# It finally happened--My computer downloaded a Trojan

**URL:** <https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205>\
**Category:** Factual Questions\
**Created:** [July 26, 2007, 9:16am UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205 "2007-07-26T09:16:51Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Frylock](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Frylock](https://boards.straightdope.com/u/Frylock)\
**Post date:** [July 26, 2007, 9:16am UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/1 "2007-07-26T09:16:51Z")

</div>

WinAntiSpyware 2007 was the name of the thing. I found a link on Wikipedia to a program designed specifically to remove it. After investigating further, I determined this anti-WinAntiSpyware program was legit, and I downloaded and ran it, and the trojan itself seems to have been removed.

But it left behind a bunch of stuff. I keep getting IExplorer popups, and it even places icons (shortcuts to webpages) on my desktop every now and then!

In my task manager I find the following processes which I do not recognize:

retadpu77  
winpop  
was7mon (which is associated with WinAntiSpyware so looks like that’s not been completely removed at all.)  
hyrojtaA (which I can not find mention of online).

I looked up retadpu77 through google, and I see several pages wherein people are asking for advice on how to remove it. In each case, someone asks them to post long lists of registry key entries and so forth, then gives the person highly individualized advice as to how to remove the thing from their particular system.

My question is, is there any quite general procedure I can use to get rid of it? Or is it actually necessary, after all, for me to download something called “Hijack This” and have it spit out a long document, let a techie read it, then download something called “combofix,” (this is what I see on each of the websites wherein I’ve found advice so far), show _it’s_ list to a tech-type person, then go through and delete specific entries, and so on and so on?

If so, then, um, does anyone here want to help me? ☹

-FrL-

---

<div class="post-metadata">

**Author:** ![Frylock](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Frylock](https://boards.straightdope.com/u/Frylock)\
**Post date:** [July 26, 2007, 9:27am UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/2 "2007-07-26T09:27:32Z")

</div>

Oops, there’s more:

mpdsregp  
webbuying  
arpa

These also show up in my task manager and are bad. Geez, maybe these have been there for a while and I just never noticed. I confess to some laxity over the past year or so when it comes to my system’s security.

Dammit.

-FrL-

---

<div class="post-metadata">

**Author:** ![yojimbo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/yojimbo/32/232_2.png) [@yojimbo](https://boards.straightdope.com/u/yojimbo)\
**Post date:** [July 26, 2007, 10:02am UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/3 "2007-07-26T10:02:22Z")

</div>

Here’s a pretty good walkthrough of the steps you should take.

> **[Read & Run Me First Malware Removal Guide (incl. Spyware, Virus, Trojan,...](https://forums.majorgeeks.com/index.php?threads%2F35407%2F)**
>
> See new READ ME PROCESS dated 12-10-16 below or above depending on how you chose to display threads ( oldest first or newest first ).

---

<div class="post-metadata">

**Author:** ![N9IWP](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/n9iwp/32/3154_2.png) [@N9IWP](https://boards.straightdope.com/u/N9IWP)\
**Post date:** [July 26, 2007, 1:23pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/4 "2007-07-26T13:23:06Z")

</div>

I just had a similar issue. I used Norton. I uses Spambot Search & Destroy. I used VundoFix. All found stuff and said they fixed it. But the next day the problem ruturned. But ComboFix seems to have solved my problem.

Brian

---

<div class="post-metadata">

**Author:** ![WreckingCrew](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wreckingcrew/32/4080_2.png) [@WreckingCrew](https://boards.straightdope.com/u/WreckingCrew)\
**Post date:** [July 26, 2007, 2:37pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/5 "2007-07-26T14:37:53Z")

</div>

I got hit by this little bugger few weeks ago. It is an insidious bastard - pop ups all over the place, and constantly trying to download other programs. I went to [http://www.pchell.com](http://www.pchell.com) to find some advice, and went through their multi-step process which seemed to make sense and were easy enough for the most part. The hijack this thing really requires letting a techie look at if if you aren’t familiar with what are the good programs on your computer.

In the end my computer was over three years old, so after a few attempts I said screw it and went out and got a new one. Now, if you would like to hear my review of Vista, I’ll be glad to share.

