peter e Posted February 23, 2004 Report Share Posted February 23, 2004 I appear to have got myself a trojan. :angry: To cut a long story short, tonight I opened an e-mail in my hotmail account from my sister-in-law. There was no attachment. But shortly after I opened the e-mail, Norton popped-up and said I was infected with the Trojan.ByteVerify.I went to their site and followed their instructions to the letter (downloaded new updates, switched off System Restore, Booted in Safe Mode, ran a scan). It found five infections but could only quarantine one of them and wouldn't quarantine or delete the other four.It's odd because I'm on live update and it's been very active lately. Even so, there were five updates for me to download from Norton's site. I have Sygate firewall, and run AdAware and Spybot at least once each week.Also, the Norton site said that this particular trojan was easy to detect and delete!Anyway, what can I do now? Advice appreciated.peter e Quote Link to comment Share on other sites More sharing options...
bvw Posted February 23, 2004 Report Share Posted February 23, 2004 To see hidden files:On the Tools menu in Windows Explorer, click Folder Options. Click the View tab. Under Hidden files and folders, click Show hidden files and folders.Note To access Windows Explorer, click Start, point to All Programs, and then click Windows Explorer.You'll probably find it in a hidden file or folder, delete it from there. Quote Link to comment Share on other sites More sharing options...
Boris Posted February 23, 2004 Report Share Posted February 23, 2004 Is your IE Home Page still set to what you think it should be ? Quote Link to comment Share on other sites More sharing options...
Guest ellas Posted February 23, 2004 Report Share Posted February 23, 2004 would suggest running coolwebshedder but it seems to be down,try ad aware Quote Link to comment Share on other sites More sharing options...
Boris Posted February 23, 2004 Report Share Posted February 23, 2004 If it has changed - I think it may be a coolwebsearch variant ?Download CW Shredder from here :-http://www.majorgeeks.com/download4086.html Quote Link to comment Share on other sites More sharing options...
peter e Posted February 23, 2004 Author Report Share Posted February 23, 2004 Yes, Boris. The write up on the trojan says it will change the home page and may add porno links to favourites. None of this appears to have happend.I followed bvw's advice and have found two (?) files named TrojanByteVerify.Here's the screen dump of their properties. Is this them? Can I delete them? Quote Link to comment Share on other sites More sharing options...
Guest ellas Posted February 23, 2004 Report Share Posted February 23, 2004 delete,it wont change things because norton has quarantine it. Quote Link to comment Share on other sites More sharing options...
Boris Posted February 23, 2004 Report Share Posted February 23, 2004 Go for it ! Quote Link to comment Share on other sites More sharing options...
Boris Posted February 23, 2004 Report Share Posted February 23, 2004 Read this !http://computercops.biz/postt13332.html Quote Link to comment Share on other sites More sharing options...
bvw Posted February 23, 2004 Report Share Posted February 23, 2004 Yes, delete them Peter then do another scan.....you should get the exact path to any other files/folders that may have the virus.Make a note of these, find and delete them as well. Quote Link to comment Share on other sites More sharing options...
peter e Posted February 23, 2004 Author Report Share Posted February 23, 2004 Sorry to have taken so long. I deleted one of them but the other refused to be deleted in the normal way. It was in the temporary internet files folder. Eventually I selected All and deleted the lot. That seems to have done it.How come Norton couldn't delete them?Anyway, thank you all for your help. It's much appreciated. I'll run another search and a scan to make sure it's all gone. Thanks again.peter e Quote Link to comment Share on other sites More sharing options...
Chris Posted February 23, 2004 Report Share Posted February 23, 2004 http://securityresponse.symantec.com/avcen...byteverify.html Quote Link to comment Share on other sites More sharing options...
peter e Posted February 23, 2004 Author Report Share Posted February 23, 2004 Thank you, Boris. I'll download the shredder thingy. I must say I'm a bit disappointed with Norton. Quote Link to comment Share on other sites More sharing options...
Guest ellas Posted February 23, 2004 Report Share Posted February 23, 2004 run coolwebshedder,norton cant delete in the temp folder,its doing its job keeping it in there till you empty it,doubt if any thing has been changed. Quote Link to comment Share on other sites More sharing options...
Guest ellas Posted February 23, 2004 Report Share Posted February 23, 2004 why disappointed with norton it did its job,it quarantined it in the temp folder so it could not run. Quote Link to comment Share on other sites More sharing options...
Andy-2004 Posted February 23, 2004 Report Share Posted February 23, 2004 i cant remember where the origional post was but i figured i could borrow this thread for a secthere was once a post where sum1 said about the process - scvhost.exethey said that it could well be a virus...well i remembered this and today noticed i had this process running....5 times over!!any thoughts? Quote Link to comment Share on other sites More sharing options...
Guest ellas Posted February 23, 2004 Report Share Posted February 23, 2004 normal Quote Link to comment Share on other sites More sharing options...
Andy-2004 Posted February 23, 2004 Report Share Posted February 23, 2004 soo you think it isnt a vius or nething to worrie about? Quote Link to comment Share on other sites More sharing options...
peter e Posted February 24, 2004 Author Report Share Posted February 24, 2004 Well, ellas, I suppose it did limit the infection. But the Norton scan found five infected files, it quarantined one but said it couldn't delete or quarantine the other four. I don't understand why it couldn't do that. I don't know much about viruses etc so maybe I was expecting too much. I've just run the Coolshredder thing and it said everything was clear. :) Incidentally, I thought viruses etc were normally in attachments. The e-mail from my sister-in-law didn't have an attachment so how does the Trojan hide? Or am I barking up the wrong tree. If it was in that e-mail I guesss my sister-in-law has the Trojan on her machine too.Anyway, thanks for your help, ellas. Quote Link to comment Share on other sites More sharing options...
Boris Posted February 24, 2004 Report Share Posted February 24, 2004 soo you think it isnt a vius or nething to worrie about?Its part of XP :D Quote Link to comment Share on other sites More sharing options...
Guest Shirley_Crabtree Posted February 24, 2004 Report Share Posted February 24, 2004 ssvchost.exe in startup is the one to worry about. ;) Quote Link to comment Share on other sites More sharing options...
Andy-2004 Posted February 24, 2004 Report Share Posted February 24, 2004 rite thanks Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.