Stuka Stunt Control Line Forum
Archive, 2000–2021 · recovered from the Internet Archive
Forums › Stuka Stunt Main Forum

troj_sagent.a virus help!

Stuka Stunt Main Forum · 18 of 18 known posts recovered

elmores · Jun 08, 2004 04:38 PM

#0 source
EEEK!

This is a nasty one that has led to me having to cancel my credit card it's a keystroke recorder that can grab your passwords etc.

Anyone else had it and know how to clobber it.

I've tried Trend but their solution didn't work.

Tony

LNeumann · Jun 08, 2004 04:48 PM

#2 source
I have got Norton and Spybot-Search and Destroy on my computer. The first stops viruses, the second stops spyware. And they both update to keep up with the latest "trends".
Load 'em, fire 'em up, get rid of your trash.

Eggbert · Jun 08, 2004 08:38 PM

#5 source
>I have got Norton and Spybot-Search and Destroy on my
>computer. The first stops viruses, the second stops spyware.
>And they both update to keep up with the latest "trends".
>Load 'em, fire 'em up, get rid of your trash.

Add Zonealarm firewall(to what Len has already said. It's free and doesn't let anything access your computer unless you give your permission.

Kiwi · Jun 08, 2004 05:30 PM

edited#3 source
The below broadside is because a great deal of trouble these days is caused by software that loads itself without permission, but for purposes other than damaging your computer. The damage occurs incidentally.
+ from an Annoyances thread +

"re: xp problems maybe virus?
Tuesday, June 8, 2004 at 4:53 am
Windows XP Annoyances Discussion Forum
Posted by Otter (2132 messages posted)

Perform the following:

(Note: Do this offline, with no browser active, after you empty your temporary internets file cache, your history, delete anything in the TEMP folder, and empty your recycle bin.)

1. Disable System Restore (if you use WinME, Win2K, or WinXP)
2. Perform an online virus scan.
3. Download, update, and run these tools:
* Spybot Search & Destroy
* Lavasoft Adaware
* CWShredder
Repeat as necessary until clean.
4. To protect against reinfection, download and use these:
* Javacool's SpywareBlaster
* Javacool's SpywareGuard
* Malware-blocking HOSTS file
5. Optionally Reenable System Restore
6. If you still experience problems after doing these steps, download HijackThis and post a log to this forum.

If you encounter any broken links, please inform me of them. Also note that these links direct through my web server to allow me to keep them up-to-date or post additional info.

The Wereotter"

For virus protection, try AVG fron grisoft.com or Avast from avast.com

.

Kiwi

**

Randy Powell · Jun 08, 2004 07:42 PM

#4 source
Another one is AdAware from Lavasoft. Very good ad and spware killer. But I don't mess with much of this. I use Linux and so far, virus' aren't a problem. Not much chance of it due to the structure of the system. Heck, I operate out of a user account.

Not to say it will never happen. DOS is still a problem.

Randy

Kiwi · Jun 08, 2004 08:42 PM

#6 source
Randy, Tony runs his own public-invited web site; it makes him a target for all kinds of unpleasant fun and games. When I was teaching at the local community college, I regularly had to disinfect all of the floppy disks that I carried back and forth, and all of the work stations in my classrooms, but (knock on wood) none of the incidents was ever close to out of my control, and none of the malicious garbage ever caused damage on any personal systems of my own.

Right now, it seems to me that adware and spyware is the most insidious, pestiferous, plaguelike of annoyances affecting Internet users. I went to Annoyances.Org's web site asking about a confusing item I'd run into with Win2K, and found it to be an excellent resource. That quote is a good example.

.

Kiwi

**

Randy Powell · Jun 10, 2004 11:24 AM

edited#13 source
Kiwi,

Yea, though Linux doesn't suffer from the never ending viruses that Windows users have to put up with, that still leave Denial of Service attacks, port attacks and spyware/adware. I have my browser (FireFox) pretty locked down and that helps. No popups without my expressed permission, No persistent cookies unless I specifically say so, and of course, no registry so no registray hacking. Linux doesn't allow access to certain areas of the file structure unless you have set up specific root access. I don't allow that, so no problem. I try to install most things in either the /home/user directory or in a /usr/local directory so if there were anything malicious, it would be pretty much contained and pretty easy to fix. 8 years of using Linux and I've never had a problem that wasn't easily recoverable from.

