Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Trojan Found - Do I need to do a complete reinstall?

 
   Security Forums (Home) -> General Discussions RSS
Next:  Help -- Virus Advice Fix -- download.trojan??!!  
Author Message
Tim

External


Since: May 28, 2004
Posts: 2



(Msg. 1) Posted: Fri May 28, 2004 5:31 pm
Post subject: Trojan Found - Do I need to do a complete reinstall?
Archived from groups: alt>comp>anti-virus, others (more info?)

I updated my virus detection file and found two viruses on my computer:
VBS/Psyme & Exploit-MhtRedir.gen. From what I read, these are trojans that
can download some other piece of software that wouldn't get detected by my
AV detector. If that's the case, my computer might now have some lerking
demon - a keystroke monitor / uploader etc. Should I do a complete
reinstall to be safe?

On the other hand, I would imagine that the trojan author would have his
secondary piece of software delete the trojan to cover his tracks. Any
thoughts?

Thanks!

 >> Stay informed about: Trojan Found - Do I need to do a complete reinstall? 
Back to top
Login to vote
Jason Wade

External


Since: May 28, 2004
Posts: 3



(Msg. 2) Posted: Fri May 28, 2004 8:15 pm
Post subject: Re: Trojan Found - Do I need to do a complete reinstall? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Fri, 28 May 2004 12:31:30 -0500, Tim wrote:

> I updated my virus detection file and found two viruses on my computer:
> VBS/Psyme & Exploit-MhtRedir.gen. From what I read, these are trojans
> that can download some other piece of software that wouldn't get
> detected by my AV detector. If that's the case, my computer might now
> have some lerking demon - a keystroke monitor / uploader etc. Should I
> do a complete reinstall to be safe?
>
>
yes

> On the other hand, I would imagine that the trojan author would have his
> secondary piece of software delete the trojan to cover his tracks. Any
> thoughts?
>
> Thanks!

no, usually trojans do not automatically delete themselves.

They make themselves as difficult to delete as possible. Some even prevent
you from backing up so that you can't delete them without losing
everything.

If you think you have a trojan, you need to get it off your system ASAP.

If you do reinstall, I suggest installing linux alongside windows. You'll
have a backup OS for times when windows gets messed up.

That's what I did.

good luck and safe computing

--
Please place your reply beneath the other person's text.
Long discussions will flow more logically.

 >> Stay informed about: Trojan Found - Do I need to do a complete reinstall? 
Back to top
Login to vote
Tim

External


Since: May 28, 2004
Posts: 2



(Msg. 3) Posted: Fri May 28, 2004 9:05 pm
Post subject: Re: Trojan Found - Do I need to do a complete reinstall? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Jason Wade" <savon1414_050404+gb2.nospam@earthlink.net> wrote in message
news:pan.2004.05.28.18.50.59.569599.763@earthlink.net...
> On Fri, 28 May 2004 12:31:30 -0500, Tim wrote:
>
> > I updated my virus detection file and found two viruses on my computer:
> > VBS/Psyme & Exploit-MhtRedir.gen. From what I read, these are trojans
> > that can download some other piece of software that wouldn't get
> > detected by my AV detector. If that's the case, my computer might now
> > have some lerking demon - a keystroke monitor / uploader etc. Should I
> > do a complete reinstall to be safe?
> >
> >
> yes
>
> > On the other hand, I would imagine that the trojan author would have his
> > secondary piece of software delete the trojan to cover his tracks. Any
> > thoughts?
> >
> > Thanks!
>
> no, usually trojans do not automatically delete themselves.
>
> They make themselves as difficult to delete as possible. Some even prevent
> you from backing up so that you can't delete them without losing
> everything.
>
> If you think you have a trojan, you need to get it off your system ASAP.
>
> If you do reinstall, I suggest installing linux alongside windows. You'll
> have a backup OS for times when windows gets messed up.
>
> That's what I did.
>
> good luck and safe computing
>
> --
> Please place your reply beneath the other person's text.
> Long discussions will flow more logically.
>

I have a major amount of time invested in the installation of programs, OS
updates etc on my system. I'd hate to go through the process again! If I
install a software firewall like ZoneAlert to tell me if something is
accessing the internet without my permission, will that suffice?

From my understanding, viruses make themselves hard to delete. But a trojan
delivers an incidious payload. And I would think that after it did so, it
would delete itself to cover up its tracks. What are the chances the trojans
left something behind if they were still around to be found?

