It's called Forthgoer, a password stealer, and is on my desktop. I'm usually quite careful about things, but my kids are on this computer and who knows. Windows Defender catches it and removes it, but it keeps appearing so I must have some file running that keeps downloading it.
Anybody want to help spot something suspicious?
Logfile of HijackThis v1.99.1
Scan saved at 10:51:02 PM, on 8/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
this may not help in the here and now, but i work in IT and at home i have 4 computers networked and i run Norton Internet Security on all along with Spybot (free) I have yet to have any problems in the 5 years i have gone with this. Another good precaution is to get into your router setup and disable wan ping, may also be called internet ping or wan side ping.that basically keeps your pc's from answering when hackers are pinging around looking for open machines.
i would suggest running that, and possibly a spybot search & destroy.
(avail at download.com)
-----
so far, everything i've found online about the virus mentions Windows Defender as being the detector.. did you install this program? it sounds fishy to me.
i would suggest running that, and possibly a spybot search & destroy.
(avail at download.com)
-----
I concur on downloading the AVG. Even the FREE version is an incredible thing. At the Grisoft Site, you can also download the AVG Anti-Spyware or the security suite (probably named different than that) that AVG just bought and tweaked and they are sweet!
And, although I know this may create some grumbling... download and switch to Firefox as your browser. MSIE seems (to me anyway) to be wrought with problems. Firefox is free... and less susceptible to security issues. And... there are a whole lot of add-ons to make things fun.
I heard once that it is best to run the ad/spyware and virus software after you do a safe boot, does this really make a difference?
Last week I ran adaware on a guys computer and found 462 (yes that number is correct) items. I deleted them and thought his system was clean but have to go back tonight to run spybot and see if we can find his problem. He said that after being on the internet (happens no matter what page he visits) for about 10 minutes he gets a ton of pop-ups and stuff that says HP update.
Of course, that's no guarantee that the trojan won't just add the key straight back in! - It would be more thorough to run an anti-virus program to remove it.
I heard once that it is best to run the ad/spyware and virus software after you do a safe boot, does this really make a difference?
Last week I ran adaware on a guys computer and found 462 (yes that number is correct) items. I deleted them and thought his system was clean but have to go back tonight to run spybot and see if we can find his problem. He said that after being on the internet (happens no matter what page he visits) for about 10 minutes he gets a ton of pop-ups and stuff that says HP update.
a safe boot does a few good things, it doesn't allow access to the internet, and it only loads the drivers/applications that windows needs to operate.
personally, i think you need to configure your antivirus to run on next startup. what this does is it allows the antivirus program to run/scan/delete ... BEFORE any other application. this greatly increases your chances of getting rid of the infection.
Of course, that's no guarantee that the trojan won't just add the key straight back in! - It would be more thorough to run an anti-virus program to remove it.
Haven't had time to read all of this as I am off to work, but did anyone mention that the good Doc should turn off his system restore before he starts his scanning process, it could be that his virus is re-infecting his system with every start-up.
Ray
PS: I run Ad-Aware SE Personal, Spybot Search and Destroy for anti-spyware , and Avast and AVG for virus scanning and have encountered no problems to date.
Thanks for the help guys. I think I'm getting on top of it. I'll have to see if it's there again when I get home. I used Dr-Fixit or something like that and it found two sources. I had also found the woso file myself on Hijackthis, but hadn't seen the other (crasos).
I'm embarassed for having one. I don't think I've had a virus on the computer since Virginia over 5 years ago.
When I caught a trojan earlier this year, the only thing that could zap it was a McAfee and Spy Sweeper combo. Neither are free, but the free stuff didn't work.
When I caught a trojan earlier this year, the only thing that could zap it was a McAfee and Spy Sweeper combo. Neither are free, but the free stuff didn't work.
I have the free version of AVG and Avast, and both of these have worked famously for me. I also visit Trend Micro on a weekly basis and take advantage of their free scanning programs.
Hmmmm...while you're busy housecleaning your computer, you may consider changing any passwords you use for online banking, ebay, amazon or any account that gives access to credit card information.
I used this site some time ago and experts at the site will review your log file and help you remove the bad stuff. Worked like a charm for me. Read the rules on posting log files/seeking help.