It's just less hassle for productivity and internet/communications stuff than Windows...for me anyway. But I still have WinXp Pro installed on a partition (my system is dual boot). I do need a game platform afterall.

elmores · Jun 10, 2004 02:43 AM

#7 source
Thanks for the advice all!

Nothing seems to remove it!

I've tried both Spybot, Adaware and Trend online virus scan.

Now I've installed Zonealarm will this prevent the infector erading the data stored?

Tony

Larry Cunningham · Jun 10, 2004 03:07 AM

#8 source
Tony,

I found out the hard way a couple of years ago with the Klez/W32.. If you don't start up your computer in "protected mode", these tools may not be able to remove a virus. And the damage can extend beyond infected files.

I made the mistake of trying to run the little standalone scrubber program without doing this, and it just kept spreading, as it was supposedly clean. Ultimately, I lost a bunch of data. And even after I got the thing cleaned, the registry remain somehow damaged, and my Norton automatic update never worked right again. I even re-installed the Norton AV, to no avail. NOTHING seemed to get it going properly again.

Ultimately, I just gave up and installed two new big disks on my computer, re-installed all software from the operating system up and effectively started over. With a new Norton AV AND the Personal Firewall, AND keeping the Windows updates up, things have been working since then. (knock wood).

[photo not recovered: 3e69bb3870f12ad5.jpg]

"Never get married in the morning, 'cause you may never know who you'll meet that night." -Paul Hornung

Iskandar Taib · Jun 10, 2004 04:40 AM

#9 source
Here's what it takes to restore a system after it's been compromised:

http://kb.indiana.edu/data/anbp.htm

Linux boxes are vulnerable to a different sort of problem - hackers. For much the same reasons - users/administrators who aren't up on the latest patches, or who otherwise leave their systems vulnerable. If a hacker ever gets root access to your machine, you're probably looking at doing something very similar to recover. Happened to a couple friends at work.

Swordsman18 · Jun 10, 2004 06:26 AM

#11 source
>Here's what it takes to restore a system after it's been
>compromised:
>
>http://kb.indiana.edu/data/anbp.htm
>
>Linux boxes are vulnerable to a different sort of problem -
>hackers. For much the same reasons - users/administrators
>who aren't up on the latest patches, or who otherwise leave
>their systems vulnerable. If a hacker ever gets root access
>to your machine, you're probably looking at doing something
>very similar to recover. Happened to a couple friends at
>work.

This shut down our laboratory for two weeks while we rebuilt our Linux boxes (used for data aqusition) from scratch. Hackers relish UNIX type systems for their little antics. Any sense of security you have running UNIX/Linux boxes is purely an illusion. They are the preferred target of hackers.

Andy

Randy Powell · Jun 10, 2004 11:36 AM

#14 source
Andy,

Yea, they have to have a route in. And you're right: while buffer overflow and such isn't a problem, denying root access can be if you're not up on the file updates or leave you're ports hanging in the wind. Having a router between you and the internet along with a decent firewall setup and a proxy definately helps. I've never had a problem with insuring denial of root access, but there are things that a lot of Linux/Unix users do to make certain operations more convenient, but will definately compromise your ability to deny root access and protect your system.

Any system that is connected to the internet is inherently vunerable regardless of the OS, hardware or system type. But much like a burgler that sees a house with decent security; he will more likely just avoid it and go to the next house without any security. It's just easier. In order to hack into a system, there must be a route. If they routes are denied...

Randy Powell · Jun 10, 2004 11:44 AM

edited#15 source
Isky,

>>users/administrators who aren't up on the latest patches, or who otherwise leave their systems vulnerable.<<

And there's the point. I've had a few friends try Linux, but they ultimately went back to Windows because they didn't like not being able to just delete files or copy files (outside of the home directory) or being able to save stuff anywhere they wanted. One guy hacked his system to allow him general access to the /etc directory and /usr directory and then was unhappy when he deleted a file he thought he didn't need and the display quit working correctly. Unlike Windows, if you operate with root access, Linux won't stop you from doing something stupid.

