ianr Posted March 30, 2016 Share Posted March 30, 2016 Here's a very short and clear officialish forum thread concurring in the belief that it's a false positive. http://answers.microsoft.com/en-us/protect/forum/mse-protect_scanning/microsoft-essentials-shows-trojan-dropper-on-dell/2134f8e4-9b89-406c-a672-2f94bc6f7dc4I can see why MSE isn't putting a 3.5GB file into its quarantine folder. Embedded within that is one small file, uninst.exe, for uninstalling the AOL Connectivity Service (ACS), that triggered the alarm. Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980208 Share on other sites More sharing options...
Sue Posted March 30, 2016 Author Share Posted March 30, 2016 Loz Wrote:-------------------------------------------------------> > Can you actually see your D drive from explorer? > On my Dell, I can only see the C drive and the E> drive (my dvd drive). The recovery partition is> not actually mounted, so it's not accessible (and> therefore my AV doesn't scan it). > Yes I can see the D drive. Never actually looked at it very closely before :) or indeed at all :)I think ianr may be right.Though I have no idea what the AOL Connectivity Service is.I still have two AOL email accounts which I occasionally check, but I haven't used AOL as a browser for some years. Do I still need ACS or could I just uninstall it and then delete the uninst.exe file?Also, given that the PC status is now showing as protected, am I OK or not? Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980228 Share on other sites More sharing options...
Loz Posted March 30, 2016 Share Posted March 30, 2016 As I said, Sue, that partition is just to reinstall the operating system. You can't delete an individual file from it, as it's all packaged up into one big file.And deleting the corresponding file from the C drive would almost certainly cause other issues, and not solve this one. Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980275 Share on other sites More sharing options...
Twoddle Posted March 31, 2016 Share Posted March 31, 2016 Latest version of CCleaner has some startup items management. You can research the items and disable/delete them if they look suspicious. 'Experts' will use tools like Autoruns in the Sysinternals Suite or do a scan with Malwarebytes.A common way you get these things in the first place is from visiting bootleg websites eg. live sports channels, that trick you into installing a 'required plugin' which of course is infected with said trojan. Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980319 Share on other sites More sharing options...
DulwichFox Posted March 31, 2016 Share Posted March 31, 2016 Twoddle Wrote:-------------------------------------------------------> Latest version of CCleaner has some startup items> management. You can research the items and> disable/delete them if they look suspicious.> 'Experts' will use tools like Autoruns in the> Sysinternals Suite or do a scan with> Malwarebytes.> A common way you get these things in the first place is from visiting bootleg websites eg. live sports channels, that trick you into installing a 'required plugin' which of course is infected with said trojan.This is very true... Watch Live Football for FREE is a classic example...DulwichFox Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980324 Share on other sites More sharing options...
Sue Posted March 31, 2016 Author Share Posted March 31, 2016 OK sorry Loz, I think I'm confusing two different things.And I can assure you that I haven't visited any iffy websites, Fox :)) Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980327 Share on other sites More sharing options...
Help-Ma-Boab Posted March 31, 2016 Share Posted March 31, 2016 And here was me thinking as TrojanDropper was a condom. Live and learn suppose. Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980356 Share on other sites More sharing options...
pipsky2008 Posted April 1, 2016 Share Posted April 1, 2016 Apologies for going off thread slightlyWhat are views about AVG free for online banking / purchasing ?Someone advised me not to use internet explorer at all for this kind of usage but to use Google Chrome for windows 7Thanks for your thoughts Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980971 Share on other sites More sharing options...
Loz Posted April 1, 2016 Share Posted April 1, 2016 AVG is not the worst AV out there - I just find it a bit naggy, as it keeps pestering you to buy the non-free version. That was the big reason I switched to MSE.Not sure what you mean by for 'online banking / purchasing'. An AV (should) protect you at all times.Ditto with browsers - I don't think any of them is better/worse in terms of security. I use Firefox as a rule, but often switch to Chrome simply because I don't have any add-ons there, which can seriously reduce your security. The big one is not to let your browser store any login/passwords for anything you want to keep secure. It's a trivial job to see them. Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980975 Share on other sites More sharing options...
pipsky2008 Posted April 1, 2016 Share Posted April 1, 2016 Loz Wrote:-------------------------------------------------------> AVG is not the worst AV out there - I just find it> a bit naggy, as it keeps pestering you to buy the> non-free version. That was the big reason I> switched to MSE.I does pop up and pester, I agree, but would, on balance, prefer to be pestered by something that worked than something that didn't.Thank you for mentioning MSE, I hadn't previously heard of it but will look into it.> > Not sure what you mean by for 'online banking /> purchasing'. An AV (should) protect you at all timesBy online banking I mean giving passwords, answering security questions, where there are bogus websites that say they are rated as 'official' when amending standing orders or setting up direct debits or merely sighning in to check an account balenceby purchasing I mean buying on ebay or amazon etc> > > Ditto with browsers - I don't think any of them is> better/worse in terms of security. I use Firefox> as a rule, but often switch to Chrome simply> because I don't have any add-ons there, which can> seriously reduce your security. The big one is> not to let your browser store any login/passwords> for anything you want to keep secure. It's a> trivial job to see them.I never let a browser store my password even for an email address password, however for some sites, even my bank, my browser doesn't automatically ask me, as does yahoo for example when signing into email. I am awaiting a written response from my bank regarding this.Thank you for your reply Loz Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980982 Share on other sites More sharing options...
Loz Posted April 1, 2016 Share Posted April 1, 2016 pipsky2008 Wrote:-------------------------------------------------------> Thank you for mentioning MSE, I hadn't previously heard of it but will look into it. MSE is Microsoft Security Essentials, their version of antivirus. Normally I shy away from MS stuff like this, but MSE is pretty damn good and ties in quite nicely with the Windows Firewall. And it's free.> > Not sure what you mean by for 'online banking / purchasing'. An AV (should) protect you at all> > times> > By online banking I mean giving passwords, answering security questions, where there are> bogus websites that say they are rated as 'official' when amending standing orders or> setting up direct debits or merely sighning in to check an account balenceAh. Whilst some AV's can help, that's not really what they do. The usual advice is NEVER go somewhere like that via clicking on an email or similar. Keep the links in your bookmarks. Personally, I use KeePass, which allows me to store and use a known URL/link to my banking/ebay/paypal/etc.Malware can, however, redirect even a real URL to a bad site. That's where AV usually should help. If in doubt, check the security certificate. When you are on the banking site, the URL should start with 'https://' If it doesn't, get out of there. If it does, you should be able to click on the padlock to the left of there and the security certificate details should come up. The Common Name on the certificate should be the expected URL.Although I don't use it myself, I understand the Trusteer Rapport software that most banks offer to you helps weed out such things.> I never let a browser store my password even for an email address password, however for some > sites, even my bank, my browser doesn't automatically ask me, as does yahoo for example when signing into email. That sounds like something's wrong. I have never encountered that. You can go into the browser's password area and delete them. Link to comment https://www.eastdulwichforum.co.uk/topic/100067-advice-on-trojandropper-removal/page/2/#findComment-980984 Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now