Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

How do you remove Trojan Virus? My McAfee program can't seem to get rid of it.

20 views
Skip to first unread message

The Sun Tribe

unread,
May 9, 2009, 5:38:42 AM5/9/09
to
I keep getting re-directed when I used search engines. I think I have
trojan virus. Is that what the trojan virus does? Screws up searches
on google and yahoo?

I ran McAfee several times, and each time it detected and removed
NTOSKRNL-HOOK (Trojan). And, my searches on google and yahoo are back
to normal again. But, few days later, I start getting redirected to
funny sites when I do searches again. So, I re-run the McAfee scan and
it says it detected and removed the Trojan hook again. How can I get
rid of it permanently?

Is the SPYHUNTER download software on this site worth it and
effective? : http://www.wiki-security.com/wiki/ov_Parasite_Category/Trojans/

Thanks in advance.

1PW

unread,
May 9, 2009, 6:13:29 AM5/9/09
to
On 05/09/2009 02:38 AM, The Sun Tribe sent:

Hello:

Download, install, update and run the following freeware:

MBAM: <http://www.malwarebytes.org/mbam-download.php>
SAS: <http://www.superantispyware.com/superantispywarefreevspro.html>

Please update this thread with your progress. IMO, the above are the
top two applications of their kind.

HTH

Pete
--
1PW @?6A62?FEH9:DE=6o2@=]4@> [r4o7t]

Jose

unread,
May 9, 2009, 12:51:31 PM5/9/09
to

If Malwarebytes doesn't fix it, let us know.

If you or your AV scans can say what trojan was found, that will also
be good to know.

Jose

unread,
May 9, 2009, 12:55:34 PM5/9/09
to

Oops - you did identify it. Did it give any other clues?

Try the Malwarebytes and if that doesn't do it, run MBAM again in safe
mode.

Does Start, Run, regedit work? How about Start, Run, cmd?

Please report back.

Buffalo

unread,
May 9, 2009, 12:58:58 PM5/9/09
to

I was under the impression that MBAM worked better in Normal mode while SAS
works better in Safe Mode.


Jose

unread,
May 9, 2009, 1:33:04 PM5/9/09
to

That could very well be, I sure don't know for sure either way! I
think I have only booted in safe mode twice in my life.

David H. Lipman

unread,
May 9, 2009, 4:50:41 PM5/9/09
to
From: "Buffalo" <Er...@nada.com.invalid>


| I was under the impression that MBAM worked better in Normal mode while SAS
| works better in Safe Mode.


You are correct.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


Frank

unread,
May 9, 2009, 6:25:15 PM5/9/09
to

I imagine virus can be different but one got past my McAfee and when I
restored computer to previous date but McAfee would not work and I had
to remove it. Rather than reinstall I thought I'd try free Avast

> http://www.avast.com/eng/avast_4_home.html

and it found and removed the Trojan virus. Been about 6 trouble free
weeks now. The virus had reverted my computer to about the day I had
bought it and none of my files were there including new programs I had
installed. It was frightening but fortunately Vista restored to a
previous date and all was OK.


McAfee is free from Comcast isp but for me has always been a PITA as a
resource hog.

David H. Lipman

unread,
May 9, 2009, 6:31:15 PM5/9/09
to
From: "Frank" <frankperi...@comcast.net>

>> Thanks in advance.

>> http://www.avast.com/eng/avast_4_home.html

Either it is a trojan or a virus. Its one or the other (unless you have a case of a
trojan infected with a virus).

Saying "trojan virus" ike like saying my car is is a Ford Chrysler.

FromTheRafters

unread,
May 9, 2009, 6:52:54 PM5/9/09
to
"The Sun Tribe" <and-...@live.com> wrote in message
news:5def6616-7b04-43bd...@r13g2000vbr.googlegroups.com...

>I keep getting re-directed when I used search engines. I think I have
> trojan virus. Is that what the trojan virus does? Screws up searches
> on google and yahoo?

There is no such thing as a "trojan virus" despite what you may have
heard.

Mostly, search engine hijacks and browser hijacks are adware/foistware
related.

> I ran McAfee several times, and each time it detected and removed
> NTOSKRNL-HOOK (Trojan). And, my searches on google and yahoo are back
> to normal again. But, few days later, I start getting redirected to
> funny sites when I do searches again. So, I re-run the McAfee scan and
> it says it detected and removed the Trojan hook again. How can I get
> rid of it permanently?

