Oct 13, 2006, 04:04 AM // 04:04
|
#1
|
Forge Runner
Join Date: Jan 2006
Location: Toronto
Guild: Hopping
Profession: Mo/A
|
Win32:Agent-CBL [TRJ] :mad:
I just got this spyware around 9 hours ago, because I took my Zone Alarm firewall down and threw the Windows one up, for a lower ping/less lag on both GW and Vent. After 2 games or so, this little bastard came up. It seems to be stuck in my system32\Rsvtub.dll [UPX]
I've tried everything, like running AVG/Spybot/Windows Defender/Ad-Ware SE in safemode, and a few boot scans with AVG, and nothing could seem to get the thing off my computer. It just manages to remain after EVERY time AVG or I manually delete it in normal mode. If I delete it in safe mode, it will recreate itself once I'm in normal mode again.
It's not causing any serious problems though, but if I take down the avast warning window, it will just repop up and that smartass voice wil go: causion, a virus has been detected, and it's hella annoying.
Anyone else getting this problem or have a fix, or have any sites they would reconnmend for this kinda thing, please shed some knowledge, thank you.
|
|
|
Oct 13, 2006, 06:39 AM // 06:39
|
#3
|
Forge Runner
Join Date: Jan 2006
Location: Toronto
Guild: Hopping
Profession: Mo/A
|
Nope. Did every single step accordingly, that damn thing is still poping up.
|
|
|
Oct 13, 2006, 08:31 AM // 08:31
|
#4
|
Krytan Explorer
Join Date: Dec 2005
Location: Denmark
Guild: First Degree
Profession: Mo/
|
spybot s&d.
ad-aware.
dr. delete.
|
|
|
Oct 13, 2006, 08:51 AM // 08:51
|
#5
|
Jungle Guide
Join Date: Dec 2005
Guild: Left gw..yawn
Profession: W/N
|
spy-bot in safe mode is ur best bet
altho, try do a system restore to a day before...thats is always a saviour
|
|
|
Oct 13, 2006, 09:34 AM // 09:34
|
#6
|
Forge Runner
Join Date: Jan 2006
Location: Toronto
Guild: Hopping
Profession: Mo/A
|
Yeah, I've done all those listed above...as for system restore, will I loose some of my files?
|
|
|
Oct 13, 2006, 05:07 PM // 17:07
|
#7
|
Wilds Pathfinder
|
Don't do System Restore. It tends to make things like this worse.
|
|
|
Oct 13, 2006, 05:22 PM // 17:22
|
#8
|
Forge Runner
Join Date: Jan 2006
Location: Toronto
Guild: Hopping
Profession: Mo/A
|
Well any other ideas? This damn virus just won't stop bothering me. It's not doing any harm that I'm aware of, just triggering AVG's virus detection system, but I'd rather have it removed...so...any ideas left?
|
|
|
Oct 13, 2006, 07:13 PM // 19:13
|
#9
|
Lion's Arch Merchant
Join Date: Aug 2006
Location: Alabama
|
I would suggest something that may seem more drastic, but is probably the best full solution.
Backup your data, and do a full wipe and reload. For a lot of virus and trojans, that is really the only way to really get rid of them. It sounds like you have multiple "dropper trojans" running in the background.
The problem with most of them is that they come out almost daily. It takes 3-14 days for the AV companies to discover them and write a removal. The problem is that by the time they find one, you have 2-5 newer versions already in your system that it can't detect yet.
It sounds like this is the circle you are in. You find some, and remove them. But since you are still infected with newer versions, it happens all over again.
Probably 75% of the computers that come into my shop are infected with virus and other malware. And it truely is an epidemic. And so far, every system that came in with P2P software (including Torrent, Kazaa, Limewire, etc) has had multiple infections. And the same goes for people that use the gambling sites. PartyPoker inserts multiple trojans and spyware when you use it, and other gambling sites are even worse.
Backup your data, then do a complete wipe and reload of your OS. Install all the updates, and a good antivirus (Norton, AVG, or Avast). And install multiple spyware programs and run them regularly. I install AdAware, SpyBot, and Microsoft Defender on every system I build or reload.
And stay away from what I call the "Dark Alleys of the Internet". That includes peer-to-peer file trading, gambling, hacker sites, and porn sites (other then the more "legitimate" ones like Playboy). This is where most trojans and malware tends to come from.
|
|
|
Oct 13, 2006, 08:33 PM // 20:33
|
#10
|
Furnace Stoker
Join Date: Jul 2005
Location: near SF, CA
|
^agreed with the above^
Asside from disabling your firewall (big no-no!), you can also get infected by connecting to a Vent or TS server if that system is either compromised or set up by its owner to deliver a trojan payload.
