This is topic Trojan Horse PSW.Agent.AUH in forum Books, Films, Food and Culture at Hatrack River Forum.


To visit this topic, use this URL:
http://www.hatrack.com/ubb/main/ultimatebb.php?ubb=get_topic;f=2;t=041512

Posted by pH (Member # 1350) on :
 
What does it do? I can't find any information on it through Google.

-pH
 
Posted by Boris (Member # 6935) on :
 
Password stealer. Basically, it logs all the passwords you enter on your computer and emails them to someone.
 
Posted by pH (Member # 1350) on :
 
Seriously?

[Eek!] [Eek!] [Eek!] [Eek!]

What do I do? I clicked "Heal" on the anti-virus because when I tried to just delete the infected file, it said that it was a system file, and if I deleted it, Windows might not work anymore. And there were like ten infected system files.

Is it gone? Do I need to change all my passwords? What if I logged into my school account with my social security number before the anti-virus found it?!

-pH
 
Posted by fugu13 (Member # 2859) on :
 
Run the virus check again.

Backup all the files you care about.
 
Posted by pH (Member # 1350) on :
 
What if I logged into Napster and it has my credit card information?!

-pH
 
Posted by pH (Member # 1350) on :
 
I took the computer to Best Buy. They said all the viruses are gone, and everything should be cool. In fact, they said my computer doesn't even have adware or spyware.

But when I got home, it detected the virus again, but this time it was in a temp file (before, the virus was in System32 files). I deleted all my temp files. Do I need to be worried? Should I reinstall Windows anyway? I really don't want to reinstall if I don't have to. I'm lazy, and I'm not sure where I put my system disks, and I'll probably end up paying Best Buy $80 to do it for me. [Frown]

-pH
 
Posted by Boris (Member # 6935) on :
 
Do you have system restore on? If so, turn it off, run the scan again. If it still shows up, you might look into re-formatting. If not, you're good.
 
Posted by pH (Member # 1350) on :
 
...how do I do that?

-pH
 
Posted by pH (Member # 1350) on :
 
Also, I have AVG as my antivirus. If all of these files are in the "Virus Vault" and I click "Wipe Objects," does that delete the file or set it free to roam about my computer once more?

What if I click "Empty Vault?"

-pH
 
Posted by Corwin (Member # 5705) on :
 
quote:
What does it do?
Do? It doesn't do an... Oh, wait, wrong thread...
 
Posted by Corwin (Member # 5705) on :
 
quote:
...how do I do that?
Now for a real (try of an) advice: I've actually done that, but I don't remember where exactly you shut down the system restore, may be in the "My Computer" properties somewhere. If no one comes up with other info I'll look it up tomorrow. It's 5AM here, I need to sleeeeep now...

Edit: Wait, found it. Go to "My Computer" and right click and go to Properties, then to the System Restore tab, then check "Turn off System Restore on all drives". Do the scan, the start it again.

Can't help you with the antivirus thingy though, but I don't think it lets them "free". That would be a first! o_O
 
Posted by Boris (Member # 6935) on :
 
quote:
Originally posted by pH:
Also, I have AVG as my antivirus. If all of these files are in the "Virus Vault" and I click "Wipe Objects," does that delete the file or set it free to roam about my computer once more?

What if I click "Empty Vault?"

-pH

The virus vault is basically a safe place where viruses can be kept until you are certain that your computer can run properly without the files (and to make certain something wasn't mistakenly erased). Clicking wipe files will delete them from the hard drive permanently.
 
Posted by Corwin (Member # 5705) on :
 
Empty Vault (make a search for "Empty Vault" on that page)

I don't understand why there are both Wipe Objects and Empty Vault. o_O Maybe Wipe Objects is for immediate deletion, not passing through the Vault?! I don't really know, I've never used AVG.
 


Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2