetLinus is offline   Reply With Quote
Unread 22 Aug 2004, 12:36   #8
Sunday8pm
Banned
 
Join Date: Jul 2004
Posts: 2,442
Sunday8pm is an unknown quantity at this point
Re: [Viruses/Trojans] Help me find out some stuff

Thanks Jetlinus, no thanks to the others.
Sunday8pm is offline   Reply With Quote
Unread 22 Aug 2004, 12:41   #9
Leshy
Mr. Blobby
 
Leshy's Avatar
 
Join Date: Nov 2000
Location: Belgium
Posts: 8,271
Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.
Re: [Viruses/Trojans] Help me find out some stuff

Goddamnit, JetLinus said practically the same thing as I did
__________________
http://www.leshy.net
Leshy is offline   Reply With Quote
Unread 22 Aug 2004, 14:45   #10
JetLinus
Friendly geek of GD :-/
 
JetLinus's Avatar
 
Join Date: Nov 2000
Location: On my metal roid
Posts: 923
JetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud of
Arrow Re: [Viruses/Trojans] Help me find out some stuff

Quote:
Originally Posted by Leshy
Goddamnit, JetLinus said practically the same thing as I did
You forget a tiny but important detail: Automatic Windows System Restore would restore (hence the name) the virus after reboot. This is one drawback of a great invention actually, that can't be neglected...

Also 2 reboots (one in safe mode, one to normal) are better than one.
__________________
[»] Entropy increases! :-/
JetLinus is offline   Reply With Quote
Unread 22 Aug 2004, 14:49   #11
Sunday8pm
Banned
 
Join Date: Jul 2004
Posts: 2,442
Sunday8pm is an unknown quantity at this point
Re: [Viruses/Trojans] Help me find out some stuff

Yah I forgot about the system restore, which is extremely handy advice.
Sunday8pm is offline   Reply With Quote
Unread 22 Aug 2004, 16:30   #12
Leshy
Mr. Blobby
 
Leshy's Avatar
 
Join Date: Nov 2000
Location: Belgium
Posts: 8,271
Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.
Re: [Viruses/Trojans] Help me find out some stuff

Quote:
Originally Posted by JetLinus
You forget a tiny but important detail: Automatic Windows System Restore would restore (hence the name) the virus after reboot.
System Restore doesn't automatically trigger on a reboot. Unless you've ****ed some critical Operating System files, which Windows generally doesn't even let you delete to begin with.

Aditionally, everything that's loaded during a safe boot is also loaded during a regular boot. So there's little need to do a seperate boot into Safe Mode if you want to check whether a virus is still active or not.
__________________
http://www.leshy.net
Leshy is offline   Reply With Quote
Unread 22 Aug 2004, 16:47   #13
JetLinus
Friendly geek of GD :-/
 
JetLinus's Avatar
 
Join Date: Nov 2000
Location: On my metal roid
Posts: 923
JetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud of
Arrow Re: [Viruses/Trojans] Help me find out some stuff

Quote:
Originally Posted by Leshy
System Restore doesn't automatically trigger on a reboot. Unless you've ****ed some critical Operating System files, which Windows generally doesn't even let you delete to begin with.
Some viruses get restored by Windows. Even if it was just ONE single virus, it would still be sufficient to let me disable system restore once.
(One example being Blaster btw).

I mean, it even makes sense, "corrupted system files" (corrupted by the virus even in the repair folder) get restored.



Quote:
Originally Posted by Leshy
Aditionally, everything that's loaded during a safe boot is also loaded during a regular boot. So there's little need to do a seperate boot into Safe Mode if you want to check whether a virus is still active or not.
Nope. Why do you think there's a safe mode?



I mean, same really bad trojans / viruses replace system files, or register as services or whatever themselves.
Or you could load a virus as driver.

Compare running processes in normal and safe mode, there are less in the latter (could be because of reduced autostart).

Anyway, this was about points to be 100% sure (or at least as sure as possible).
__________________
[»] Entropy increases! :-/
JetLinus is offline   Reply With Quote
Unread 22 Aug 2004, 17:00   #14
Sunday8pm
Banned
 
Join Date: Jul 2004
Posts: 2,442
Sunday8pm is an unknown quantity at this point
Re: [Viruses/Trojans] Help me find out some stuff

Jetlinus is right here cause this is how I had to go about removing one certain trojan before, it's just been over a year since I did it and I was following instructions on the norton site.