Skype is a safer alternative since it is centrally controlled, but you need a fast system (usually a newer PC with 2+ cores) to avoid taking a GW performance hit.
|
|
|
Oct 15, 2006, 06:55 AM // 06:55
|
#11
|
Forge Runner
Join Date: Jan 2006
Location: Toronto
Guild: Hopping
Profession: Mo/A
|
Hmm...problem is, I don't have any place to backup my files to, and most of which are pretty important. I still have no clue how I got that virus, the only thing I did was log into our guild vent server, and after a while, avast goes crazy...
I'll try your solution Mushroom, when I find someplace to back up my stuff, thanks
|
|
|
Oct 15, 2006, 09:16 PM // 21:16
|
#12
|
Krytan Explorer
Join Date: May 2005
Location: Louisiana
Profession: E/Mo
|
|
|
|
Oct 15, 2006, 09:48 PM // 21:48
|
#13
|
Technician's Corner Moderator
Join Date: Jan 2006
Location: The TARDIS
Guild: http://www.lunarsoft.net/ http://forums.lunarsoft.net/
|
Install Avast and let it do a boot-time scan.
If you have questions, just ask. I deal with this stuff constantly.
|
|
|
Oct 16, 2006, 08:14 AM // 08:14
|
#14
|
Site Legend
|
I had something similar (couple pages back) I finally managed to get rid of it when I found the source of the problem IE the file that is reloading the Trojan after you have deleted it.
I_N_S_T_A_L_L_A_F_T_E_R_R_E_B_O_O_T <~~the file should look similar to that, delete that file and it should solve your problem.
The program that found it was ADware 4.0 the scan is free but you have to buy the program for it to remove the problems. Its amazing what that program finds that all the "so called" best programs completely miss.
|
|
|
Oct 16, 2006, 08:18 AM // 08:18
|
#15
|
Forge Runner
Join Date: Jan 2006
Location: Toronto
Guild: Hopping
Profession: Mo/A
|
Quote:
Originally Posted by The Admins Bane
I_N_S_T_A_L_L_A_F_T_E_R_R_E_B_O_O_T <~~the file should look similar to that, delete that file and it should solve your problem.
|
Eh, where do I find that file ><
|
|
|
Oct 16, 2006, 10:16 AM // 10:16
|
#16
|
Site Legend
|
Hiding in the system32 files somewhere.
|
|
|
Oct 16, 2006, 10:49 AM // 10:49
|
#17
|
Jungle Guide
Join Date: Dec 2005
Guild: Left gw..yawn
Profession: W/N
|
Quote:
Originally Posted by EF2NYD
Don't do System Restore. It tends to make things like this worse.
|
actually no, its a very useful tool, it fixed my comp after a virus deleted most of my system filses...got my computer running back to speed in a matter of minutes, maybe from experiences u had made it worse, but in general its a very useful tool and a tmesaver
and not it dosent delete files...it reverts recently installed progs tho
|
|
|
Oct 16, 2006, 04:24 PM // 16:24
|
#18
|
Ninja Unveiler
Join Date: Jun 2005
Location: Louisiana, USA
Guild: Boston Guild[BG]
Profession: W/Me
|
Quote:
Originally Posted by lord_shar
^agreed with the above^
Asside from disabling your firewall (big no-no!), you can also get infected by connecting to a Vent or TS server if that system is either compromised or set up by its owner to deliver a trojan payload.
Skype is a safer alternative since it is centrally controlled, but you need a fast system (usually a newer PC with 2+ cores) to avoid taking a GW performance hit.
|
I wouldn't even trust Skype, its just a glorified TS/Vent anyway.
Private TS/Vent servers are less likely to cause any infection than the public ones. More than likely you know the person who runs it and they most likely know how to secure it.
|
|
|
Oct 16, 2006, 07:41 PM // 19:41
|
#19
|
Ascalonian Squire
Join Date: Oct 2006
Location: College Park
|
Hmm..Skype is useful though for calling people who don't play games. I use it to talk to my friend in Sweeden (she moved there after we graduated).
I've never had a good experience with System Restore. Tried to use it to fix Oblivion and it just wound up causing more problems then it solved.
|
|
|
Oct 17, 2006, 01:28 PM // 13:28
|
#20
|
Forge Runner
Join Date: Jan 2006
Location: Toronto
Guild: Hopping
Profession: Mo/A
|
Ok, so my only option now is to fine a file called I_N_S_T_A_L_L_A_F_T_E_R_R_E_B_O_O_T as suggested by Admin's Bane...
Gosh man you sure you have the right name? It looks pretty whack...and I can't find it.
Also avast is detecting the virus and showing a window that it did it...every 5 seconds. If I close the window, it pops up. If I shutdown and restard avast, it doesn't detect it.
Last edited by Poison Ivy; Oct 17, 2006 at 01:50 PM // 13:50..
|
|
|
Thread Tools |
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 01:32 PM // 13:32.
|