Thanks.
 >> Stay informed about: Trojan Found - Do I need to do a complete reinstall? 
Back to top
Login to vote
madmax

External


Since: May 28, 2004
Posts: 9



(Msg. 4) Posted: Fri May 28, 2004 10:39 pm
Post subject: Re: Trojan Found - Do I need to do a complete reinstall? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Tim wrote:
> I updated my virus detection file and found two viruses on my computer:
> VBS/Psyme & Exploit-MhtRedir.gen. From what I read, these are trojans that
> can download some other piece of software that wouldn't get detected by my
> AV detector. If that's the case, my computer might now have some lerking
> demon - a keystroke monitor / uploader etc. Should I do a complete
> reinstall to be safe?
>
> On the other hand, I would imagine that the trojan author would have his
> secondary piece of software delete the trojan to cover his tracks. Any
> thoughts?
>
> Thanks!
>
>
Try installing some anti-trojan software that has been mentioned in
other posts.Also what program are you using for your mail?
If you are using the one supplied by MS,try a different one.
-max

--
This message is virus free as far I can tell
Change nomail.afraid.org to neo.rr.com so you can reply
(nomail.afraid.org has been set up specifically for
use in Usenet. Feel free to use it yourself.)
 >> Stay informed about: Trojan Found - Do I need to do a complete reinstall? 
Back to top
Login to vote
FromTheRafters

External


Since: Sep 19, 2003
Posts: 1207



(Msg. 5) Posted: Fri May 28, 2004 11:02 pm
Post subject: Re: Trojan Found - Do I need to do a complete reinstall? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Tim" <unidentified.RemoveThis@127.0.0.1> wrote in message news:SHKtc.13683$Tn6.3633@newsread1.news.pas.earthlink.net...
> I updated my virus detection file and found two viruses on my computer:
> VBS/Psyme & Exploit-MhtRedir.gen. From what I read, these are trojans that
> can download some other piece of software that wouldn't get detected by my
> AV detector. If that's the case, my computer might now have some lerking
> demon - a keystroke monitor / uploader etc. Should I do a complete
> reinstall to be safe?

This is a prime example of why it is sometimes necessary to do what
is otherwise considered overkill. This is a judgement call - that you
must make.

> On the other hand, I would imagine that the trojan author would have his
> secondary piece of software delete the trojan to cover his tracks. Any
> thoughts?

If the intruder wanted to make sure that the intrusion was not detected,
he would indeed do as you suggest. Not all intruders would bother to
try and cover their tracks though.

You could use every type of scanner imaginable to scan your system
for indications of actual intrusion. If no additional indications are found
you could assume that the intrusion was not successful and carry on as
if nothing had happened. If you are not comfortable with that, then the
only way to be sure is to break it down - and rebuild it.

On my home computer, I might be comfortable with making such an
assumption. But if I were responsible for an employer's computer or
network - I would not be at all comfortable with it. This is why it is a
judgement call that *you* must make.
 >> Stay informed about: Trojan Found - Do I need to do a complete reinstall? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
New Trojan? - Not sure what's up with my machine, but the spousal unit was on Ebay the other night and may have picked up something. I've noticed since then, when I've used Hotmail as well as our bank's website, the on-screen chars. and the typing lags behind...

trojan.svc.a - my avg anti virus resident sheild has come up with constant warnings 'backdoor trojan svc.a detectected' I can find no inf on this one-i ran avg it said it detected and healed but i went away for a while came back then it said same message. What is this....

PUP.exe Trojan? - I have been having some odd problems lately with my PC which seem to indicate a Trojan in onboard. On startup I get a 'new' .exe appearing in my C:\windows\system32 directory ervery time. It always has a different name (tblfiltu.exe, ssecd.exe,..

How to get rid of ICQ.PWS.Trojan - Got a problm here. NAV detected ICQ.PWS.Trojan but can't clean or quarantine. it. Access denied. And my system is getting very slow. How can i get rid of that trojan and the associated Worm.Win32.Bizex? Thanks philip

Trojan - I have a trojan, I can't quite remember the full message, something about a dialler, maybe windows dialler or something. AVG picks it up but won't fix it, s and b, cw shredder and Trojan Guarder Gold don't work. I know there's not much to work off..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]