You may be getting rid of it just fine, but then re-exposing yourself to
the foistware by visiting certain sites with your security settings to
lenient.

> Is the SPYHUNTER download software on this site worth it and
> effective? :
> http://www.wiki-security.com/wiki/ov_Parasite_Category/Trojans/

I don't know too much about that one, but I don't think they will help
you as much as increased security will. If you really are being only
partially cleaned by McAfee (or other antimalware), I would suggest
MalwareBytes Antimalware (MBAM) and SuperAntiSpyware (SAS) because of
the good recommendations I hear about them in these security related
newsgroups.


Jose

unread,
May 9, 2009, 7:47:20 PM5/9/09
to

I agree about McAfee - I have Comcast also. Slow and a resource hog
like you said, plus it never found a darn thing. Now it is history.

I am up on MBAM for the moment. Never tried SAS, but might.

I think he means it like - "the TROJAN virus!", like that is the name
given to the virus, TROJAN. I'm sticking with "malicious software" to
be safe.

Good to know about the safe mode thing...

FromTheRafters

unread,
May 9, 2009, 8:03:51 PM5/9/09
to
"Jose" <jose...@yahoo.com> wrote in message
news:7d62d976-5dd5-49ac...@m24g2000vbp.googlegroups.com...

> I think he means it like - "the TROJAN virus!", like that is the name
> given to the virus, TROJAN.

That would be an incredibly stupid name for the professionals to use for
a virus.

> I'm sticking with "malicious software" to be safe.

Malware (malicious software) is the correct umbrella term. A virus is a
particular type of recursively self-replicating malware.


Buffalo

unread,
May 9, 2009, 8:20:44 PM5/9/09
to

David H. Lipman wrote:
>> Saying "trojan virus" ike like saying my car is is a Ford Chrysler.

I never knew they made them. :)


Frank

unread,
May 15, 2009, 2:27:37 PM5/15/09
to

Can't remember exactly what Avast said, but word "Trojan" was there.
The way the govmint is mucking up the auto industry, I expect to see a
Ford Chrysler one day ;)

Buffalo

unread,
May 15, 2009, 3:18:20 PM5/15/09
to

Frank wrote:
> Can't remember exactly what Avast said, but word "Trojan" was there.
> The way the govmint is mucking up the auto industry, I expect to see a
> Ford Chrysler one day ;)

Yes, it will be called a Chryord .
Buffalo


FromTheRafters

unread,
May 15, 2009, 3:23:01 PM5/15/09
to
"Frank" <frankperi...@comcast.net> wrote in message
news:gukc6q$mu2$1...@news.motzarella.org...
> David H. Lipman wrote:

>> Either it is a trojan or a virus. Its one or the other (unless you
>> have a case of a trojan infected with a virus).
>>
>> Saying "trojan virus" ike like saying my car is is a Ford Chrysler.
>>
>
> Can't remember exactly what Avast said, but word "Trojan" was there.

That wouldn't surprise me - but that doesn't make it correct. :o)

A generally acceptable (but also not entirely correct) hierarchical view
is that it is a trojan, unless it recursively self-replicates, in which
case it is a worm, unless it attaches it's replicant to code, in which
case it is a virus. In actuality the terms are not mutually exclusive.
Each virally infected file for instance can be considered a trojan.
Worms often first present themselves to the victim as a trojan as part
of their lifecycle. Some experts view all replicating code as "virus"
and place "worm" as a subtype of virus - trojans don't recursively
self-replicate. So it is a trojan unless it recursively self-replicates,
in which case it is a virus or worm (which is a type of virus). I think
David subscribes to this view.


David H. Lipman

unread,
May 15, 2009, 4:16:44 PM5/15/09
to
From: "FromTheRafters" <err...@nomail.afraid.org>


What he said :-)

Wolf K

unread,
May 15, 2009, 7:01:32 PM5/15/09
to

For-Cry-inoutloud.

wolf k.

the-changling

unread,
May 28, 2009, 11:47:55 PM5/28/09
to

If you actually are compromised with a virus (different than simply
catching a virus within a file) the only way to be sure is a wipe and
reinstall.

0 new messages