---

<div class="post-metadata">

**Author:** ![Iggins](https://avatars.discourse-cdn.com/v4/letter/i/b9e5f3/32.png) [@Iggins](https://boards.straightdope.com/u/Iggins)\
**Post date:** [July 26, 2007, 3:21pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/6 "2007-07-26T15:21:41Z")

</div>

I just spent 10 hours trying to remove a trojan from a friend’s computer. What a major clusterf\*&k! I finally managed to remove the trojan, but it managed to corrupt EXPLORER.EXE - I could get to windows, but there was no desktop/start menu/etc. I could get to Task Manager and run applications, but it was basically borked.

A reinstall of SP2 and a repair install of XP didn’t fix EXPLORER. It needed a complete re-install.

People who write trojans are a special kind of jerk.

---

<div class="post-metadata">

**Author:** ![ChrisBooth12](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@ChrisBooth12](https://boards.straightdope.com/u/ChrisBooth12)\
**Post date:** [July 26, 2007, 3:29pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/7 "2007-07-26T15:29:18Z")

</div>

A slight piece of advice but never ever use anything Norton…ever

---

<div class="post-metadata">

**Author:** ![Frylock](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Frylock](https://boards.straightdope.com/u/Frylock)\
**Post date:** [July 26, 2007, 3:57pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/8 "2007-07-26T15:57:34Z")

</div>

[QUOTE=N9IWP]  
I just had a similar issue. I used Norton. I uses Spambot Search & Destroy. I used VundoFix. All found stuff and said they fixed it. But the next day the problem ruturned. But ComboFix seems to have solved my problem.

Brian  
[/QUOTE]

I ran combofix just now. It gave me a log file telling me what it had found, but I can’t tell whether it actually _did_ anything.

I think the problem seems better, but I did just get a pop-up. There don’t _seem_ to be as many though.

-FrL-

W/ apologies, FTR, here’s the log file:

“Jessica” - 2007-07-26 8:18:51 [GMT -7:00] - ComboFix 07-07-24 - Service Pack 2 NTFS  
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))  
C:\WINDOWS\system32\wvuutuu.dll

