Log on:
Powered by Elgg

Terry Wassall :: Blog :: Trojan attack

May 15, 2006

I have just spent the whole weekend trying to clean a new PC of various spys,  malware, viruses etc. The worst one kept hijacking my browser home page so it went to a site selling antispy software. It also produced false Windows security messages and even changed my desktop image to one that looks like a blue screen of death. I also got advert windows popping up even when not on-line. All invited me to download software of one sort or another. Windows Defender found nothing. Spy Doctor (a PCtools product and highly rated) found 81 infections but wants a credit card number to register and clean. For obvious reasons I am not keen to enter my cared number.  Adaware found nothing, nor did Spybot, recommended on teh MS Windows security site. Windows firewall couldn't spot a trojan if it was made of wood and was pushed in by 100 sweaty soldiers. However Prevx did find it and has cleaned sucessfully. It is free for 28 days. I think I will probably buy this in due course. I have also installed the free basic version of ZoneAlarm, recommended by my computer services people (as was Adaware). Very effective but not easy to use for a non-techy like me. I may be blocking stuff I shouldn't.

 Any advice would be gratefully received. Any recommendations of antispyware, firewalls, security strategies etc? I think UNIX is probably not an option for me for the above reasons of non-techyness.

Keywords: firewalls, Spyware, trojans

Posted by Terry Wassall


Comments

  1. Hello, Terry,

    Sorry to hear about your spyware woes -- this anti-spyware cocktail has worked well for me:

    a hardware firewall through my home/office wireless
    a software firewall (McAfee or Symantec will do)
    AdAware and Spybot, with the list of spyware updated regularly
    antivirus software (I currently use Symantec AV)
    Foxfire for all browsing (I use explorer for testing sites I design, but that's about it)
    Thunderbird mail, with settings set to not display inline images

    I've been using this setup for at least the last year, and, at the risk of jinxing myself, I've been largely spyware-free.

    Hope this helps.

    Cheers,

    Bill 

    Bill FitzgeraldBill Fitzgerald on Tuesday, 16 May 2006, 04:25 CEST # |

  2. Do you have any anti-virus software installed?

    I use the free one from http://free-av.com/

    Sven EdgeSven Edge on Tuesday, 16 May 2006, 11:29 CEST # |

  3. Thanks for the advice and information. I have McAfee antivirus installed and this is updated regularly Sven. But this didn't prevent or detect the infection. I guess it wouldn't as McAfee sell a separate spyware detector program. Thanks for the info on Antivir. It looks like the paid for version includes spyware detection.

    Using ZoneAlarm rather than the Windows firewall works ok, although as I said in my post it is a bit intermedating for a novice. I'm nor sure what a 'hardware firewall' is Bill. Is this something I have got that just needs switching on?

    Terry WassallTerry Wassall on Tuesday, 16 May 2006, 14:04 CEST # |

  4. Hello, Terry,

    A hardware and software firewall do pretty similar things -- the software firewall runs on your computer, where the hardware firewall runs on a piece of hardware on your network --

    For small networks (ie, home/small office wireless) the hardwire firewall comes with the cable/dsl modem. If you're working at a larger school, they almost certainly have a hardware firewall installed.

    FWIW, my wife has the McAfee antispyware, antivirus, software firewall, and she has also been spyware free for the last several months.

    Cheers,

    Bill 

     

    Bill FitzgeraldBill Fitzgerald on Tuesday, 16 May 2006, 14:46 CEST # |

  5. Thanks Bill. I think we are pretty bullet-proof on campus behind our firewall - at least I hope so. I like McAfee AV and it has kept me safe form viruses for several years now. I think it will be worth giving their antyspyware and firewall a go too. Cheers.

    Terry WassallTerry Wassall on Tuesday, 16 May 2006, 17:17 CEST # |

  6. I would also recommend changing your browser to Firefox -- it's pretty much the same as Explorer for all intents & purposes, and you're much less open to all the junk on the web.  The other thing I'd suggest is installing the google toolbar, as that stops a lot of the malicious pop-up stuff.  I've installed that on all of my user's pcs, as it keeps them from clicking on things that they shouldn't.

    Nathan GarrettNathan Garrett on Wednesday, 24 May 2006, 15:59 CEST # |

  7. Thanks for this Nathan. I have been using both IE and FireFox for a while and have almost finished using IE altogether. But I do need to test stuff in it as my institutional browser is IE. I'll get the Goole toolbar and see how it works.

     Cheers.

    Terry WassallTerry Wassall on Wednesday, 24 May 2006, 20:45 CEST # |

  8. Terry:

    Work limits me to IE, but I've had a very similar experience to yours.  I found that a few tools are often required to sort out a problem like the one you had.

    • Download the trial version of Ewido.  I found it to be excellent at spotting things that the Corp. A/V didn't see.
    • Download XoftSpy.  It was well worth the purchase.  It basically acts as a 'sweeper' to look for malware
    • Try x-cleaner.  Works as above

    The tools sweep my machine regularly and I'm willing to forego the loss of "remember me" cookies for some peace of mind.

    I found myself highly pissed that an alleged 'Spyware Removal' tool masqueraded so effectively as a legit piece of software, but basically hijacked my machine...to say nothing of losing an entirel weekend to getting the machine back up and running effectively.

    Makes one wish for some form of retributive justice, doesn't it?

    Mark L. SheppardMark Sheppard on Friday, 14 July 2006, 20:14 CEST # |

  9. Hanging's too good for them Mark!!

    Thanks for all the advice everyone has given me. I finally settled on 2 products.  I have installed PCtools Spyware Doctor. This and another malware detection utility, Prevx1, were the only ones I tried that detected the infection I had. Both are free for a while but have to be subscribed to for continued use. Both will continue to detect after the time limit but cease to remove. I have subscribed to both for the moment, Prevx1 is about £10 per year and Spydoctor £24. I also run McAfee anti-virus. This is free as we have a campus license. One of the two, I can't remember which one, is incompatible with the ZoneAlarm fire wall I usually run so I have uninstalled ZA and turned on the Windows XP firewall instead. I also run Adaware form time to time but now it never finds anything critical. As a matter of interest Windows Defender found nothing!

    Terry WassallTerry Wassall on Tuesday, 15 August 2006, 07:31 CEST # |

You must be logged in to post a comment.