FacebookTwitter
Hatrack River Forum   
my profile login | search | faq | forum home

  next oldest topic   next newest topic
» Hatrack River Forum » Active Forums » Books, Films, Food and Culture » Uh. Crap. I have a Trojan Horse virus.

   
Author Topic: Uh. Crap. I have a Trojan Horse virus.
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
I've lost the package to my Halo CD, and needed to download a key generator to re-install my computer. I downloaded one, but then Norton Antivirus pops up telling me I have a virus and it can't do anything about it. I'm running a virus scan right now, but the little box from Norton's repeatedly said it can't repair or delete the file.

Just how screwed am I right now?

Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
Ayelar
Member
Member # 183

 - posted      Profile for Ayelar   Email Ayelar         Edit/Delete Post 
No offense, Lalo, but you would be so much happier with a Mac... [Smile]
Posts: 2220 | Registered: Jun 1999  |  IP: Logged | Report this post to a Moderator
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
Probably, but I'm in debt with this computer, and in no financial shape or mood to spend another couple grand on a pretty-boy computer with a one-button mouse.
Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
Farmgirl
Member
Member # 5567

 - posted      Profile for Farmgirl   Email Farmgirl         Edit/Delete Post 
Usually if you go to McAfee's or Norton's web sites, and type in the name of the trojan you system has caught, there will be instructions on how to manually rip it from your system and registry.

FG

Posts: 9538 | Registered: Aug 2003  |  IP: Logged | Report this post to a Moderator
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
Dammit. I wonder if my computer getting a virus means that one of the squirrels is sick...
Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
It provided a link to the page, and it told me I have a Trojan horse virus and no other information. Literally, they had something along the lines of "You have a Trojan Horse virus. There is no further information for you because we like to watch you squirm."
Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
aspectre
Member
Member # 2222

 - posted      Profile for aspectre           Edit/Delete Post 
Sometimes, virus breeders program to attack&defeat the most common anti-virus software,
so go to TrendMicro.

Posts: 8501 | Registered: Jul 2001  |  IP: Logged | Report this post to a Moderator
fugu13
Member
Member # 2859

 - posted      Profile for fugu13   Email fugu13         Edit/Delete Post 
This is why you don't download key generators . . .

I can't mention them here, but there are so many better ways to pirate windows!

Posts: 15770 | Registered: Dec 2001  |  IP: Logged | Report this post to a Moderator
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
Uh. This is strange. I ran Norton Antivirus to find it, and it finds nothing. I had an online thing from Symantec (same company) doing a virus check, then played a game of AoM online -- when I get back, the window's gone.

Does this mean the virus died?

Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
No, wait, now the Symantec window exists. It promises that my computer's safe from virii and Trojan horses.

What the hell happened to it, then?

Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
Hobbes
Member
Member # 433

 - posted      Profile for Hobbes   Email Hobbes         Edit/Delete Post 
Turns our is really was just a big wooden horse.

Hobbes [Smile]

Posts: 10602 | Registered: Oct 1999  |  IP: Logged | Report this post to a Moderator
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
By the way, Fugu, if you can suggest a way to get a keygen for this game, I'd appreciate it. It's not piracy -- I do own the game -- but I've lost my key and I could really use one.

If only to see how Halo performs on my brand new DSL.

Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
Argèn†~
Member
Member # 4528

 - posted      Profile for Argèn†~           Edit/Delete Post 
Why don't you just call Microsoft, tell them you have the CD, and that you lost the packaging with the key on it? They would most likely just give you a new key once you answered a couple questions. They are usually that easy with software that costs way more and is more important than just a game.
Posts: 346 | Registered: Jan 2003  |  IP: Logged | Report this post to a Moderator
TomDavidson
Member
Member # 124

 - posted      Profile for TomDavidson   Email TomDavidson         Edit/Delete Post 
Lalo, I think it's very likely that you never actually had a trojan horse virus, and were just a victim of a common web browser exploit that pops up a fake window TELLING you that you have a trojan horse.

For one thing, both Norton and McAfee will always tell you the NAME of the virus, even before they tell you the type, when they find it.

Posts: 37449 | Registered: May 1999  |  IP: Logged | Report this post to a Moderator
WheatPuppet
Member
Member # 5142

 - posted      Profile for WheatPuppet   Email WheatPuppet         Edit/Delete Post 
Damn Greeks! How dare they put a giant wooden horse inside your computer. What's worse, they didn't even fill it with murderous hoplites! What nerve! ;-)
Posts: 903 | Registered: May 2003  |  IP: Logged | Report this post to a Moderator
Bokonon
Member
Member # 480

 - posted      Profile for Bokonon           Edit/Delete Post 
Tom, or as another possibility, it could be the Windows Messenger exploit, which looks like a regular popup window.

