| Computers & Internet For all those computer related discussions. |
07-02-2007, 11:22 PM
|
#1 (permalink)
|
|
Contributing Member
Join Date: 06-30-07
Posts: 331
|
Trojan anomaly?
I was recently informed by Windows live onecare(after running a virus scan)that I have a high risk virus , trojan:win32/anomaly.gen!a. One care cannot delete it, my nortan antivirus cant even find it, my computer shows no side effects yet, But I am worried!
Could any one recomend the best anti virus software, before I go an shell out my hard earned cash, I thought norton was the best but I guess I was wrong
|
|
|
07-03-2007, 09:42 AM
|
#2 (permalink)
|
|
Contributing Member
Join Date: 10-25-06
Location: London, U.K.
Posts: 111
Latest Blog: None
|
Many folk consider Norton to be bloated and ineffective against the latest forms of virus. What you have is a very new variant of another Trojan and Onecare know about it. Most of the time, like you, folk are reporting that Onecare finds it but nothing else does and there's no apparent trouble with the system.
I suggest you run some first line (free) removal programs. These three ...
Superantispyware > http://www.superantispyware.com/
AVG Anti Spyware > http://www.ewido.net/en/
TrojanHunter > http://www.misec.net/
Download each and have them run full scans on your entire systems.
Let them fix whatever they find.
Then run another Onecare scan and let us know if the malware still comes up. There are other things we can do.
OJ
__________________
“A computer lets you make more mistakes faster than any other invention with the possible exceptions of handguns and Tequilla” Mitch Ratcliffe
|
|
|
07-03-2007, 10:15 AM
|
#3 (permalink)
|
|
v7n Mentor
Join Date: 04-13-07
Location: Romania
Posts: 2,936
|
I suggest you Kaspersky AV. It's the best, and it has been proven. No matter what anybody else has to say.
|
|
|
07-03-2007, 12:45 PM
|
#4 (permalink)
|
|
Inactive
Join Date: 07-01-07
Posts: 5
Latest Blog: None
|
Hum,In my opinion,why did One care cannot delete it? Because the trojan is still runing.We know we can't delete the program which is runing.I think you should kill trojan's process firstly. and then,you can delete it easily.I also suggest you KAV, It's always good.
Good luck to U ^ ^
|
|
|
07-03-2007, 12:50 PM
|
#5 (permalink)
|
|
Super Moderator
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 16,395
Latest Blog: None
|
Quote:
Originally Posted by costin_trifan
I suggest you Kaspersky AV. It's the best, and it has been proven. No matter what anybody else has to say.
|
Hmmm!
I guess thats why most Corporates use Mcafee and Symantec then
btw - Kaspersky is definately a good piece of kit and up there with the best of them 
__________________
.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.
|
|
|
07-03-2007, 01:17 PM
|
#6 (permalink)
|
|
Inactive
Join Date: 07-03-07
Posts: 9
Latest Blog: None
|
i use Mcafee it's really great and it helps protect your computer
|
|
|
07-03-2007, 03:15 PM
|
#7 (permalink)
|
|
Contributing Member
Join Date: 06-30-07
Posts: 331
|
Quote:
Originally Posted by oddjob
Many folk consider Norton to be bloated and ineffective against the latest forms of virus. What you have is a very new variant of another Trojan and Onecare know about it. Most of the time, like you, folk are reporting that Onecare finds it but nothing else does and there's no apparent trouble with the system.
I suggest you run some first line (free) removal programs. These three ...
Superantispyware > http://www.superantispyware.com/
AVG Anti Spyware > http://www.ewido.net/en/
TrojanHunter > http://www.misec.net/
Download each and have them run full scans on your entire systems.
Let them fix whatever they find.
Then run another Onecare scan and let us know if the malware still comes up. There are other things we can do.
