question bout trojans..

angstsoldat

Senior member
Jun 30, 2005
623
0
0
How come their are so many anti-spyware programs for free like Spybot, Adaware, Stinger, Hijackthis, etc etc. Yet no free trojan remover programs.. Imo I think trojans are a lot worse than spyware and should be focused on more..
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Trojans fall more under the realm of antivirus software, and there is free antivirus software out there, free for personal non-business use. AVG, AntiVir and Avast are three popular ones. AntiVir comes up on top in Trojan detection in the tests I've seen thanks to Schadenfroh's research. There are pay-for antivirus programs that do better against Trojans if you're serious enough about your protection to spend $35 or so.
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
I use antivir but still .. most of that Antivirus software sucks for trojan detecting paying or not paying.. they all got low detection rates
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: angstsoldat
I use antivir but still .. most of that Antivirus software sucks for trojan detecting paying or not paying.. they all got low detection rates
Some of them are pretty good at detecting the known Trojans... Kaspersky and McAfee are typically over 99% in the AVComparatives.org tests if I recall correctly. But new Trojans come out all the time, and as the name "Trojan Horse" implies, you are the one who brings them in the door and lets them loose on your system. Sometimes common sense is needed, on top of all the technical safeguards.
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
yeah Im thinking about getting McAfee on top of Antivir.

Can you use AntiVir and McAfee at the same time without any conflict?

Also I tried the S-t-i-n-g-e-r thing from mcAfee, the free trojan detector for like 50 trojans or something, and it took like an hour to scan.. is the McAfee ANtiVirus like that? and I've seen like 12 different McAfee things, Anti spam, anti virus, firewall and virus, etc etc. what should I get specifically from McAfee?
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
btw I looked at Shadenfrohs guide and it said he deleted it and to go to fatwallet.com which I did and read that one
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
I installed Ewido And I clicked Update and nothing happen. and it said it had a database of only 165 bad files so I uninstalled......
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
Oh yeah, currently.. would anything possible need an IDE connector for anything besides CD Drives and hard drives?
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
oh yeah one more question.. how do you "tie the cables" out of the way of fans and whatnot inside your case? Like is their some sort of rubber band that works, or do you just tie it around itself and knot it? im pretty sure neither of those would work so kinda curious o_O
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
If you'll be using a combination of a router plus ZoneAlarm (or Sygate or Kerio or Windows Firewall) for your firewall solution, then all you'd need from McAfee is VirusScan 9.0 "standard edition" (as opposed to Professional).

I would steer you towards Kaspersky for a couple reasons: 1) updates hourly, and 2) it can update manually from within a Limited account, which last I checked, McAfee VS 9.0 could not do, not manually at least. Kaspersky is also less annoying than McAfee's home-user stuff, no retarded splash screens to drive you crazy. In Kaspersky's lineup, the AntiVirus Personal 5 non-Pro would be a good pick and I think it's $35 nowdays.
Can you use AntiVir and McAfee at the same time without any conflict?
Not a good idea to have two at the same time.
Also I tried the S-t-i-n-g-e-r thing from mcAfee, the free trojan detector for like 50 trojans or something, and it took like an hour to scan.. is the McAfee ANtiVirus like that?
Where Stinger is looking for variants of 50 popular ones, full-on McAfee is looking for roughly 130,000 worms, viruses, trojans, adware, spyware, dialers, password-cracking programs and even joke programs. If you have lots of stuff on your hard drives, then schedule the scan to run starting at 1AM in the morning on Thursday mornings and Sunday mornings, and leave the computer on for those scans to take place. Your first reliance should be on the real-time protection from having the antivirus software running all the time, but sometimes "backscans" will find stuff that slipped using the previous virus definitions.
Oh yeah, currently.. would anything possible need an IDE connector for anything besides CD Drives and hard drives?
Zip drives or LS-120 drives, some entry-level tape drives, ATA coffeemaker controllers (ok, not really)... that's what I can think of ATM :confused:
 

Technonut

Diamond Member
Mar 19, 2000
4,041
0
0
Thats strange that ewido did not update for you...

It is very good, and scans quickly.

There is a review Here...

The Ewido file scanner detected four infected products in our trojan test set and the monitor detected an additional four. With a total of 8 detections Ewido came in third in this set of reviews and was only marginally bettered by TDS-3 (9) and Trojan Hunter (9). For a new product, this is an impressive performance.
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
Thanks mech :D

I heard Kaspersky takes up a lot of system resources though, hence bad for playing games? I talked to my bud on MSN and he says he uses McAfee and gets no lag, and nothing gets through to him like malware, trojans, viruses, etc.

