answersLogoWhite

0

📱

Computer Viruses

Computer viruses are harmful pieces of software which can reproduce themselves and automatically spread to other computers and networks. Questions about computer virus techniques and specific computer viruses belong here.

5,673 Questions

How can you trace and remove backdoors on your PC?

You can find if it is running on a port and process name by typing at a command prompt Strat>run(Type "command") when you get to a command prompt type "netstat -obna" you will get a list of executable that are involved with each port or listening ports. You can get a list of commands for NETSTAT by typing "netstat ?" after you find the file name you might have to boot in safe mode to remove it. You can run it in intervals by typing "netstat -obna 5" the five is the number of seconds it waits to run again you may change this number. Also you can look at http://www.symantec.com and do a search at the top.

How do you remove Trojan horse Downloader turown A from C System Volume Information td exe?

I'm using Windows 98se. This is the way I remove the Turown.A Trojan horse

Go to Start,Find,Files and folders, open, Type setup_TD.exe make sure you are searching on C: or whatever letter your hard drive is. Click on that file(setup_TD.exe and delete. Run you anti-virus and it will heal the infected files.Run again and it will say hopefull no virus found. Good Luck /this worked for me.

What does the computer virus Trojan horse Downloader Rameh b do?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

How can you get rid of Trojan downloader Rameh A?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

I had the virus in my "System Volume Information" folder. I turned off the system backup and then turned it back on. This destorys all the XP restore points, but it did get rid of my virus.

I tried that, it didn't work. How else can it be removed?

How do you remove Trojan downloader 5 N and what does it do?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

I had Downloader.Small.5.N & Downloader.Bridge.A.

AVG found them but could not vault them. I ran Norton - didn't find them. Looked all over the internet. People suggested deleting from the files. Did not work. People suggested Spybot. I had already run that and that did not fix it. They suggested Ad-ware 6 and RegSeeker. I did both. Regseeker came up with 850 files to "delete". I was not going to delete 850 files!!! until I saw someone else say the same - and he had "taken the bull by the horns", shut his eyes and deleted without reperussion - so I did the same eventually. No prob so far. I also ran the Ad-ware 6 and deleted those files (Trusting!!) Still AVG said they were there. Rebooted, rescanned, still there. Then this morning (13.04.04) AVG said it had healed Downloader.Bridge.A. and not sign of Downloader.Small.5.N - obviously taken out by RegSeeker or Adware.

Have no idea what either Trojan Horse does but I have not been adverseley affected by any of this awful time - yet!!

It took me 3 full days of searching as neither of these were to be found anywhere.

Good luck.

How do you get rid of Trojan horse Downloader keenval c and why does AVG antivirus not detect it?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

I use AVG free version 6.0.684 with latest updates on a Win 98 P166Mhz 97Mb RAM PC. This seems to detect and heal downloader.keenval types B,C,D&E. My PC detects these in C:\program files\common files\updmgr. Q:Where have any other users discovered these viruses, and do you know how they infect PCs?

support.Microsoft.com

I found this link and haven't tried it yet but it's worth a shot and the best answer I have found to date. Hope it helps.

i have avg free version and it finds it, it found keenval.c, j and b twice. keeps coming back though....

The Trojan horse is install via Euniverse WUpdater - Part of the Kazaa software, deleting it and running Kazaa redownloads the software, the solution is to install Diet K dietk.com and let this remove all the background rubbish that is installed along side Kazaa.

You will also add some additional features to Kazaa, well worthwhile.

All Trojan horses are hidden files so you would need to go to the Files Option (click the View tab)at Control Panel and uncheck both the *Hide file extension for known file types & *Hide protected operating system files (Recommended)-boxes, then OK yourself out. You will then need to restart your computer and and go into Safe Mode by holding the F8 key down -(kind of at the beginning of bootup). When you're at the DeskTop screen go to Start/ Search/ For Files and Folders and type up the NAME OF THE FILE & EXT which would have shown up on your Anti-Virus software, you can delete this file from here. Also, make sure to empty your Recycle Bin.