- 
  - 
    - POST RUN FILES/FOLDERS \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \* \*  
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))  
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\salesmonitor  
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007  
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\Abbr  
C:\DOCUME~1\ALLUSE~1\APPLIC~1.\winantispyware 2007\Data\ProductCode  
C:\Documents and Settings\All Users.\documents\setup.exe  
C:\Program Files\Common Files\winantispyware 2007  
C:\Program Files\Common Files\winantispyware 2007\err.log  
C:\Program Files\Common Files\winantispyware 2007\uwas7cw.exe  
C:\Program Files\Messenger ecodol83122.dll  
C:\Program Files\outerinfo  
C:\Program Files\outerinfo\Terms.rtf  
C:\Program Files\poolsv  
C:\Program Files\poolsv\k11u72.exe  
C:\Program Files\poolsv\svhost.exe  
C:\Program Files\poolsv\WinAntiSpyware2007FreeInstall.exe  
C:\Program Files\poolsv\wr-1-0000077.exe  
C:\Program Files\poolsv\YazzleBundle-1549.exe  
C:\Program Files\svhost  
C:\Program Files\svhost\wr-1-0000077.exe  
C: emp n3  
C:\WINDOWS\b122.exe  
C:\WINDOWS\dls0523pmw.exe  
C:\WINDOWS\poolsv.exe  
C:\WINDOWS\rau001978.exe  
C:\WINDOWS\retadpu77.exe  
C:\WINDOWS\setup.exe  
C:\WINDOWS\svhost.exe  
C:\WINDOWS\system32\b10FdUe  
C:\WINDOWS\system32\b10FdUe\b10FdUe1099.exe  
C:\WINDOWS\system32\drivers\core.cache.dsk  
C:\WINDOWS\system32\drivers\core.sys  
C:\WINDOWS\system32\drivers\fopn.sys  
C:\WINDOWS\system32\ecurit~1  
C:\WINDOWS\system32\ecurit~1\r?ndll32.exe  
C:\WINDOWS\system32\G1  
C:\WINDOWS\system32\G1\kmhp83122.exe  
C:\WINDOWS\system32\G11  
C:\WINDOWS\system32\G11\z553.exe  
C:\WINDOWS\system32\G3  
C:\WINDOWS\system32\G3\wr725.exe  
C:\WINDOWS\system32\G5  
C:\WINDOWS\system32\G5 ns2.exe  
C:\WINDOWS\system32\G7  
C:\WINDOWS\system32\G9  
C:\WINDOWS\system32\rqaql.dll  
C:\WINDOWS\system32\win  
C:\WINDOWS\system32\wtsicomsv.exe  
C:\WINDOWS\TISKY009.exe  
C:\WINDOWS\wr.txt  
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))  
-------\LEGACY\_CORE  
-------\LEGACY\_FOPN  
-------\LEGACY\_NET\_AGENT  
-------\LEGACY\_WINDOWS\_OVERLAY\_COMPONENTS  
-------\core  
-------\Net Agent  
((((((((((((((((((((((((( Files Created from 2007-06-26 to 2007-07-26 )))))))))))))))))))))))))))))))  
2007-07-26 08:15 51,200 --a------ C:\WINDOWS  
ircmd.exe  
2007-07-26 01:05 \<DIR\> d-------- C:\Program Files\SSRemoval Tool  
2007-07-26 00:23 6,467 —hs---- C:\WINDOWS\system32\edeeg.bak1  
2007-07-26 00:22 228,960 --a------ C:\WINDOWS\system32\geede.dll  
2007-07-26 00:17 626,352 -r-hs---- C:\WINDOWS\hyrojtaA.exe  
2007-07-26 00:17 54,784 --a------ C:\WINDOWS\hyrojta.exe  
2007-07-26 00:17 171,520 --a------ C:\WINDOWS\system32\lkwicmj.dll  
2007-07-26 00:16 31,254 --a------ C:\WINDOWS\system32\fccyvvv.dll  
2007-07-26 00:16 \<DIR\> d-------- C:\Temp\brr  
2007-07-26 00:16 \<DIR\> d-------- C:\Temp\0c2  
2007-07-26 00:16 \<DIR\> d-------- C:\Temp  
2007-06-29 10:49 \<DIR\> d-------- C:\DOCUME~1\Jacob\APPLIC~1\Yahoo! Messenger  
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-26 15:36:28 -------- d-----w C:\Program Files\Messenger  
2007-07-26 15:10:31 -------- d-----w C:\Program Files\MSN Gaming Zone  
2007-07-16 22:29:31 -------- d-----w C:\Program Files\Yahoo!  
2007-07-16 22:23:37 -------- d-----w C:\Program Files\ICQ  
2007-07-16 22:20:33 -------- d-----w C:\Program Files\SlideShow  
2007-06-01 18:10:10 -------- d-----w C:\Program Files\America Online 7.0  
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll  
2006-05-29 18:10:22 70,736 ----a-w C:\DOCUME~1\Jessica\APPLIC~1\GDIPFONTCACHEV1.DAT  
2006-05-18 02:06:17 524,300 ----a-w C:\DOCUME~1\Jessica\APPLIC~1\position.bin  
2006-05-16 03:31:16 774,144 ----a-w C:\Program Files\RngInterstitial.dll  
2006-04-24 00:07:40 585,728 ----a-w C:\DOCUME~1\Jessica\APPLIC~1\arasan.exe  
2006-04-23 01:22:56 999,424 ----a-w C:\DOCUME~1\Jessica\APPLIC~1\arasanx.exe  
2006-04-18 02:49:42 1,179,648 ----a-w C:\DOCUME~1\Jessica\APPLIC~1\book.bin  
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

_Note_ empty entries & legit default entries are not shown

[HKEY\_LOCAL\_MACHINE~\Browser Helper Objects{3964D8D6-86D0-493A-B460-A805B5401114}]  
2007-07-26 00:16 31254 --a------ C:\WINDOWS\system32\fccyvvv.dll

[HKEY\_LOCAL\_MACHINE~\Browser Helper Objects{b8f25cdd-bbc2-4a5d-8cc9-bc886aff5012}]  
2007-07-26 00:17 171520 --a------ C:\WINDOWS\system32\lkwicmj.dll

[HKEY\_LOCAL\_MACHINE~\Browser Helper Objects{BF79CAEE-5A1C-4877-A482-2E249B08CB4C}]  
2007-07-26 00:22 228960 --a------ C:\WINDOWS\system32\geede.dll

