SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics > PC Hardware/Software forum
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 12-10-08, 10:32 PM   #1
richardphat
Seasoned Skipper
 
Join Date: Apr 2008
Location: Canada
Posts: 682
Downloads: 17
Uploads: 0
Default Trojan.Zlob.G Help!

Caught it by accident when i jump in a website which "is supposed to be safe".
Looks like it is not.
Security Center Alert me of this trojan and suggest me to download Perfect Defender 2009. Still i can't get ridd of that virus!
richardphat is offline   Reply With Quote
Old 12-10-08, 10:41 PM   #2
FIREWALL
Eternal Patrol
 
Join Date: Mar 2006
Location: CATALINA IS. SO . CAL USA
Posts: 10,108
Downloads: 511
Uploads: 0
Default

What kinda protection do you use now that didn't work ?
__________________
RIP FIREWALL

I Play GWX. Silent Hunter Who ???
FIREWALL is offline   Reply With Quote
Old 12-10-08, 10:57 PM   #3
Reece
CINC Pacific Fleet
 
Reece's Avatar
 
Join Date: Sep 2003
Location: Down Under
Posts: 32,782
Downloads: 171
Uploads: 0
Default

Check this, see post #4:
http://www.cfra.com/computes_show/fo...howtopic=11309
I use Ad-Aware & it's free!
__________________

Sub captains go down with their ship!
Reece is online   Reply With Quote
Old 12-10-08, 11:43 PM   #4
richardphat
Seasoned Skipper
 
Join Date: Apr 2008
Location: Canada
Posts: 682
Downloads: 17
Uploads: 0
Default

Thx guys, i must download it tomorrow.
Oh and by the way, i did some search.
PERFECT DEFENDER 2009 IS A FAKE VIRUS/SPY WARE scanner. In fact it infect your computer.
******* this and i download and install that s***
Now now i should calm.......
richardphat is offline   Reply With Quote
Old 12-11-08, 08:24 AM   #5
Reece
CINC Pacific Fleet
 
Reece's Avatar
 
Join Date: Sep 2003
Location: Down Under
Posts: 32,782
Downloads: 171
Uploads: 0
Default

What is bad is some popups if you press no it's Yes, Yes is Yes & close the window is yes, what I do in this case, just to be sure, is bring up the task manager, highlight the offender & hit "End Task"!!
__________________

Sub captains go down with their ship!
Reece is online   Reply With Quote
Old 12-11-08, 08:54 AM   #6
AVGWarhawk
Lucky Jack
 
AVGWarhawk's Avatar
 
Join Date: Jun 2005
Location: In a 1954 Buick.
Posts: 27,343
Downloads: 90
Uploads: 0


Default

Yeah, I hate those friggin come-ons stating your computer is full of porn or virus'. Download now! Then you can not x out of the petulant come-on. I just end internet connection and start again.
__________________
“You're painfully alive in a drugged and dying culture.”
― Richard Yates, Revolutionary Road
AVGWarhawk is offline   Reply With Quote
Old 12-11-08, 02:59 PM   #7
richardphat
Seasoned Skipper
 
Join Date: Apr 2008
Location: Canada
Posts: 682
Downloads: 17
Uploads: 0
Default

Lol anti spyware bot detect 3138 infected files and yet the scan is not done!
richardphat is offline   Reply With Quote
Old 12-11-08, 09:10 PM   #8
CaptainHaplo
Silent Hunter
 
CaptainHaplo's Avatar
 
Join Date: Apr 2007
Posts: 4,404
Downloads: 29
Uploads: 0
Believe it or not - when your dealing with antispyware - windows defender isnt half bad. Though it is by no means exhaustive.

http://www.symantec.com/security_res...012-99&tabid=2


Symantec's writeups are second to none (wish their AV was) - this could be used to manually remove the trojan and the registry entries related to it. Kill the processes associated with it (in this case nvctrl.exe) and delete the files referenced including all your temp stuff. Once that is done - clean the registry of the keys involved - see the removal tab as well for assistance on part of that. Make sure you reboot after that. Also would be smart to make sure you have an antivirus program running and up to date definition wise at all times.

Windows Security Center will never tell you or advise you to download a non-microsoft program.
__________________
Good Hunting!

Captain Haplo

Last edited by CaptainHaplo; 12-11-08 at 09:11 PM.
CaptainHaplo is offline   Reply With Quote
Old 01-11-09, 07:08 PM   #9
FIREWALL
Eternal Patrol
 
Join Date: Mar 2006
Location: CATALINA IS. SO . CAL USA
Posts: 10,108
Downloads: 511
Uploads: 0
Default

I use AVAST. It doe's everything. Symantic\Norton.