I have had 4 Trojan horses on my C drive and kinda figured out the above method a week ago. I deleted the Temp file (as these keep putting the same files back into your system) from the Restore folder after unchecking the hidden files boxes, then went to SafeMode to delete what virus files that were still there. My computer is now absolutely FREE of these pests!

PS. I also have AVG 6.0 (the free one) & also the Ad-aware 6 and I use them every day as my kids love to play games from the Internet.

The Free AVG version will identify Trojans but doesn't delete them all. Some it will only heal (temporarily) depending on the criticality of the file.

It most cases AVG will pick up keenval c. Sometimes it identifies the existence of the Trojan during its DOS scan. When windows has fully loaded you should then run AVG from the windows desktop . Run Complete Test but make sure it is set to heal file. This should resolve your problem.

You may wish to try the links below which will provide you with free anti-Trojan software

http://www.emsisoft.com/en/software/free/

This next link is another Trojan software program which is free to evaluate for 30 days.

http://www.simplysup.com/tremover/download.HTML

Good Luck!

How do you get rid of the Trojan horse Downloader Agent P virus when AVG can detect it but cannot heal or remove it?

A Trojan horse has infected your system. For a user like you this really sucks. But I can help you. It seems like the author of the malware has incorporated the abilities of spyware and viruses. This combination is deadly for a system. By what you have said I take it that your internet connection still works. So instead of searching the internet for software that may have malware in it I would go to trendmicro.com and run housecall. Housecall will search the componets of your system to find active malware. The Trojan is still working so trendmicro will definitely find it. Once it finds it it will attempt to restore the damaged files, delete the Trojan, delete the file, quarintine the infected file or deny the Trojan access. This is the best solution in my opinion because the site has got it down to a science.

There is another solution but it will cost you around sixty bucks. You could go out and by a rescue CD that would attempt to heal your system.

Good luck,

Computer Guru

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

Here's what I know about "downloader.agent":

1/ The file-name extension (after the 2nd decimal point)varies. Such as "Downloader.Agent.A", "Downloader.Agent.AS", "Downloader.Agent.MM", etc. So far I've found at least 50 different extensions.

2/ It creates the file "Kernell32.exe" in Windows, which is NOT a Microsoft Windows file. This file over-writes your main Dynamic Link Library file, (Kernell32.dll), which controls memory allocation for programs, ability to display images, and browser functionality.

3/ It alters the files: "Autoexec.bat", "Config.sys", and "Command.com". These are the critical files to start your machine.

4/ It creates a directory from the C:\ prompt called: "_restore\temp". You will find hundreds of files in here with a ".CPY" extension, which are NOT part of Windows. It is a log of your activity which is transmitted to someplace called the "Kazaa Network" through Outlook without your knowledge everytime you logon. If you're on DSL, you are transmitting constantly without knowing it. This is what slows down your page loading and prevents you from using icons on your desktop.

It also creates a sub-folder in Windows called "Plaxo". (C:\Windows\Plaxo). In here, you will find more CPY files, and a file called "Plaxo.Log". If you view this file, you will see a record of every single thing you've done since inheriting the virus. To view it, open your MS-DOS prompt, change the directory to c:\windows\plaxo , and then type in TYPE: PLAXO.LOG|MORE

(the | is the "pipe" sign above your backslash which lets you view the file one page at a time.)

By viewing this file, you can pinpoint the date/time you caught the virus.

It is impossible to delete the infected files, since they are in use by Windows and access is denied. Even if you change the properties of the files to delete them, Windows will not work properly since key-Windows files have been altered.

The only answer I've found so far to get rid of it, unfortunately, is to save all your user files on floppys or burn them to a CD, and RESTORE Windows from your Restore disc of Microsoft Windows disc.

I repair PCs, and have worked on more than a dozen machines in the past month all with this same problem.

Hope this helps.