[HKEY\_LOCAL\_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]  
“TkBellExe”=“C:\Program Files\Common Files\Real\Update\_OB\realsched.exe” [2004-07-31 10:07]  
“iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [2006-02-08 15:03]  
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2006-02-23 17:06]  
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.5.0\_10\bin\jusched.exe” [2006-11-09 16:07]  
“nwiz”=“nwiz.exe” [2006-08-11 22:43 C:\WINDOWS\system32  
wiz.exe]  
“Adobe Photo Downloader”=“C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe” [2007-03-09 11:09]  
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader\_sl.exe” [2007-05-11 03:06]

[HKEY\_CURRENT\_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]  
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 09:24]  
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-04 00:56]  
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-07-25 01:27]  
“updateMgr”=“C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe”

[HKEY\_USERS.default\software\microsoft\windows\currentversion\runonce]  
“RunNarrator”=Narrator.exe

C:\Documents and Settings\Jessica\Start Menu\Programs\Startup  
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50]  
Clean Access Agent.lnk - C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe [2007-05-09 16:54:38]  
Picaboo.lnk - C:\Program Files\Picaboo\Picaboo\PicabooMain.exe [2005-05-16 15:38:42]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup  
Clean Access Agent.lnk - C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe [2007-05-09 16:54:38]  
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY\_LOCAL\_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]  
“{3964D8D6-86D0-493A-B460-A805B5401114}”= C:\WINDOWS\system32\fccyvvv.dll [2007-07-26 00:16 31254]

[HKEY\_LOCAL\_MACHINE\software\microsoft\windows nt\currentversion\winlogon  
otify\fccyvvv]  
fccyvvv.dll 2007-07-26 00:16 31254 C:\WINDOWS\system32\fccyvvv.dll

[HKEY\_LOCAL\_MACHINE\software\microsoft\windows nt\currentversion\winlogon  
otify\geede]  
C:\WINDOWS\system32\geede.dll 2007-07-26 00:22 228960 C:\WINDOWS\system32\geede.dll

[HKEY\_LOCAL\_MACHINE\software\microsoft\windows nt\currentversion\winlogon  
otify\MCPClient]  
C:\Program Files\Common Files\Stardock\mcpstub.dll 2003-08-25 10:25 139264 C:\Program Files\Common Files\Stardock\MCPStub.dll

[HKEY\_LOCAL\_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]  
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk  
backup=C:\WINDOWS\pss\BigFix.lnkCommon Startup

[HKEY\_LOCAL\_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]  
“C:\Program Files\Messenger\msmsgs.exe” /background

[HKEY\_LOCAL\_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]  
C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

[HKEY\_LOCAL\_MACHINE\software\microsoft\shared tools\msconfig\startupreg\susp]  
C:\WINDOWS\susp.exe

[HKEY\_LOCAL\_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVTMD]  
C:\WINDOWS\TVTMD.exe

[HKEY\_LOCAL\_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebSavingsfromEbates]  
wjview /cp:p “C:\Program Files\WebSavingsfromEbates\System\Code” Main lp: “C:\Program Files\WebSavingsfromEbates”

R1 Kbdclass;Keyboard Class Driver;C:\WINDOWS\system32\DRIVERS\kbdclass.sys  
R1 Mouclass;Mouse Class Driver;C:\WINDOWS\system32\DRIVERS\mouclass.sys  
R1 SSHDRV85;SSHDRV85;??\C:\WINDOWS\system32\drivers\SSHDRV85.sys  
R1 VIAPFD;VIAPFD;C:\WINDOWS\system32\Drivers\VIAPFD.SYS  
R2 IOPort;IOPort;??\C:\WINDOWS\System32\DRIVERS\IOPORT.SYS  
R2 TBPanel;TBPanel;C:\WINDOWS\system32\drivers\TBPanel.sys  
R3 Gpc;Generic Packet Classifier;C:\WINDOWS\system32\DRIVERS\msgpc.sys  
R3 wanatw;WAN Miniport (ATW);C:\WINDOWS\system32\DRIVERS\wanatw4.sys  
S3 Cardex;Cardex;??\C:\WINDOWS\system32\drivers\TBPANEL.SYS  
S3 gUSBSTOi;gUSBSTOi;??\C:\DOCUME~1\Kris\LOCALS~1\Temp\gUSBSTOi.sys  
S3 HidUsb;Microsoft HID Class Driver;C:\WINDOWS\system32\DRIVERS\hidusb.sys  
S3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys

* * *

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [http://www.gmer.net](http://www.gmer.net)  
Rootkit scan 2007-07-26 08:45:18  
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden registry entries …

[HKEY\_LOCAL\_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]  
“TracesProcessed”=dword:000001ee

scanning hidden files …

scan completed successfully  
hidden files: 0

* * *

Completion time: 2007-07-26 8:51:26 - machine was rebooted  
C:\ComboFix-quarantined-files.txt … 2007-07-26 08:51

```
--- E O F ---

```

---

<div class="post-metadata">

**Author:** ![Frylock](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Frylock](https://boards.straightdope.com/u/Frylock)\
**Post date:** [July 26, 2007, 4:25pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/9 "2007-07-26T16:25:04Z")

</div>

FYI

Combofix seems indeed to have almost fixed it. The only problem left is a very occasional pop up (“brought to you by WebBuying”) while I am running internet explorer. I’ll find a way to fix this when I come back home from work tonight.

-Kris

---

<div class="post-metadata">

**Author:** ![MrSquishy](https://avatars.discourse-cdn.com/v4/letter/m/b9e5f3/32.png) [@MrSquishy](https://boards.straightdope.com/u/MrSquishy)\
**Post date:** [July 26, 2007, 6:25pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/10 "2007-07-26T18:25:03Z")

</div>

Probably too late for this advice, but did you try reverting to a recent system restore point? That always worked for me anytime I screwed up my Windows machine.

Also, your **computer** downloaded a trojan? :dubious: 😉

---

<div class="post-metadata">

**Author:** ![Frylock](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Frylock](https://boards.straightdope.com/u/Frylock)\
**Post date:** [July 26, 2007, 6:32pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/11 "2007-07-26T18:32:56Z")

</div>

[QUOTE=MrSquishy]  
Probably too late for this advice, but did you try reverting to a recent system restore point? That always worked for me anytime I screwed up my Windows machine.

[/quote]

I wasn’t sure how that works. Wouldn’t it just have “restored” me to the point right after the malware had been installed? I didn’t know, and so decided to try other means.

> [@](#):
>
> Also, your **computer** downloaded a trojan? :dubious: 😉

😕 I don’t get it.

-FrL-

---

<div class="post-metadata">

**Author:** ![Strinka](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/strinka/32/512_2.png) [@Strinka](https://boards.straightdope.com/u/Strinka)\
**Post date:** [July 26, 2007, 8:53pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/12 "2007-07-26T20:53:28Z")

</div>

[QUOTE=Frylock]  
😕 I don’t get it.

-FrL-  
[/QUOTE]

Your computer isn’t going to spontaneously download something, so **you** downloaded it.

---

<div class="post-metadata">

**Author:** ![sturmhauke](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@sturmhauke](https://boards.straightdope.com/u/sturmhauke)\
**Post date:** [July 26, 2007, 8:57pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/13 "2007-07-26T20:57:10Z")

</div>

[QUOTE=Strinka]  
Your computer isn’t going to spontaneously download something, so **you** downloaded it.  
[/QUOTE]

Incorrect. If you go to some websites and you have inadequate security software, they can push malicious scripts onto your machine.

---

<div class="post-metadata">

**Author:** ![ChrisBooth12](https://avatars.discourse-cdn.com/v4/letter/c/e95f7d/32.png) [@ChrisBooth12](https://boards.straightdope.com/u/ChrisBooth12)\
**Post date:** [July 26, 2007, 8:58pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/14 "2007-07-26T20:58:34Z")

</div>

Nope, computers dont do anything they are not told to do. He downloaded it, indreictly but still it was him

---

<div class="post-metadata">

**Author:** ![drachillix](https://avatars.discourse-cdn.com/v4/letter/d/48db29/32.png) [@drachillix](https://boards.straightdope.com/u/drachillix)\
**Post date:** [July 26, 2007, 9:38pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/15 "2007-07-26T21:38:10Z")

</div>

[QUOTE=Iggins]  
I just spent 10 hours trying to remove a trojan from a friend’s computer. What a major clusterf\*&k! I finally managed to remove the trojan, but it managed to corrupt EXPLORER.EXE - I could get to windows, but there was no desktop/start menu/etc. I could get to Task Manager and run applications, but it was basically borked.