Hence I needed some affirmation about the processes.
Sunday8pm is offline   Reply With Quote
Unread 22 Aug 2004, 18:59   #15
Leshy
Mr. Blobby
 
Leshy's Avatar
 
Join Date: Nov 2000
Location: Belgium
Posts: 8,271
Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Leshy has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.
Re: [Viruses/Trojans] Help me find out some stuff

Quote:
Originally Posted by JetLinus
Some viruses get restored by Windows.
That would require for Windows to somehow ignore the modification of the critical file by the virus, make a system restore point of the file including virus, then see the file as corrupted after the virus scanner fixes it, and restoring it.

I didn't know the Windows Restore function actually triggered on it's own, though, other than with the exception of replacing damaged and/or missing critical files belonging to the Operating System with their original versions. Which, in fact, should prevent a virus from actually damaging these files, considering Windows Restore should automatically swap the infected files for clean ones.

Granted, this is Microsoft we're talking about.
Quote:
Compare running processes in normal and safe mode, there are less in the latter (could be because of reduced autostart).
That's what I said, isn't it. Viruses loading as a driver or service might not do so in Safe Mode - hence booting in Safe Mode would indicate a healthy PC, whereas booting in Normal Mode would trigger the virus again when the additional drivers are loaded.

It's only useful if you have a resident virus that your virus scanner somehow can't remove. If you boot the PC in normal mode and there is no infection, booting it in Safe Mode and scanning again won't do anything other than waste time.
__________________
http://www.leshy.net
Leshy is offline   Reply With Quote
Unread 22 Aug 2004, 19:00   #16
Dace
so f*cking zen
 
Dace's Avatar
 
Join Date: Jan 2003
Location: Hitting Bottom
Posts: 8,499
Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.Dace has ascended to a higher existance and no longer needs rep points to prove the size of his e-penis.
Re: [Viruses/Trojans] Help me find out some stuff

"Switch the computer on and off at the wall to fix it"
__________________
On a long enough timeline, the survival rate for everyone drops to zero.
Dace is offline   Reply With Quote
Unread 22 Aug 2004, 19:06   #17
Kumnaa
Unreregistered User
 
Kumnaa's Avatar
 
Join Date: Dec 2002
Posts: 824
Kumnaa is infamous around these parts
Re: [Viruses/Trojans] Help me find out some stuff

computers can get a virus ?
__________________
I have been unbanned.
Kumnaa is offline   Reply With Quote
Unread 22 Aug 2004, 20:03   #18
JetLinus
Friendly geek of GD :-/
 
JetLinus's Avatar
 
Join Date: Nov 2000
Location: On my metal roid
Posts: 923
JetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud ofJetLinus has much to be proud of
Arrow Re: [Viruses/Trojans] Help me find out some stuff

Quote:
Originally Posted by Leshy
That would require for Windows to somehow ignore the modification of the critical file by the virus, make a system restore point of the file including virus, then see the file as corrupted after the virus scanner fixes it, and restoring it.

I didn't know the Windows Restore function actually triggered on it's own, though, other than with the exception of replacing damaged and/or missing critical files belonging to the Operating System with their original versions. Which, in fact, should prevent a virus from actually damaging these files, considering Windows Restore should automatically swap the infected files for clean ones.
K, admittedly, I have no exact idea of how windows restore works.
I mean the "automatic" restore now, not that about restore points.
But apparently for every working configuration, your system files get backed up.
So at one point, the infected virus file gets backed up. Yes, apparently it isn't checked properly enough or whatever.
Anyhow, if you reboot, Windows detects the modification, and gets the (infected) backup file.

Hmmm, so, it seems we've discovered that the automatic windows system restore is shit. As it should've detected the virus infection in the first place, and then the original file would've replaced the virus. But it didn't.


Quote:
It's only useful if you have a resident virus that your virus scanner somehow can't remove. If you boot the PC in normal mode and there is no infection, booting it in Safe Mode and scanning again won't do anything other than waste time.
Yep, that's what I actually ment. I was talking about removing, while you were talking about finding. So you were right actually.

Although, having virusses fight virus-scanners sometimes, it can only be of advantage if the scanner runs and the virus DOESN'T.
__________________
[»] Entropy increases! :-/
JetLinus is offline   Reply With Quote
Reply



Forum Jump


All times are GMT +1. The time now is 04:00.


Powered by vBulletin® Version 3.8.1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2018