Bob

Right ok bob im no computer whizz i had one of these Trojan downloaders you are talking about, burn all your files from your computer then restore it, what are you talking about all i did was run avg free then quarentined it and then ran malwere bytes and all traces of the virus has gone.

so there is no need at all to fully restore you computer or anything like that

How do you remove Trojan horse Downloader Bridge A from a bridge dll file?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

First off bridge.dll is a Trojan itself, so press start click run, type msconfig, click start up tab and uncheck bridge.dll if it is running on your startup, next click start, right click on my computer go to properties, click system restore take it off on all drives, then go to this link http://vil.nai.com/vil/stinger/ download the stinger antitrojan file run it on all drives, then i recommend you run avg free antivirus (at the same time if you like) these should get rid of them, also after you take off system restore go to control panel add remove programs and see if bridge.dll is on your program list uninstall it if it is (it wasnt for me) but if you do all this at the end just turn system restore back on should be gone or fixed by stinger :)

I experienced this on a cracks page running AVG: I had the AVG message about the bridge.dll Trojan come up asking me if I wanted to heal or ignore. I chose to heal, and I got a windows error saying the target of a file copy procedure (presumably the bridge.dll file) was missing. Does this mean it renamed itself already? I hope not. But I'm asking the people at Steve Gibson/AVG about it. When I run AVG on my windows/temp folder no viruses are present any longer (or so it says...) I haven't yet run the program on all drives.

I would like to know if anybody had similar experiences or knows what bridge.dll does (and will reveal this closely held trade secret...)

What is Trojan horse Downloader SiboCo B and how do you remove it?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

AnswerI updated my AVG Free Virus program this morning. It found the Downloader.Siboco.B and healed it. AnswerI updated my Free AVG this morning. Siboco is found but the program cannot heal the infected file. Additionaly, AVG cannot move the infected file to the virus vault neither delete it. AnswerThe only way I can remove it is going into safe mode and deleting the file that it is in. I am getting this virus everyday. IT is always in my Temp Folder Not my temporary internet folder but just Temp folder. It is always in the folder named ~7168797242.tmp AnswerI've got the same problem, I duel boot xp and xp on my computer. One instance for just plain copying cds and DVDs and that sort of thing with no internet or portals setup. This is the one that is problem free. The other instance is the one with the problem. I have to restart my computer in safe mode to rid the bug and then it shows back up again after I reboot. This seems to me that there is another program somewhere that is reloading it into the temp file after reboot. Any one have a solution AVG just finds it and cant delete it and if it did it'd probably reappear anyway. Please help. AnswerI ended up having to completely reload windows, after messing with it so long I accidentally erased an important file. However, here is what I learned. The Trojan changes the registry keys. While you are OFFLINE, run Spybot Search and destroy to eliminate the bad registry keys, then restart, and go into safemode to eliminate the virus itself. If you don't get rid of the bad registry keys, as soon as you get back online the Trojan re-enstalls itself. If this helps someone please post. If anyone out there has better information than this please post also!

Little Bit Farm

AnswerDon't know what it is. But go here and use the free on line virus scan and it will take care of it. http://housecall.antivirus.com Answerhttp://housecall.antivirus.com

Did the trick!

AnswerI see it in (porn) pictures or movies people have downloaded via kazza or such;

Disable System restore , Shutdown and restart in safe mode,

Open, My Computer, C:\WINDOWS\TMP and delete the infected file. You may need to right-click, properties and uncheck read-only or archive.

Exit and empty trash.

Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter. In the left panel, double-click the following: HKEY_CURRENT_USER>Software>Microsoft> Windows>CurrentVersion>Run In the right panel, locate and delete the entry: Msmc =\msmc.exe In the left panel, double-click the following: HKEY_LOCAL_MACHINE>Software>Microsoft> Windows>CurrentVersion>Run In the right panel, locate and delete the entry: Msmc =\msmc.exe (Note:is the Windows system folder, which is usually C:\Windows\System on Windows 95, 98 and ME, C:\WINNT\System32 on Windows NT and 2000, and C:\Windows\System32 on Windows XP.) Run a search from MyComputer while in reg-editor for msmc.exe and delete them. Close Registry Editor.