-Bok

Posts: 7021 | Registered: Nov 1999  |  IP: Logged | Report this post to a Moderator
TomDavidson
Member
Member # 124

 - posted      Profile for TomDavidson   Email TomDavidson         Edit/Delete Post 
You know, Bok, I bet that's it. Eddie just got DSL, and I doubt he sprung for a hardware firewall because I don't think he really knows what one does. [Smile]

Eddie, be sure to turn off the Messenger service on your machine. Do you know how to do that?

Posts: 37449 | Registered: May 1999  |  IP: Logged | Report this post to a Moderator
Lalo
Member
Member # 3772

 - posted      Profile for Lalo   Email Lalo         Edit/Delete Post 
I may be computer-illiterate, but I'm not dumb, Tom. Regardless of how often Pete repeats it. I know what a firewall is, and I currently have a six-month trial of McAfee Guardian running. If this virus was a hoax, it was a damn good one -- the virus scanner caught it during the download of the keygen, and after starting Norton Antivirus it linked to a Symantec site which proceeded to ID the virus -- or rather, tell me the brand without telling me the product -- and scan my computer.

That's a damn good hoax.

Windows Messenger boots with startup, and it's never been compromised before -- it'd be one hell of a coincidence for it to act as a backdoor for this exploit, whatever it is, right when I was downloading the keygen. I can't turn off Windows Messenger because it claims I have IE open -- even after I close all windows. If I can't turn it off from the taskbar, how do I do it?

Posts: 3293 | Registered: Jul 2002  |  IP: Logged | Report this post to a Moderator
TomDavidson
Member
Member # 124

 - posted      Profile for TomDavidson   Email TomDavidson         Edit/Delete Post 
I don't mean Windows Messenger, the IM. I mean the Messenger service, which is used by machines on a network to communicate to each other with the "NET SEND" command. It's a common way of spreading spam -- although I believe Guardian shuts it down by default, so that may not be it.

I've just never heard of a virus alert from Symantec that didn't identify the virus prominently by name. What do the Norton logs say? By default, NA logs all detected viruses in a text file -- date, time, name, and action taken.

----

A possibility: the keygen software could indeed have had an easily recognizable virus in it, and either Norton or Guardian -- both of which are capable of doing this -- could have noticed the virus as a component of the file during the download. By default, I believe, both programs automatically delete any virus-laden program coming in over FTP or HTTP. In this case, you would have received a warning -- which STILL should have had the name, but anyway -- and subsequent scans would display nothing, since the download would have been aborted before it completed and the temp file purged.

[ January 06, 2004, 02:55 PM: Message edited by: TomDavidson ]

Posts: 37449 | Registered: May 1999  |  IP: Logged | Report this post to a Moderator
Teshi
Member
Member # 5024

 - posted      Profile for Teshi   Email Teshi         Edit/Delete Post 
I'm pretty sure I had the Trojan Horse last year. I don't think I actually lost anything, but it wasn't me who got rid it, it was my brother, so no help except encouragement.
Posts: 8473 | Registered: Apr 2003  |  IP: Logged | Report this post to a Moderator
Liquor and Fireworks
Member
Member # 5785

 - posted      Profile for Liquor and Fireworks   Email Liquor and Fireworks         Edit/Delete Post 
To disable Messenger Service: Start Menu->Administrative Tools->Services, go down to messenger, right click it, go to properties, set start up type to disabled.
Posts: 331 | Registered: Oct 2003  |  IP: Logged | Report this post to a Moderator
Ryan Hart
Member
Member # 5513

 - posted      Profile for Ryan Hart           Edit/Delete Post 
That's what you get for throwing your lot in with Sataan.
Posts: 650 | Registered: Aug 2003  |  IP: Logged | Report this post to a Moderator
fugu13
Member
Member # 2859

 - posted      Profile for fugu13   Email fugu13         Edit/Delete Post 
In this case, trojan horse is referring to the type, rather than the name, of the virus. Which does suggest it came along in the keygen program.

Yeah, the best solution if you own the software is call the maker.

Posts: 15770 | Registered: Dec 2001  |  IP: Logged | Report this post to a Moderator
   

   Close Topic   Feature Topic   Move Topic   Delete Topic next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:


Contact Us | Hatrack River Home Page

Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2