Wednesday, August 12, 2009

Very persistent trojan?

my AVG (antivirus) found it once ,supposed to have removed it, but then i see adsl being again very busy so that i cant even surf, the trojan must still be 'around', how do i fight it?



so far i have done this,



- turn restore off (windows xp)



- restart in safe mode, run antivirus and antispyware



Very persistent trojan?antispyware



Download Wireshark w/ PCap. http://www.wireshark.com



Wireshark is a highly rated Packet Sniffer, it will give you details based on all data packets sent from your networking device. So!!!



This will capture data packets being sent or received from your PC. When you download and install it, I want you to open it. Click on "Capture" from the menu and click on "Options". Then click on the drop down menu for device and make sure you select your Network Card. Not the generic network card. Move to the bottom, leave the settings in between at default. Set the Maximum "Stop Capture" setting to 3 Megabytes. To the right of this, make sure all boxes are checked. Then click on start when activity is going crazy. This will collect data that you want to know, whether or not it's a trojan can be determined there. If it is a trojan, you can use Microsoft Windows Firewall to put a block on that and you won't have anymore traffic interferance. This will prevent communication unless it has it's own backdoor that it opens. In that case, enable the firewall and logon as a Limited User. If it doesn't stop after you put a firewall block on it. This should be a temporary fix until your Anti-Virus/Spyware gives a resolution to your situation.

No comments:

Post a Comment