But if Kaspersky dont use much resources i'll think about that one.

Also , is TrojanHunter a full-time thing, or is it just use-whenever-you-want kinda scan deal to pop and kill trojans?
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
Yo mech I dont remember your guide talking about moving the cables out of the way of airflow or how to do that .. could you tell me how to do that? Or if its in your guide you can just say that too because I printed it out.

Also, I am running a TrojanHunter scan right now, and it says this ..

Registry scan
Registry value exists: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WhenUSave (matches Adware.WhenU-Save.100) (Regedit Jump)
Registry value exists: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\windows (matches LttLogger.100) (

Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan

It says the regedit stuff in red. Is it trying to imply that I should go in to regedit and delete those files? or did it already take care of it? or what.. this is my first time using this program so Im not quite sure how it works.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Kaspersky and McAfee both have free full-function trialware available, see the Resources page of my guide for links. You can try them and see for yourself whether they have a noticable drag on the system. If nothing else, you can score 6 weeks of free major-brand antivirus protection that way.

There's no free lunch, it takes some CPU power to munch through some types of files and get at their insides. If you don't want the antivirus software having to scan chewy files as they arrive and depart while you're gaming, then don't run P2P and that should help quite a lot.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Hmm, I need broadband just so I can keep up with the stream of questions here :D

If you think you have a WhenU adware/spyware on there, then

1) uninstall AntiVir

2) install the McAfee VirusScan trialware and update it

3) install a free 30-day trial of WebRoot Spysweeper and update it

4) disable System Restore (right-click My Computer and go to the System Restore tab)

5) reboot into Safe Mode and run a McAfee scan in Safe Mode, followed by a WebRoot Spysweeper scan also while still in Safe Mode

6) ???

7) Profit! :cool:

(hehe)

After doing both scans in Safe Mode, with System Restore disabled, now restart Windows in normal mode and run another SpySweeper scan. I'm suggesting SpySweeper because it'll scan in Safe Mode, whereas Microsoft AntiSpyware Beta didn't (last I checked).

Tucking cables out of the way to improve airflow is somewhat overrated. It also depends on your case, motherboard, video cards and drive loadout. Gonna have to use your common sense on that one :)
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
hehe thx for replying to all my newbish questions lately :D

Where do I get WebRoot Spysweeper?

Also.. How come if everything thinks NOD32 is so good it takes little resources but others take a lot of resources and are also good? Also is there any way I can find out generally how much resources it would take up for each one? Like the manufacturers website or something. Im about to go look at those right now.

Also, why would you want to disable System Restore.. I mean you menchioned it in your guide and all but I mean wouldnt it benefit you to be able to restore your system to before it was infected? Or do the modern day Virsues/trojans plant themselves in the system restore files so they are there either way or something like that?
 

mAdMaLuDaWg

Platinum Member
Feb 15, 2003
2,437
1
0
Originally posted by: angstsoldat
How come their are so many anti-spyware programs for free like Spybot, Adaware, Stinger, Hijackthis, etc etc. Yet no free trojan remover programs.. Imo I think trojans are a lot worse than spyware and should be focused on more..

You talk about spyware as if you never use a computer ;)
 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
Ok this is really weird.

I had these 2 malicious software things right.. xps2.exe and run.exe , one of the two would pop up in my processes on boot up and would disable my Mozilla Firefox/Internet Explorer so I couldnt open them.. Anyway, I just finished TrojanHunter scan and it deleted the 2 registries I listed above .. However I was also running adwatch this whole time, and I get a popup saying something like An important file is trying to be altered .. Root : Hkey_Local_Machine Key: software\microsoft\windows\CurrentVersion\Run
data: run.exe

so I am not sure what this is.. Its not AntiVir, not Zone Alarm(i hope), not Kerio, not a trojan, I've done AntiVir scans, I've done Spybot 1.4, Ad-aware, SpyBlaster scans all within the last 3 days and I've had this for a couple months.

I am wondering should I go into RegEdit and delete a folder there??

Anyway im already there sitting at the RegEdit right at that folder waiting for what you guys to tell me what I should do. . I want this gone. Anway, in that Run folder that I just menchioned, the following programs are listed in this order.