You pretty much have to pay attention and insure that root access is protected even if it's a bit inconvenient sometimes.

Of course, with Windows, everyone has "root access" all day, all the time. Though getting better, it's not really very secure, even now, without a lot of effort and third party software.

Iskandar Taib · Jun 10, 2004 11:05 PM

#16 source
>Of course, with Windows, everyone has "root access" all day,
>all the time. Though getting better, it's not really very
>secure, even now, without a lot of effort and third party
>software.

Not strictly true, either. If you set up the user accounts properly, ordinary users don't have "root" access. Then again, on a one user desktop machine, few people want the hassle. Same thing with Linux boxes - put one on someone's desktop and they don't want to have to mess with the Unix admin stuff. Not to mention a lot of Linux users aren't Unix admin types.

In a situation with a lot of machines and users, Domain and Active Directory do help a lot when it comes to keeping individual machines secure from the ordinary user, while keeping user database maintenance manageable. I don't think we had any breakins or worms on our several hundred Win2000/NT4 student lab machines when I worked at I.U., the reson being that the machines were set up and administered properly.

Kiwi · Jun 10, 2004 08:40 AM

RE: Virus helpedited#12 source
>I made the mistake of trying to run the little standalone
>scrubber program without doing this, and it just kept
>spreading, as it was supposedly clean.

Which is why, I suppose, that the suggestions from Annoyances.Org said use an externally based anti-virus tool.
>
>Ultimately, I just gave up and installed two new big disks
>on my computer, re-installed all software from the operating
>system up and effectively started over. With a new Norton AV
>AND the Personal Firewall, AND keeping the Windows updates
>up, things have been working since then. (knock wood).
>
Hmmm? Weren't there URL's included in that quote I offered to Tony for the sites that offered an external virus scan? No, looking at the way WereOtter wrote his reply, that part was omitted. I suppose, for those of our readers really illiterate about their PC's, I should perform a public service and find one of the ones to edit into this message!

(A couple of minutes later, after finding a long list of sites, and grabbing the URL's for two, plus a maybe, I'm back.)

http://us.mcafee.com/root/mfs/default.asp

http://www.pandasoftware.com/activescan/com/activescan_principal.htm

http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

That last one is the "maybe"; it doesn't sound as useful as the other two!

.

Kiwi

**

elmores · Jun 10, 2004 05:11 AM

edited#10 source
All cleared up!

That firewall is marvellous for the money (eg free).

Another piece of good stuff is Zonelog analyser!

Tony

Bob Cooke · Jun 11, 2004 02:49 AM

#17 source
Before leaving Silicon Valley I asked a proffessional to install what he thought may be best for Windows XP Home Edition.
Here's his recommendations that I am still using:

Symantec Norton Antivirus Professional Edition. Pay the $25 per year to keep this going.
Set it to update automatically upon startup and every 4 hours online.

Install a hardware Router/Firewall. I am using Lynksys Model BEFSX41
Read about this at www.lynksys.com

Black Ice Protection from www.iss.net Free download

System Mechanic from www.iolo.com Free download

www.pestpatrol.com Most of you already seem to have this

Spybot Search & Destroy obtainable free download from
www.safer-networking.org/index.php?page=home

Run the updates on these at least once a week
Clear: cookies, files & history after each day
Run Disk Defragmenter once a week
Clear all shortcuts from the Desktop except Norton Protected Recycle Bin
Set Windows Update to notify you when new updates are available and go to the Microsoft website to download the ones you want. Doing this kept the recent virus/worms from getting into my system.

I found all the above to be overwhelming when first set up. Now that I have been keeping all this going properly a little more than two years I no longer have the problems encountered in the past.


Randy Powell · Jun 11, 2004 09:53 AM

#18 source
Bob,

This is a very good point. Whatever system you use, you have to stay on top of it. If you don't want to do that or don't have the time or whatever, set it up to do it automatically. My home network is set up so that my son's WinXP Pro machine and my wife's WinXP Home laptop are behind my linux box which is behind a proxy which is behind a router with decent firewalls. Both of the Win boxes have McAfee, AdAware and are set for automatic updates of these and Windows Update. I haven't had a virus problem in a long time.