Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Trojan virus. Advice please.

Thread Tools
 
Search this Thread
 
Old 06 October 2007, 03:02 PM
  #1  
paulr
Scooby Regular
Thread Starter
 
paulr's Avatar
 
Join Date: Jan 2005
Location: Lincolnshire
Posts: 15,623
Likes: 0
Received 0 Likes on 0 Posts
Default Trojan virus. Advice please.

Hi,
Eveytime i open Internet Explorer i get this warning.



I move it to the vault but it keeps coming back.
I found it and its here. I delete it but it returns.

http://homepage.ntlworld.com/paul123/paul123/schll.jpg

I've got AVG and zone alarm, windows xp.

Any advice.

thanks
Paul.

Last edited by paulr; 06 October 2007 at 03:03 PM. Reason: cvv
Old 06 October 2007, 03:31 PM
  #2  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

Reboot into safe mode then run your AVG software and get it to remove the item and then see if it comes back. You could also try healing the file, or if possible actually get it deleted.
Old 06 October 2007, 07:40 PM
  #3  
paulr
Scooby Regular
Thread Starter
 
paulr's Avatar
 
Join Date: Jan 2005
Location: Lincolnshire
Posts: 15,623
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Markus
Reboot into safe mode then run your AVG software and get it to remove the item and then see if it comes back. You could also try healing the file, or if possible actually get it deleted.
None of that worked. It came back when i opened IE.
Old 06 October 2007, 08:08 PM
  #4  
ScuuBdoo
Scooby Regular
 
ScuuBdoo's Avatar
 
Join Date: May 2006
Location: Ireland
Posts: 927
Likes: 0
Received 0 Likes on 0 Posts
Default

you need to open the system registry. Then navigate your way to where the file is and delete it manually. That should fix the problem.
Old 06 October 2007, 10:14 PM
  #5  
D16GER
Scooby Regular
 
D16GER's Avatar
 
Join Date: Sep 2005
Posts: 924
Likes: 0
Received 0 Likes on 0 Posts
Default

Best thing I can suggest is to download the trial of Kaspersky AV here.... Kaspersky Anti-Virus free trial download

and also download the updates for it here.... Setting Updater

Then, disconnect from the internet and turn off AVG and Zone Alarm completely, even uninstall them if you have to.

Once done, install Kaspersky and update it, then let it do it's thing, it's an awesome piece of kit. Oh and maybe even consider buying it, AVG is a useless pile of dung in my experience. I know lots swear by it, but I swear at it

You may also need to run a Spyware remover, you can't beat Spybot for that job.... The home of Spybot-S&D!

And finally, once you have ran those programs, go get HijackThis.... http://download.hijackthis.eu/hijackthis_199.zip

...run it, and paste the log here for analysis.... HijackThis Logfileauswertung

And finally, if after all of this you still can't get the little bugger because the file is locked or whatever, then you could try Killbox to just remove the file.... KillBox.Net

Last edited by D16GER; 06 October 2007 at 10:20 PM.
Old 07 October 2007, 08:17 AM
  #6  
mart360
Scooby Regular
 
mart360's Avatar
 
Join Date: Jul 2005
Posts: 12,329
Likes: 0
Received 0 Likes on 0 Posts
Default

Youve got a BHO... Browser helper object...

run spybot search and destroy followed by ad aware....

and then run hijack this

this should kill the little ******

then and this is very important


DONT intstall Yahoo/google or whatever else superduper toolbar thats offered to you.......

why people use these is beyond me


and finally......the best move of all



Get rid of IE and use firefox, ...far better than IE

and update your virus proggy and firewall as well

Avast & comodo are free and pick up ore than the others ive used

Mart
Old 08 October 2007, 09:52 PM
  #7  
jowl
Scooby Regular
 
jowl's Avatar
 
Join Date: Aug 2004
Posts: 1,882
Likes: 0
Received 0 Likes on 0 Posts
Default

I've just switched to Comodo from Kerio - much better and more stable!
Old 08 October 2007, 10:32 PM
  #8  
boomer
Scooby Senior
 
boomer's Avatar
 
Join Date: Feb 2000
Location: West Midlands
Posts: 5,763
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by jowl
I've just switched to Comodo from Kerio - much better and more stable!
Any more info??

Been using Kerio for a while, and mistakenly upgraded to Sunbelt with it's nag screens. What are the pros & cons of Comode (oh, and shame it doesn't work on Windows 98!).

mb
Old 09 October 2007, 08:34 AM
  #9  
paulr
Scooby Regular
Thread Starter
 
paulr's Avatar
 
Join Date: Jan 2005
Location: Lincolnshire
Posts: 15,623
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks for the great advice.
Old 09 October 2007, 06:40 PM
  #10  
Deano_P1
Scooby Regular
 
Deano_P1's Avatar
 
Join Date: Apr 2007
Location: South Wales
Posts: 559
Likes: 0
Received 0 Likes on 0 Posts
Default

You could also try Avast antivirus
Old 10 October 2007, 08:48 AM
  #11  
jowl
Scooby Regular
 
jowl's Avatar
 
Join Date: Aug 2004
Posts: 1,882
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by boomer
Any more info??

Been using Kerio for a while, and mistakenly upgraded to Sunbelt with it's nag screens. What are the pros & cons of Comode (oh, and shame it doesn't work on Windows 98!).

mb
Well I find it doesn't crash out, doesn;t hang on shut down and always starts on login.

It seems to have many options - not all of which I've fully explored yet and it's all free.

I like the control I have over it and the way it works. For example, if you have an App which wants to connect to net or changes 3 files (say on install), you set Comodo to allow the action for all 3 files. With Kerio you had to click 3 times. Of course, you can turn the 'training' mode off too. I also used to have annoying requests from Kerio when shutting down to install Windows Updates. If I forget it would mean my machine wouldn't turn off.

But best of all for me, it seems much faster - especially on startup.
Old 14 October 2007, 07:00 PM
  #12  
paulr
Scooby Regular
Thread Starter
 
paulr's Avatar
 
Join Date: Jan 2005
Location: Lincolnshire
Posts: 15,623
Likes: 0
Received 0 Likes on 0 Posts
Default

http://homepage.ntlworld.com/paul123/paul123/virus2.jpg

Here is the file but i cant delete it. I've tried most of the stuff recommended, even Killbox but they all say, "cant delete this file".

Its in WINDOWS\System32 folder.

Cant even delete it manually.
Old 14 October 2007, 07:36 PM
  #13  
paulr
Scooby Regular
Thread Starter
 
paulr's Avatar
 
Join Date: Jan 2005
Location: Lincolnshire
Posts: 15,623
Likes: 0
Received 0 Likes on 0 Posts
Default

What if i just turn of my anti-virus and leave the virus on the PC. My only concern is internet banking, can it get my details?
Old 15 October 2007, 12:59 AM
  #14  
stevebt
Scooby Regular
iTrader: (8)
 
stevebt's Avatar
 
Join Date: Sep 2002
Posts: 16,732
Received 33 Likes on 19 Posts
Default

Have you not considered paying for a different AVG I use kaspersky and I dont have any bother with any virus's or trojans ever??? I used to be bothered when I ran blueyonders free virus scan ??? But once I started paying for a proper service I never seem to worry about anything any more
Old 15 October 2007, 07:24 AM
  #15  
Beastie
Scooby Regular
iTrader: (2)
 
Beastie's Avatar
 
Join Date: Jan 2001
Location: Scotland
Posts: 2,397
Received 17 Likes on 10 Posts
Default

I had this problem not long ago. Tried everything, solution was fresh install.
Back your files up to the second hard drive or a portable hard drive and re-install. Problem will be fixed and will have taken you less time than all the programmes you have been trying.

Kaspersky didnt find my Trojan
AVG did and deleted it but it came back
Spybot did and deleted it and it came back
Other stuff didnt find it
Norton was installed and fully up to date
Old 15 October 2007, 06:27 PM
  #16  
paulr
Scooby Regular
Thread Starter
 
paulr's Avatar
 
Join Date: Jan 2005
Location: Lincolnshire
Posts: 15,623
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Beastie
I had this problem not long ago. Tried everything, solution was fresh install.
Back your files up to the second hard drive or a portable hard drive and re-install. Problem will be fixed and will have taken you less time than all the programmes you have been trying.

Kaspersky didnt find my Trojan
AVG did and deleted it but it came back
Spybot did and deleted it and it came back
Other stuff didnt find it
Norton was installed and fully up to date
I'm coming round to that way of thinking.
Old 17 October 2007, 09:06 PM
  #17  
Alan C
Scooby Regular
 
Alan C's Avatar
 
Join Date: Jun 2003
Posts: 6,702
Likes: 0
Received 0 Likes on 0 Posts
Default

Paul. Try this mate...

SDFix by Andy Manchetser..

It needs to be run in safe mode with Admin rights, but may mean the difference between a re-install..

SDFix

Before you do, run 'Hijack This' as suggested below and compare some of the entries on your log to the entries on the list from the link above.
(Note: you may spot stuff in the Hijack This log that look tempting to manually remove. Unless you really know what you're doing, be very careful as you can do some damage and you'll end up doing a re-install anyway!!)

The link above gives an extensive list of Trojans it can find and remove and you may some of them on your log.

Last edited by Alan C; 17 October 2007 at 09:11 PM.
Old 19 October 2007, 12:20 PM
  #18  
MJW
Scooby Senior
 
MJW's Avatar
 
Join Date: Nov 2001
Location: West Yorks.
Posts: 4,130
Likes: 0
Received 0 Likes on 0 Posts
Default

Its highly likely the virus is exploiting system restore to re-instate itself. Right click My Computer, select Properties from the bottom of the menu, then click the System Restore tab. Check the 'Turn off System Restore' box and run your AV again, then reboot. You can switch system restore back on again later when the virus has been zapped.
Old 19 October 2007, 02:50 PM
  #19  
Chris L
Scooby Regular
 
Chris L's Avatar
 
Join Date: May 2000
Location: MY00,MY01,RX-8, Alfa 147 & Focus ST :-)
Posts: 10,371
Likes: 0
Received 0 Likes on 0 Posts
Default

Om the subject of paying for some of this stuff - Webroot is the best anti spyware program that I have come across. Only about £15 / 20 a year. Well worth it. And again, based on my own personal experience, the only freeware AV that comes close to the fully paid versions is Avira - well worth looking at.

Once you've cleaned up your system I would also suggest using Advanced WindowsCare V2 Personal - which is free and highly effective!

I agree with what MJW is saying as well.
Old 19 October 2007, 03:00 PM
  #20  
InvisibleMan
Scooby Regular
 
InvisibleMan's Avatar
 
Join Date: May 2001
Location: .
Posts: 12,583
Received 0 Likes on 0 Posts
Default

run in safe mode, find all the associated files in c: & system32, rename them so main prog doesnt run (each time they are deleted & auto rerun theyll have a different name), delete registry entries, delete virus files

deleted that sch162.dll file too?

Last edited by InvisibleMan; 19 October 2007 at 03:06 PM.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
just me
Non Scooby Related
26
03 January 2020 11:12 AM
Sam Witwicky
Engine Management and ECU Remapping
17
13 November 2015 10:49 AM
scoobhunter722
ScoobyNet General
52
20 October 2015 04:32 PM
kenc
Wanted
6
02 October 2015 09:12 PM
timmy2take
Non Scooby Related
2
02 October 2015 08:09 AM



Quick Reply: Trojan virus. Advice please.



All times are GMT +1. The time now is 08:43 PM.