A reinstall of SP2 and a repair install of XP didn’t fix EXPLORER. It needed a complete re-install.

People who write trojans are a special kind of jerk.  
[/QUOTE]

This has been fairly common in the last few weeks (I run a pc repair shop). Clean reloads are the easy way to go so far AFAIK.

Generally our approach is

superantispyware  
AVG  
rogueremover  
avast  
windows antispyware  
trojan hunter

If those don’t get it, backup personal files and reload from scratch.

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [July 26, 2007, 10:10pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/16 "2007-07-26T22:10:28Z")

</div>

[QUOTE=ChrisBooth12]  
Nope, computers dont do anything they are not told to do. He downloaded it, indreictly but still it was him  
[/QUOTE]  
A website exploiting a bug in IE told the computer to download the trojan. Or perhaps it was an unsecured port and an external attacker used it to cause the computer to accept the trojan in both of those the home operator cannot have been said to have downloaded the trojan.

---

<div class="post-metadata">

**Author:** ![MrSquishy](https://avatars.discourse-cdn.com/v4/letter/m/b9e5f3/32.png) [@MrSquishy](https://boards.straightdope.com/u/MrSquishy)\
**Post date:** [July 26, 2007, 10:34pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/17 "2007-07-26T22:34:25Z")

</div>

[QUOTE=gazpacho]  
A website exploiting a bug in IE told the computer to download the trojan. Or perhaps it was an unsecured port and an external attacker used it to cause the computer to accept the trojan in both of those the home operator cannot have been said to have downloaded the trojan.  
[/QUOTE]  
True, but how often do either of those things happen? In real life, I mean, not security mailing list stories. Compared to the number of trojans that **are** actually downloaded and installed carelessly by users.

I was just poking a bit of fun, though. I wasn’t sure which combination of smileys to use to make that clear. I guess my “dubious wink” didn’t work. I didn’t mean any offense.

A System Restore will restore your system at the point the restore was created. So, you’d want to restore to one that was created before your computer (;)) installed the trojan. Often, a restore point is created right before you install anything, so if you have a restore point from that day, it may very well have been the one you want.

At any rate, all’s well that ends well.  
ETA: I like the Google ad. Is that because we keep saying “trojan”?

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [July 26, 2007, 11:03pm UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/18 "2007-07-26T23:03:15Z")

</div>

There are tons of articles online about how an unpatched windows XP computer will get something loaded onto it within 15 minutes of being connected to the internet so I would say it happens a lot.

---

<div class="post-metadata">

**Author:** ![Tim\_T-Bonham.net](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@Tim\_T-Bonham.net](https://boards.straightdope.com/u/Tim_T-Bonham.net)\
**Post date:** [July 27, 2007, 6:20am UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/19 "2007-07-27T06:20:40Z")

</div>

[QUOTE=Frylock]  
The only problem left is a very occasional pop up (“brought to you by WebBuying”) while I am running internet explorer. I’ll find a way to fix this when I come back home from work tonight.  
[/QUOTE]  
I would suggest the best way to fix that is to STOP “running internet explorer”. Download FireFox and run it instead. You will almost never see popups.

---

<div class="post-metadata">

**Author:** ![Frylock](https://avatars.discourse-cdn.com/v4/letter/f/ce7236/32.png) [@Frylock](https://boards.straightdope.com/u/Frylock)\
**Post date:** [July 27, 2007, 6:50am UTC](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205/20 "2007-07-27T06:50:56Z")

</div>

[QUOTE=t-bonham@scc.net]  
I would suggest the best way to fix that is to STOP “running internet explorer”. Download FireFox and run it instead. You will almost never see popups.  
[/QUOTE]

I was wrong. IExplorer popups are showing up no matter what browser I’m using. (And I do already have FireFox btw.)

And FTR, the trojan was picked up while Netscape was running, not iexplorer.

-FrL-

[Next page](https://boards.straightdope.com/t/it-finally-happened-my-computer-downloaded-a-trojan/413205.md?page=2)