(Default)
Anti-Virus Update...
AVG7_CC
AVG7_EMC
Logitech Utility
mmtask
Norton Antivirus
NvMediaCenter
nwiz (I THINK THIS IS A BAD ONE.)
Profiler
REGRUN
SaiSmart (Sai as in Saitek, its my joystick, Cyborg Evo)
THGUARD (TrojanHunter Guard i assume)
WhenUsave (wtf?)
Windows --- THIS is the one that says under DATA "run.exe"
Zone Labs Client


which is sort of funny because I uninstalled Zone Labs a hundred times, even in safe mode and whatnot. Anyway .. What should I do here? also all that I just listed have the same status for "TYPE" .. REG_SZ

anyway anyone know how to get rid of this run.exe. ? Do I just delete that registry file specifically? And why is Zone Labs still on my computer.

thx for reading if you did





 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
Originally posted by: mAdMaLuDaWg
Originally posted by: angstsoldat
How come their are so many anti-spyware programs for free like Spybot, Adaware, Stinger, Hijackthis, etc etc. Yet no free trojan remover programs.. Imo I think trojans are a lot worse than spyware and should be focused on more..

You talk about spyware as if you never use a computer ;)


lol, complete opposite, im always on the computer :)

and on these forums all the time also.. but thats mainly just cus im bored and want to get educated talk to cool people and all my clanmates left meh for BF2 :(

and CSS has gotten kinda dull lately
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Here is the link to the Webroot trialware: http://www.webroot.com/downloads/whytry

Windows itself is the one that may keep a stash of spare viruses in System Restore, in its well-meaning kind of way. If your System Restore record goes all the way back to the day you bought the computer, and you don't mind what'll happen when you restore it back to that point, then hey, go for it :evil:

On the resource usage, try some different brands using their trial versions and see what the before-&-after scenario is. If your machine is so short of RAM that the RAM usage is an issue, then the right answer is "buy more RAM!" :evil: It's astoundingly cheap right now, load up on 2 x 1GB while the getting is good.

At work, we use this. Holy all-day configuration procedure, Batman! :shocked: But it's effective.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: angstsoldat
Ok this is really weird.

I had these 2 malicious software things right.. xps2.exe and run.exe , one of the two would pop up in my processes on boot up and would disable my Mozilla Firefox/Internet Explorer so I couldnt open them.. Anyway, I just finished TrojanHunter scan and it deleted the 2 registries I listed above .. However I was also running adwatch this whole time, and I get a popup saying something like An important file is trying to be altered .. Root : Hkey_Local_Machine Key: software\microsoft\windows\CurrentVersion\Run
data: run.exe

so I am not sure what this is.. Its not AntiVir, not Zone Alarm(i hope), not Kerio, not a trojan, I've done AntiVir scans, I've done Spybot 1.4, Ad-aware, SpyBlaster scans all within the last 3 days and I've had this for a couple months.

I am wondering should I go into RegEdit and delete a folder there??

Anyway im already there sitting at the RegEdit right at that folder waiting for what you guys to tell me what I should do. . I want this gone. Anway, in that Run folder that I just menchioned, the following programs are listed in this order.

(Default)
Anti-Virus Update...
AVG7_CC
AVG7_EMC
Logitech Utility
mmtask
Norton Antivirus
NvMediaCenter
nwiz (I THINK THIS IS A BAD ONE.)
Profiler
REGRUN
SaiSmart (Sai as in Saitek, its my joystick, Cyborg Evo)
THGUARD (TrojanHunter Guard i assume)
WhenUsave (wtf?)
Windows --- THIS is the one that says under DATA "run.exe"
Zone Labs Client


which is sort of funny because I uninstalled Zone Labs a hundred times, even in safe mode and whatnot. Anyway .. What should I do here? also all that I just listed have the same status for "TYPE" .. REG_SZ

anyway anyone know how to get rid of this run.exe. ? Do I just delete that registry file specifically? And why is Zone Labs still on my computer.

thx for reading if you did
Uninstall all of your other interfering security software, Spyblaster and adwatch and whatever, and get started on my McAfee VirusScan + Webroot Spysweeper routine in Safe Mode already :p Both McAfee and SpySweeper will target WhenU.

edit: and I know those scans should take 1-3 hours each, so you better not pop in here before 2-6 hours from now claiming you did 'em ;)

 

angstsoldat

Senior member
Jun 30, 2005
623
0
0
thanks for how to get rid of WhenUsave, I am bout to begin that process right now. I will get back to you either in a couple minutes guys, or in a couple hours, Im going to see a movie soon.

Yes I am getting 2x1 GB ram, OCZ .

Would it not make a difference what kind of resources Kaspersky or McAfee require if I have "that much" RAM at my despense? anyway rebooting ..