CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Trojan horse dialer ?

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Grisoft AVG [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
TEEDUB2

Trooper
Trooper


Joined: Aug 28, 2004
Posts: 19
Location: USA

PostPosted: Sat Aug 28, 2004 11:25 pm    Post subject: Trojan horse dialer ?
Reply with quote

I have AVG 6 (free version). Every time I run Ad-Aware SE, AVG resident shield pops up and says " Virus....Trojan horse dialer" is found in file "C:\Documents and Settings\name\Local Settings\Temp\svchost.exe".
Then it tells me to run AVG. When I run AVG it finds nothing ! My AVG is updated as of today. I tried running Avg with system restore off, still nothing found. My computer seems fine. Could this be a false positive? if so how do I get rid of the resident shield popup?

Thanks in advance for your help..

Back to top
View users profile Send private message
!ComputerDoctor

Sergeant
Sergeant


Joined: Aug 28, 2004
Posts: 135


PostPosted: Sun Aug 29, 2004 3:00 am    Post subject:
Reply with quote

Go to the listed folder and delete all that is in it. d/l Spybot search and destroy and AdAware. Run the programs and fix all the problems that they find. This should address your situation.

Back to top
View users profile Send private message
TEEDUB2

Trooper
Trooper


Joined: Aug 28, 2004
Posts: 19
Location: USA

PostPosted: Sun Aug 29, 2004 2:38 pm    Post subject:
Reply with quote

Thanks for the reply Computer Doctor ! (I forgot to mention that I'm running windows xp). Your solution sounds like it will work, however I can't find file "documents and settings" even searching hidden files ! I'm new at computers "you probably noticed". How do I find this file?

Thanks for your help again..

Back to top
View users profile Send private message
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Sun Aug 29, 2004 5:23 pm    Post subject:
Reply with quote

try these.
aČ Free is also a good malware cleaner and can be downloaded from: http://www.emsisoft.com/en/software/download/?

Then update your virus scanner and scan your system again or use one of these free on-line scanners (note some spyware has been known to disable PC based AV scanners):
http://housecall.trendmicro.com or http://www.pandasoftware.com/activescan/com/activescan_principal.htm.


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
TEEDUB2

Trooper
Trooper


Joined: Aug 28, 2004
Posts: 19
Location: USA

PostPosted: Mon Aug 30, 2004 2:05 pm    Post subject:
Reply with quote

Thanks for the reply wawadave ! I tried aČ it found a couple things but nothing in Documents and settings.....I tried panda same results......
After all updates,AVG resident sheild still pops up during Ad-Aware se search ! ! ! I think if I could find the file " C:\Documents and Settings\name\Local Settings\Temp\svchost.exe". I could solve the problem.. So how does one locate this file?

p.s. By the way I treid Housecall also but had difficulty on download and couldn"t run it.

Thanks again

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Mon Aug 30, 2004 6:58 pm    Post subject:
Reply with quote

Hi TEEDUB2!

For WinXP:

Ensure that system and hidden files are set to show like so:

- Right-click the Start button, and choose 'Open'.
- Select the Tools menu and click Folder Options.
- Select the View Tab.
- Under the Hidden files and folders heading select "Show hidden files and folders".
- UNcheck the "Hide protected operating system files (recommended)" option.
- UNcheck "Hide file extensions for known file types"
- Click Yes to confirm.
- Click OK.

For WinXP only: Next go to Search and scrolldown using the scroll bar on the right. Go down to More advanced options and click. Be sure the first three boxes are selected:

Search System folders
Search Hidden Files and folders
Search SubFolders

Next, open Windows Explorer.

Look for C:\Documents and Settings in the left hand panel. There should be a "+" beside it. Click it. Now look for the rest in order "name\Local Settings\Temp\

You should keep your Temp folders clean and clear regularly. Here's something which can help. It's called Crap Cleaner and is excellent freeware. http://www.ccleaner.com/


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
TEEDUB2

Trooper
Trooper


Joined: Aug 28, 2004
Posts: 19
Location: USA

PostPosted: Tue Aug 31, 2004 3:31 pm    Post subject:
Reply with quote

Hey Prince_Serendip, thanks for the reply !! I thought I had it wipped....
Did everything you suggested. Got to my daughters docs and settings and a windows explorer window popped up saying

" documents and settings\name is not accessible"
"access denied"

also when I place the cursor on the file it says

"file is empty"

Did not try "crap cleaner" yet......

Any other suggestions ???

Thanks again for all of your time and help!!!!!

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Aug 31, 2004 5:14 pm    Post subject:
Reply with quote

Hi TEEDUB2!

Quote:
" documents and settings\name is not accessible"
"access denied"


You need to change the Administrative Settings for your daughter so you can access Documents and Settings. I suppose you have that blocked on purpose? Are you not able to access this as an Administrator, instead of doing it from your daughter's logon?


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
TEEDUB2

Trooper
Trooper


Joined: Aug 28, 2004
Posts: 19
Location: USA

PostPosted: Sat Sep 04, 2004 11:42 pm    Post subject:
Reply with quote

Hey Prince_Serendip, thanks again for the reply.....I changed my daughters setting to administrator and tried to do what you said but still shows the same thing("access denied") Any other suggestions?

Thanks again..

p.s. I also ran crapcleaner .... no change in virus.......

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sun Sep 05, 2004 8:22 am    Post subject:
Reply with quote

Hi TEEDUB2!

You need to disable 'simple file sharing'. Click tools->folder options->view, remove tick from 'use simple file sharing'.


Best regards Wink


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
TEEDUB2

Trooper
Trooper


Joined: Aug 28, 2004
Posts: 19
Location: USA

PostPosted: Tue Sep 07, 2004 12:39 am    Post subject:
Reply with quote

Hey Prince_Serendip,
Did what you suggested and realized I hadn't un-hidden my daughters files and bingo !!!! there was her docs. and settings with the bad file !!!! Deleted it and up popped a couple of others....I continued to run ad-aware and avg a few times and I think there gone.... Thanks so much for your help and patients with a newbee..... Very Happy

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Sep 07, 2004 3:02 pm    Post subject:
Reply with quote

Hello TEEDUB2!

Glad to help you and to learn something more. I will remember to suggest how to show the files and folders next time. Wink

You are most welcome too! Thumbs Up

Have a great day!

If you should have need of us again, we will be here to help you. Very Happy


_______________________________________
NOTE FROM FORUM HOSTS: This thread is now closed. Should you need it reopened, please PM a Host/mod. Everyone else having a similar issue, please launch a new topic for yourselves. Thank you.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Grisoft AVG All times are GMT
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer