Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Trojan virus. Advice please.

Thread Tools
 
Search this Thread
 
Old Oct 6, 2007 | 03:02 PM
  #1  
paulr's Avatar
paulr
Thread Starter
Scooby Regular
 
Joined: Jan 2005
Posts: 15,623
Likes: 0
From: Lincolnshire
Default Trojan virus. Advice please.

Hi,
Eveytime i open Internet Explorer i get this warning.



I move it to the vault but it keeps coming back.
I found it and its here. I delete it but it returns.

http://homepage.ntlworld.com/paul123/paul123/schll.jpg

I've got AVG and zone alarm, windows xp.

Any advice.

thanks
Paul.

Last edited by paulr; Oct 6, 2007 at 03:03 PM. Reason: cvv
Reply
Old Oct 6, 2007 | 03:31 PM
  #2  
Markus's Avatar
Markus
Scooby Regular
25 Year Member
 
Joined: Mar 1999
Posts: 25,080
Likes: 0
From: The Great White North
Default

Reboot into safe mode then run your AVG software and get it to remove the item and then see if it comes back. You could also try healing the file, or if possible actually get it deleted.
Reply
Old Oct 6, 2007 | 07:40 PM
  #3  
paulr's Avatar
paulr
Thread Starter
Scooby Regular
 
Joined: Jan 2005
Posts: 15,623
Likes: 0
From: Lincolnshire
Default

Originally Posted by Markus
Reboot into safe mode then run your AVG software and get it to remove the item and then see if it comes back. You could also try healing the file, or if possible actually get it deleted.
None of that worked. It came back when i opened IE.
Reply
Old Oct 6, 2007 | 08:08 PM
  #4  
ScuuBdoo's Avatar
ScuuBdoo
Scooby Regular
 
Joined: May 2006
Posts: 927
Likes: 0
From: Ireland
Default

you need to open the system registry. Then navigate your way to where the file is and delete it manually. That should fix the problem.
Reply
Old Oct 6, 2007 | 10:14 PM
  #5  
D16GER's Avatar
D16GER
Scooby Regular
 
Joined: Sep 2005
Posts: 924
Likes: 0
Default

Best thing I can suggest is to download the trial of Kaspersky AV here.... Kaspersky Anti-Virus free trial download

and also download the updates for it here.... Setting Updater

Then, disconnect from the internet and turn off AVG and Zone Alarm completely, even uninstall them if you have to.

Once done, install Kaspersky and update it, then let it do it's thing, it's an awesome piece of kit. Oh and maybe even consider buying it, AVG is a useless pile of dung in my experience. I know lots swear by it, but I swear at it

You may also need to run a Spyware remover, you can't beat Spybot for that job.... The home of Spybot-S&D!

And finally, once you have ran those programs, go get HijackThis.... http://download.hijackthis.eu/hijackthis_199.zip

...run it, and paste the log here for analysis.... HijackThis Logfileauswertung

And finally, if after all of this you still can't get the little bugger because the file is locked or whatever, then you could try Killbox to just remove the file.... KillBox.Net

Last edited by D16GER; Oct 6, 2007 at 10:20 PM.
Reply
Old Oct 7, 2007 | 08:17 AM
  #6  
mart360's Avatar
mart360
Scooby Regular
 
Joined: Jul 2005
Posts: 12,329
Likes: 0
Default

Youve got a BHO... Browser helper object...

run spybot search and destroy followed by ad aware....

and then run hijack this

this should kill the little ******

then and this is very important


DONT intstall Yahoo/google or whatever else superduper toolbar thats offered to you.......

why people use these is beyond me


and finally......the best move of all



Get rid of IE and use firefox, ...far better than IE

and update your virus proggy and firewall as well

Avast & comodo are free and pick up ore than the others ive used

Mart
Reply
Old Oct 8, 2007 | 09:52 PM
  #7  
jowl's Avatar
jowl
Scooby Regular
 
Joined: Aug 2004
Posts: 1,882
Likes: 0
Default

I've just switched to Comodo from Kerio - much better and more stable!
Reply
Old Oct 8, 2007 | 10:32 PM
  #8  
boomer's Avatar
boomer
Scooby Senior
 
Joined: Feb 2000
Posts: 5,763
Likes: 0
From: West Midlands
Default

Originally Posted by jowl
I've just switched to Comodo from Kerio - much better and more stable!
Any more info??

Been using Kerio for a while, and mistakenly upgraded to Sunbelt with it's nag screens. What are the pros & cons of Comode (oh, and shame it doesn't work on Windows 98!).

mb
Reply
Old Oct 9, 2007 | 08:34 AM
  #9  
paulr's Avatar
paulr
Thread Starter
Scooby Regular
 
Joined: Jan 2005
Posts: 15,623
Likes: 0
From: Lincolnshire
Default

Thanks for the great advice.
Reply
Old Oct 9, 2007 | 06:40 PM
  #10  
Deano_P1's Avatar
Deano_P1
Scooby Regular
 
Joined: Apr 2007
Posts: 559
Likes: 0
From: South Wales
Default

You could also try Avast antivirus
Reply
Old Oct 10, 2007 | 08:48 AM
  #11  
jowl's Avatar
jowl
Scooby Regular
 
Joined: Aug 2004
Posts: 1,882
Likes: 0
Default

Originally Posted by boomer
Any more info??

Been using Kerio for a while, and mistakenly upgraded to Sunbelt with it's nag screens. What are the pros & cons of Comode (oh, and shame it doesn't work on Windows 98!).

mb
Well I find it doesn't crash out, doesn;t hang on shut down and always starts on login.

It seems to have many options - not all of which I've fully explored yet and it's all free.

I like the control I have over it and the way it works. For example, if you have an App which wants to connect to net or changes 3 files (say on install), you set Comodo to allow the action for all 3 files. With Kerio you had to click 3 times. Of course, you can turn the 'training' mode off too. I also used to have annoying requests from Kerio when shutting down to install Windows Updates. If I forget it would mean my machine wouldn't turn off.

But best of all for me, it seems much faster - especially on startup.
Reply
Old Oct 14, 2007 | 07:00 PM
  #12  
paulr's Avatar
paulr
Thread Starter
Scooby Regular
 
Joined: Jan 2005
Posts: 15,623
Likes: 0
From: Lincolnshire
Default

http://homepage.ntlworld.com/paul123/paul123/virus2.jpg

Here is the file but i cant delete it. I've tried most of the stuff recommended, even Killbox but they all say, "cant delete this file".

Its in WINDOWS\System32 folder.

Cant even delete it manually.
Reply
Old Oct 14, 2007 | 07:36 PM
  #13  
paulr's Avatar
paulr
Thread Starter
Scooby Regular
 
Joined: Jan 2005
Posts: 15,623
Likes: 0
From: Lincolnshire
Default

What if i just turn of my anti-virus and leave the virus on the PC. My only concern is internet banking, can it get my details?
Reply
Old Oct 15, 2007 | 12:59 AM
  #14  
stevebt's Avatar
stevebt
Scooby Regular
iTrader: (8)
 
Joined: Sep 2002
Posts: 16,732
Likes: 33
Default

Have you not considered paying for a different AVG I use kaspersky and I dont have any bother with any virus's or trojans ever??? I used to be bothered when I ran blueyonders free virus scan ??? But once I started paying for a proper service I never seem to worry about anything any more
Reply
Old Oct 15, 2007 | 07:24 AM
  #15  
Beastie's Avatar
Beastie
Scooby Regular
iTrader: (2)
 
Joined: Jan 2001
Posts: 2,397
Likes: 17
From: Scotland
Default

I had this problem not long ago. Tried everything, solution was fresh install.
Back your files up to the second hard drive or a portable hard drive and re-install. Problem will be fixed and will have taken you less time than all the programmes you have been trying.

Kaspersky didnt find my Trojan
AVG did and deleted it but it came back
Spybot did and deleted it and it came back
Other stuff didnt find it
Norton was installed and fully up to date
Reply
Old Oct 15, 2007 | 06:27 PM
  #16  
paulr's Avatar
paulr
Thread Starter
Scooby Regular
 
Joined: Jan 2005
Posts: 15,623
Likes: 0
From: Lincolnshire
Default

Originally Posted by Beastie
I had this problem not long ago. Tried everything, solution was fresh install.
Back your files up to the second hard drive or a portable hard drive and re-install. Problem will be fixed and will have taken you less time than all the programmes you have been trying.

Kaspersky didnt find my Trojan
AVG did and deleted it but it came back
Spybot did and deleted it and it came back
Other stuff didnt find it
Norton was installed and fully up to date
I'm coming round to that way of thinking.
Reply
Old Oct 17, 2007 | 09:06 PM
  #17  
Alan C's Avatar
Alan C
Scooby Regular
 
Joined: Jun 2003
Posts: 6,702
Likes: 0
Default

Paul. Try this mate...

SDFix by Andy Manchetser..

It needs to be run in safe mode with Admin rights, but may mean the difference between a re-install..

SDFix

Before you do, run 'Hijack This' as suggested below and compare some of the entries on your log to the entries on the list from the link above.
(Note: you may spot stuff in the Hijack This log that look tempting to manually remove. Unless you really know what you're doing, be very careful as you can do some damage and you'll end up doing a re-install anyway!!)

The link above gives an extensive list of Trojans it can find and remove and you may some of them on your log.

Last edited by Alan C; Oct 17, 2007 at 09:11 PM.
Reply
Old Oct 19, 2007 | 12:20 PM
  #18  
MJW's Avatar
MJW
Scooby Senior
 
Joined: Nov 2001
Posts: 4,130
Likes: 0
From: West Yorks.
Default

Its highly likely the virus is exploiting system restore to re-instate itself. Right click My Computer, select Properties from the bottom of the menu, then click the System Restore tab. Check the 'Turn off System Restore' box and run your AV again, then reboot. You can switch system restore back on again later when the virus has been zapped.
Reply
Old Oct 19, 2007 | 02:50 PM
  #19  
Chris L's Avatar
Chris L
Scooby Regular
 
Joined: May 2000
Posts: 10,371
Likes: 0
From: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Default

Om the subject of paying for some of this stuff - Webroot is the best anti spyware program that I have come across. Only about £15 / 20 a year. Well worth it. And again, based on my own personal experience, the only freeware AV that comes close to the fully paid versions is Avira - well worth looking at.

Once you've cleaned up your system I would also suggest using Advanced WindowsCare V2 Personal - which is free and highly effective!

I agree with what MJW is saying as well.
Reply
Old Oct 19, 2007 | 03:00 PM
  #20  
InvisibleMan's Avatar
InvisibleMan
Scooby Regular
 
Joined: May 2001
Posts: 12,583
Likes: 0
From: .
Default

run in safe mode, find all the associated files in c: & system32, rename them so main prog doesnt run (each time they are deleted & auto rerun theyll have a different name), delete registry entries, delete virus files

deleted that sch162.dll file too?

Last edited by InvisibleMan; Oct 19, 2007 at 03:06 PM.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
just me
Non Scooby Related
26
Jan 3, 2020 11:12 AM
Sam Witwicky
Engine Management and ECU Remapping
17
Nov 13, 2015 10:49 AM
scoobhunter722
ScoobyNet General
52
Oct 20, 2015 04:32 PM
kenc
Wanted
6
Oct 2, 2015 09:12 PM
timmy2take
Non Scooby Related
2
Oct 2, 2015 08:09 AM




All times are GMT +1. The time now is 12:33 AM.