Shutdown and reboot

Answermany thanks to Howard T tho' did not see the msmc.exe under HKEY LOCAL MACHINE in the secondary part of the regedit info. Their was an entry 'kianxmjwnafxc C/WINDOWS/SYSTEM/ dhisic.exe i left it their then using mcafee quickclean run orphaned registery files and deleted it from their... whether it was related dunno. against the HKEY LOCAL MACHINE was AVG antivirus info so perhaps that had erased the msmc.exe.... it was a nuisance closing it meant losing start bar and icons.

What does Trojan horse Downloader small 6ba do?

1. Download and run firefox to protect your computer from future spyware attacks and pop ups which are coming in through internet explorer (Trojan downloaders, win32 ).Browser attacks aren't easy to spot because they piggyback on legitimate traffic that doesn't exhibit many obvious warning signs

http://securitynewsfromthenet.blogspot.com/2007/05/spyware-fighter-essentials.html

2. Run the vundo and combo fix http://securitynewsfromthenet.blogspot.com/2007/05/vundofix-and-combo-fix.html

3. Run Malwarebytes Anti-Malware

http://securitynewsfromthenet.blogspot.com/2008/03/malwarebytes-anti-malware-105.html

4. Run the anti spyware remove programs spybot http://securitynewsfromthenet.blogspot.com/2007/03/spybot-search-and-destroy-spyware-and.html and superantispyware http://securitynewsfromthenet.blogspot.com/2007/04/superantispyware-home-edition-free.html to get rid of the nasties

5. Run a complete scan with free curing utility Dr.Web CureIt!

http://securitynewsfromthenet.blogspot.com/2008/05/dr-web-cureit.html

Trojan horse Downloader Swizzor AF?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

How do you delete the Trojan downloader-LL?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

How do you remove Trojan Horse Agent BF Agent BN and Winshow AN?

good news ppl ime running on windows xp pro edition.ive just had the virus agent.bf and i finally got rid of it.heres how-------follow this link-------> download.com

once downloaded install and run update immediatley.finally run adaware once it finishes click next and it will show you your log file.where you will see your hijacker.right click any file in the log and select all objects then press next.it will tell you that all the files that were interupting your system will be moved to quarentine click ok.then before going back to your internet browser goto tools internet options and put your homepage back in the top bar.once apllied close all browsers again and run an updated avg virus test.your system should be clean.if this also works for you just leave a message in thanks ;)

You can remove this virus by following these steps .

1 Download and intall the Malwarebytes on your computer .

2 Update your Malwarebytes .

3 Scan your computer for all the malwares in your computer .

4 Remove all the malwares , found while scanning with the malwarebytes .

5 Restart your computer .

What is Trojan horse downloader keenval j and why would a virus protection not recognize the virus?

its not a virus its a trogan hourse i would recomend downloading spysweeper or spybot....and you get lots of bad things on your computer from looking at porn...... not that im saying you do

How do you remove the virus Trojan horse keenval j from Windows XP?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

How do you delete keenval b c e from the RESTORE TEMP files?

If you go to Start-> Programs->Accessories -> System Tools -> System Restore. It should open the System Restore Program. On the left side it should have System Restore Settings. Click on that. Then there should be a box to check to turn off monitoring on all drives. Check that and save. Now...if you know what program you downloaded that gave you the virus.....uninstall and delete it. Manually check the temp files to make sure they are empty. Empty the recycle bin and clear cookies from your browser and site history. Then run your Antivirus software. If it detected it before, it should see it if it is in the restore file(cause now it is a regular file and not skipped with the antivirus) and get rid of it. Make sure your .dat files for your antivirus is up to date.

How do you get rid of virus Trojan Horse Downloader Turown I?

AVG version 7.0 (www.grisoft.com)$33 US for 2yr license

The only anti-virus software that seems to address the turown virus.

How do you get rid of Trojan downloader siboco B virus when it cannot be quarantined or deleted because it is in the programs and settings file?

You need to run these 5 essential steps to remove all the spyware on your computer.