OJ
|
I was going to download the free trials of these programs, but the publishers could not be verified. Is it safe to run these programs?
|
|
|
07-03-2007, 03:39 PM
|
#8 (permalink)
|
|
Inactive
Join Date: 09-22-06
Location: Los Angeles
Posts: 678
Latest Blog: None
|
Quote:
|
I was going to download the free trials of these programs, but the publishers could not be verified. Is it safe to run these programs?
|
Get used to that ... it simply means that the publisher's "checksums", the little code they include with their programs to verify that they haven't been tampered with during a download, are not in the Microsoft checksum database ... but neither are most of Microsoft's own "hashes", so ...
If you are downloading and installing those programs directly from the publisher's sites, you should be just fine.
This trojan is also known as: "Dropper" and "MESPAM.C", and as Email-Worm.Win32.Zhelatin.bg, Worm/Zhelatin.BG.3, and as a "security risk" named W32/Tibs.TF.
Also check out Clam Antivirus. Note that ALL of the programs listed in this thread EXCEPT for Symantec and McAfee will run just fine all at the same time. And BTW, with the exception of AVG and SuperAntiSpyware (and Clam) are free for personal use ... they are not "free trials" ... they're just "free".
BTW, the Win32/Anomaly.gen!A trojan is classified by OneCare as low severity, low infection rating, easy recovery difficulty (several people report that OneCare successfully removed/quarantined the program), low damage rating and low transmission rating. Apparently it has been distributed by some third-party WinAmp skins (and possibly other programs) and doesn't really affect your system unless you force Windows to install that skin.
(PS: G10: Many corporations use Norton/Symantec and McAfee because Microsoft doesn't support any other AV programs except for those and their own, and most corporations who run large Microsoft networks depend on Microsoft tech support. Those programs are by no means the best, and often cause issues with Windows systems that aren't OEM. In our own corporation, we have been more than satisfied with the performance of the Sophos AV programs - SMTP, server and client - and have found them to be far more reliable and timely in the detection and removal of net-borne bugs than Norton or McAfee, which are often slow to issue new signatures and often have difficulty with the removal process.)
Last edited by StupidScript : 07-03-2007 at 03:49 PM.
Reason: Added aliases.
|
|
|
07-03-2007, 06:26 PM
|
#9 (permalink)
|
|
Inactive
Join Date: 04-04-07
Posts: 5,463
Latest Blog: None
|
NOD32 anti-virus software. The best there is!!!
|
|
|
07-03-2007, 06:57 PM
|
#10 (permalink)
|
|
v7n Mentor
Join Date: 04-13-07
Location: Romania
Posts: 2,936
|
Quote:
Originally Posted by seda
NOD32 anti-virus software. The best there is!!!
|
If an AV program allows you to kill its process, then that's not a good AV.
AV programs that allows that: Avira & Nod32. These two were tested by me on my pc and they miserable failed.
The point is that if I can stop their processes then an attacker can do the same. And that's not desirable, don't you think?

|
|
|
07-03-2007, 07:24 PM
|
#11 (permalink)
|
|
Inactive
Join Date: 04-04-07
Posts: 5,463
Latest Blog: None
|
Quote:
Originally Posted by costin_trifan
If an AV program allows you to kill its process, then that's not a good AV.
AV programs that allows that: Avira & Nod32. These two were tested by me on my pc and they miserable failed.
The point is that if I can stop their processes then an attacker can do the same. And that's not desirable, don't you think?

|
Good point. But I've yet to be failed by NOD.
|
|
|
07-04-2007, 02:06 AM
|
#12 (permalink)
|
|
Contributing Member
Join Date: 10-25-06
Location: London, U.K.
Posts: 111
Latest Blog: None
|
We don't want this thread to go too far off topic for jasonk1234.
Jason ... please do as stupidscript said. Just download from the sites I gave you. They are the original source sites and are all fine.
Please post back and let us know how you get on.
OJ
__________________
“A computer lets you make more mistakes faster than any other invention with the possible exceptions of handguns and Tequilla” Mitch Ratcliffe
|
|
|
07-04-2007, 10:29 AM
|
#13 (permalink)
|
|
Contributing Member
Join Date: 06-30-07
Posts: 331
|
well after almost 9 hours of scanning my computer last night with the recomended antivirus programs, I am haappy to say the trojan anomaly was removed along with a couple other virus's that onecare did not find.