The only way to get rid of it is to reformat.
__________________
RIP FIREWALL

I Play GWX. Silent Hunter Who ???
FIREWALL is offline   Reply With Quote
Old 01-11-09, 07:44 PM   #10
Task Force
Rear Admiral
 
Join Date: Jul 2008
Location: SPACE!!!!
Posts: 10,142
Downloads: 85
Uploads: 0
Default

Somehow, I got that same pop up. exited out of that d** thing quick. scanned with windows defender. Found nothing.:hmm:
__________________
Task Force industries "Taking control of the world, one mind at a time"
Task Force is offline   Reply With Quote
Old 01-11-09, 10:12 PM   #11
Reece
CINC Pacific Fleet
 
Reece's Avatar
 
Join Date: Sep 2003
Location: Down Under
Posts: 32,782
Downloads: 171
Uploads: 0
Default

Start chewing your nails, I got it awhile ago and had to re-ghost my system, nothing I found at the time would fix it, I since switched on DEFENCE+ in COMODO, it's a pain as it asks permission for every new app & process thats initiated but gives peace of mind!
__________________

Sub captains go down with their ship!
Reece is online   Reply With Quote
Old 01-11-09, 10:25 PM   #12
Bill Nichols
Master of Defense
 
Join Date: Mar 2000
Posts: 1,502
Downloads: 125
Uploads: 0
Default

I feel yall's pain... I'm recovering from a nasty infection by the Vandu virus. Had to reformat and reinstall WinXP. Thankfully, I have a backup of all my files

__________________
My Dangerous Waters website:
Bill Nichols is offline   Reply With Quote
Old 01-12-09, 05:24 AM   #13
She-Wolf
Watchdog
 
Join Date: Jan 2007
Location: Hampshire UK
Posts: 971
Downloads: 152
Uploads: 0
Default

Richard - all of you - I fix computers all the time and have had three or four computers infected with this particular stable of fake antivirus products. They are very well put together and will fool a lot of us because they actually use screens such as the Windows splash screen, a blue screen with a fake stop message on, and, as Richard has found, the security centre screen, to make you think the message is genuine and that you should buy that product - all fake. I manually remove all the files I can see are from them, most of which ( apart from straight installs) are in system32 in XP,but you have to be careful as not every file dated the same day and time will necessarily be part of the fake AV package. Also the registry keys and data need to be removed where recognised. However, on the parts that cannot be moved manually, either because you are denied access, even in safe mode, or because they reproduce the moment you have deleted them, I have found a useful little tool that has finished the job off. Possibly just running that tool will do the lot - I don't know.

It is called Malwarebytes Anti-M alware v 1.32 and you can download this latest version from http://www.malwarebytes.org/

ps it is free..
__________________

Last edited by She-Wolf; 01-12-09 at 06:04 AM.
She-Wolf is offline   Reply With Quote
Old 01-12-09, 07:21 AM   #14
rifleman13
Grey Wolf
 
Join Date: May 2008
Location: Depth-charged to Kingdom Come
Posts: 927
Downloads: 28
Uploads: 0
Default

Man...

If you're going to download something, do a search for it first.
The first hint of trouble, DO NOT DOWNLOAD IT!

And...

If you're using Firefox, I suggest you add the add-on: The Web of Trust or WOT for short.

Saves a lot of time and energy identifying bad sites from the good ones.
Remember GREEN is GOOD, RED is BAD!
rifleman13 is offline   Reply With Quote
Old 01-12-09, 07:40 AM   #15
CaptainHaplo
Silent Hunter
 
CaptainHaplo's Avatar
 
Join Date: Apr 2007
Posts: 4,404
Downloads: 29
Uploads: 0
its always smart to do things like turn off popups, set your browser AX controls restrictive, and don't download just because it "looks ok". Also remember - the windows security center will NOT EVER tell you to download new, non-microsoft products. It can remind you that your AV is out of date and should be updated, it can advise you that your OS has patches and such it should have - but these are reminders only, and are only relevant to programs you have already installed.

A side note on Symantec / Norton - their writups on security hazards are excellent. However their home protection software has become bloatware - which is sad. If their AV was not so resource intensive as it has become - then they would have remained at the top of the market.

They remain a powerful and very useful tool in enterprise situations however.
__________________
Good Hunting!

Captain Haplo
CaptainHaplo is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 01:02 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 1995- 2024 Subsim®
"Subsim" is a registered trademark, all rights reserved.