1. Run Deckard's System Scanner (DSS)

2. Run Malwarebytes Anti-Malware

3. Run the anti spyware removal programs spybot

4 Run Superantispyware

5. Run a complete scan with free curing utility Dr.Web CureIt!

Install threat fire which will enhance your antivirus protection

What do does the Trojan Horse Downloader Swizzor BB virus do and how do you get rid of it?

"Trojan Horse": The horse was left in Troy as a gift. "Beware of gift Horses". For PCs the gifts installed as trojans may be screensavers, games, atomic clock updaters etc.... that really do work! ... but beware of gift horses! Downloader: Something that downloads other software, usually without your knowledge. Beware of sites with virus encyclopedia definitions indicating a Trojan Downloader as beiing non-destructive.. which may be true.. because the other things it downloads can be destructive... and not even considered to be virii (IE: keyloggers to get banking passwords). How do you get rid of it. I use Ad-aware, SpyBot and SpyBlaster. Be vert wary of any other spyware programs./. as some are soyware in disguise! These were not completely effective. Add HijaakThis to capture logs. Be careful in using this program, but note strange looking exe files. The names seem to vary alot, but have strange names. A system I cleaned included names like Flagdraw.exe and "clock kind idle bolt.exe" I beliebve swizzor uses some kind of dictionary to assemble the exe names based on a property of the computer infected so that each infected system gets files with different names. Mark down the exact names and full paths of the files since Ad-Aware and Spybot do not appear to fully clean them off the systems. Before running Ad-Aware and Spybot run MS-Config, turn off virtually everything in Startup (especially programs like MSN Messenger, Real Networks etc. that can serve to download malware... and o course everything you don't know... even things you do know like SYSTRAY could be malware in disguise!) Only AFTER running ad-aware and spybot manually remove the exes in the paths shown in Hijaak if they still exist. If they are in 'TEMP' folders delegte everything in the temp folder. Also clear your Internet Cache (Tools - Internet Options) and change your Advanced - Security settings to clear the internet cache each time you close the browser. Check that no malware type BHOs (Browser Helper Objects) remain by running HiJaak... more than once. (They may re-appear a few seconds after getting a clean scan). Check that your browser no longer has odd menus to shopping and gambling sites. Finally delete any odd desktop icons like Casino Online and Poker. If you cannot drop them into the recycle bin right click and Delete. DO THIS for each user... running ad-aware and Spybot under each user account!

How do you get rid of the Trojan horse downloader.swizzor.2.AQ?

I am no good in English but. I get rid of that horse today. Some programs brings it in. Find the map vhere the horse is, and delete it, and find the program(s), that brings it in, and delete it.I am no good in English. It is a longer vay to discripe it here., and in English.In `start`find the program `find`Find the map 32warn in files and maps in all the harddiscs. The map is hidden but delete the maps and the horse is avay. Find the program installet the day about the time you saw the Trojan horse, and delete the program, and I beliewe that the horse is away.`systemgendannelsen`deaktiver and aktiver den, to delete it from there.

How do you get rid of a Trojan horse downloader Dyfica.2.An in RestoreTemp A0009739 CPY?

It has some how saved itself in one of your system restore points. Disable system restore from the system properties under control panel, should take care of things. After your sure it has been removed. Turn system restore back on.

How do you get rid of Trojan horse donloader.xten.a found in System Volume Information?

If the virus is in the system volume information Download AVG from Grisoft.com, it is free. AVG will not pick it up straight away though. Follow the steps in this page and run AVG complete test. AVG should have picked up your virus this time. (You have the option in AVG to run a custom scan where you can set it to scan the system volume information only).

How do you remove Downloader.Swizzor.2.BG from System Volume Information?

You can remove any virus from System Volume Information, by shutting down System Restore, restarting your computer and then start System Restore Again. When you shutdown System Restore, all Restore Points are deleted (including the virus(ses)). When you restart System Restore, it automaticly makes a new (and clean) Restore-point.

Good Luck! Jawwi :-)

I have had this virus before, and i downloaded grisoft.com free virus remover software. It locaed it and automatically removed it. andy :'P