Thank you to all who helped me on this one!!!
|
|
|
07-04-2007, 10:42 AM
|
#14 (permalink)
|
|
Super Moderator
Join Date: 05-10-04
Location: UK - Cheshire
Posts: 16,395
Latest Blog: None
|
Quote:
Originally Posted by StupidScript
(PS: G10: Many corporations use Norton/Symantec and McAfee because Microsoft doesn't support any other AV programs except for those and their own, and most corporations who run large Microsoft networks depend on Microsoft tech support. Those programs are by no means the best, and often cause issues with Windows systems that aren't OEM. In our own corporation, we have been more than satisfied with the performance of the Sophos AV programs - SMTP, server and client - and have found them to be far more reliable and timely in the detection and removal of net-borne bugs than Norton or McAfee, which are often slow to issue new signatures and often have difficulty with the removal process.)
|
I am aware of it but then again I spent 12 years supporting all that nonsense when I was with IBM and have seen some pretty interesting AV's on some sites
Symantec is pretty good at hitting response times when a virus comes out and usually release a utility that you can run from disk.
I personally don't run symantec at home as I have seen better results from Mcafee.
Sophos is very good and I also recommend it but personal choice on home systems is Mcafee.
__________________
.: I WAS BORN WITH NOTHING...AND I STILL HAVE MOST OF IT LEFT!! :.
|
|
|
07-04-2007, 11:08 AM
|
#15 (permalink)
|
|
Contributing Member
Join Date: 10-25-06
Location: London, U.K.
Posts: 111
Latest Blog: None
|
Quote:
Originally Posted by jasonk1234
well after almost 9 hours of scanning my computer last night with the recomended antivirus programs, I am haappy to say the trojan anomaly was removed along with a couple other virus's that onecare did not find.
Thank you to all who helped me on this one!!!
|
Glad to help. Good to hear it worked out for you.
If you are on XP and are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis.
More on System Restore ...
http://www.microsoft.com/windowsxp/u...w_03may19.mspx
What may have lead up to your infection and help keep your computer free of malware …
http://www.castlecops.com/t7736-So_h...rst_place.html
http://www.help2go.com/Tutorials/Pro...Hijackers.html
http://www.techsupportforum.com/secu...do-i-need.html
There is a little duplication/crossover but all these tutorials are well worth reading.
Don’t forget to keep AVG Anti Spyware / Superantispyware updated and use it to scan/disinfect your computer from time to time.
If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) …
http://www.ccleaner.com/
Also run through this before posting another HijackThis log …
http://www.help2go.com/Tutorials/Pro...Hijackers.html
Best wishes.
OJ
__________________
“A computer lets you make more mistakes faster than any other invention with the possible exceptions of handguns and Tequilla” Mitch Ratcliffe
|
|
|
07-06-2007, 04:32 PM
|
#16 (permalink)
|
|
Contributing Member
Join Date: 06-30-07
Posts: 331
|
what do you mean by hijack this log?, I hear this term everywere.
p.s. Thanks for all the help!
|
|
|
07-08-2007, 01:03 AM
|
#17 (permalink)
|
|
Contributing Member
Join Date: 06-30-07
Posts: 331
|
nevermind my last post I understand now, Is there any point in keeping norton antivirus on my computer, or is it just a waste of space now that I have the software that was recommended to me?
|
|
|
07-09-2007, 07:07 AM
|
#18 (permalink)
|
|
Contributing Member
Join Date: 07-05-07
Posts: 128
Latest Blog: None
|
I bet you pay for your norton? Not too sure which version u are running, if its a few months old I would say run norton and disable the second AV.
For run 2 av in background, it conflict.
Just a tip, sometimes if you scan in safe mode, your av will perform better.
|
|
|
07-09-2007, 08:06 AM
|
#19 (permalink)
|
|
Contributing Member
Join Date: 06-30-07
Posts: 331
|
Im using norton 2007, but it doesnt seem to find any of the virus's that these other antivirus programs find.
Thanks for the tips!
|
|
|
|