1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Trojan Small AR

Discussion in 'Malware and Virus Removal Archive' started by Daisy30875, 2003/12/31.

Thread Status:
Not open for further replies.
  1. 2003/12/31
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Ok so i ran this Trend Micro free virus scanner on my computer and it came up with the Trojan Small AR virus was on it so I deleted the file like it told me to do. Ok so that got rid of the virus? No, I'm still having problems with my internet explorer favorites being changed to **** sites and also recieving Rundll error message stating that ctrlpan.dll couldnt start or whatever. I need all the help I can get with removing this virus and all its meyhem. Any and all advice would be great thank you!:confused:
     
  2. 2004/01/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116

  3. to hide this advert.

  4. 2004/01/01
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Daizy - Welcome to the Board :)

    Be sure to update the reference files for Spybot and AdAware before you run them.

    If running those programs, including CWShredder fails to solve your problem your browser may have been hijacked.
    Download HijackThis , run it and post the log here for the experts to view and comment on.

    Moving this thread to Security/Virus/Spyware
     
  5. 2004/01/01
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
  6. 2004/01/01
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Pete C show me the way!

    Hi thank you all for responding so quickly. I downloaded spybot and I'm not sure where to find the reference files that you speak of. Could you please tell me where they are? thanks....again!

    :confused:
     
  7. 2004/01/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Open Spybot
    1. Click on 'Online' in the navigation bar,
    2. Click on 'Update',
    3. Search for available updates,
    AFTER SEARCH IS DONE, A DROP DOWN LIST OF AVAILABLE SERVERS WILL BE SEEN AT THE TOP MENU (1-Search for updates, 2- Download upodates, 3- list of servers)
    4. Select ALL available updates,
    5. Download the selected updates.
     
  8. 2004/01/01
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Broni I'm going crazy

    :mad:

    Ok so I keep attempting to download the updates and spybot stops responding! Is there anyway to fix my Trojan Small AR problem without having to download the updates? Or is there a way I can make spybot download the updates without locking up? This is so annoying.

    Oh one additional question, I need to settle an arguement with my husband. I keep telling him its his fault that we got this darn Trojan thing in the first place. He surfs **** sites and I dont. So, isnt it more likely that we got this problem from **** sites that he visits? I feel like blocking his internet access but that would just cause me more grief, is there anyway we can tell the "safe" sites from the "non-safe" sites?
     
  9. 2004/01/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Daisy
    Spybot's servers has been busy lately, but try a different Spybot server:
    Australia's server worked for me.
    As for:
    Yes. Do you have a firewall? If you don't, you need one.
     
  10. 2004/01/01
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Broni

    :confused:

    Gosh, Im not even sure if I have a firewall. I thought AOL had them automatically integrated into their program. But I know that Microsoft Explorer pops up while he surfs so I'm not sure if that has firewalls or not, so here we go again...How do i find out if I have a firewall, and if I dont have one, how do I get one? I thought I knew a lot about computers, just feeling a little small these days now! LOL

    thanks again!
     
  11. 2004/01/01
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Aleekat

    The write up you suggested I look at is for a different Trojan virus. Is it still recommended that I take the steps outlined on that page? The links listed are the exact links listed in my favorites. I read it yesterday but was afraid to follow the steps because of the different name. Thank you for all your help.
     
  12. 2004/01/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Daisy
    If you don't know, if you have a firewall, and you don't remember insatlling one, probably you don't have it.
    It's better to make sure, however, because it's not recommended to run TWO software firewalls at the same time.
    You need to provide some more info here to find out.
    If you install all your programs to C:\Program Files, post a list of programs you have listed there.
    We can go from there.
    ...and, yes, you have to follow steps from Aleekat link, just to make sure, that trojan is gone.
     
  13. 2004/01/01
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Troj_Small AR is listed here on the Trend website, but it doesn't seem to have the effect you describe - 'DB' fits your problem more closely. Check out the Technical tab on that page - at the bottom is a list of the **** sites which replace favourites. If they look familiar follow the solution given.

    According to
    this the latest version of CWShredder fixes the trojan. Check you have the latest version.

    You will have to delete the **** links manually - see the Trend article.

    Firewall - which OS - if Win XP the native firewall is loaded by default. With Win Me > Win 95 you will need to get one.

    Simplest freeware firewall is ZoneAlarm but many prefer Kerio but it can be a bit tricky to set up.

    Late this side of the pond - will catch up on developments in the morning.
     
  14. 2004/01/01
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Starting to chill out...

    Ok so here is my update, I downloaded Spybot and its updates and ran that. Had the program fix the problem and restarted my computer, ran spybot again like it had recommended I do. I had it fix the problems again, restarted my computer and still had the ctrlpan.dll error. Downloaded Adaware and its updates and ran that, had the program delete and quarentene the problem files--which by my understanding means that they backed up the files in case I deleted something useful. Restarted my computer, ran adaware once more and nothing was found however still had the ctrlpan.dll error upon restart. Downloaded the latest version of CWshredder and ran that had it delete problem files and restarted the computer. Still had the ctrlpan.dll error. Went to Trend Micro and did everything it said to do but was unable to find any of the files or componants that it said to delete in the Regedit. Finally I get frustrated and turn off the computer and come back later. No error, everything seems fine. Whats up with this?

    I have another question, while in the Regedit I found a lot of things that looked like **** sites is it ok to delete these? Im going nuts and its all my husbands fault LMAO pervert!!

    I will now attempt to download Hijack program which was brought up earlier and see what that can do for me. After this I will see about those firewalls, are they free?
    Thanks again all...
     
  15. 2004/01/01
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Program Files

    Here is a list of my program files

    Accessories, Adobe, AIM, AOL 9.0, Aod, Aol Companion, Chat, Common Files, Creative, DirectX, Hewlett Packard, HP DeskJet 930c, HP PhotoSmart, Internet Explorer, InterVideo, Labtech, Lavasoft, Learn2.com, Logitech, Microsoft Encarta, Microsoft Expedia, Microsoft Hardware,Microsoft Home Publishing2000,
    Microsoft Money,Microsoft Office,Microsoft Picture Express,Microsoft works,Microsoft Works Suite,nCASE,Netmeeting
    NetZero,NZSearch, Online Services, Outlook Express, Phone Tools, Plus!, Poison Frog, Real, SGGames, Spybot, Srng, Viewpoint, Webpublish, Windows Media Player, WinZip, Yahoo!


    Now isnt nCASE a bad program?
     
  16. 2004/01/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Daisy
    You've been doing really good, so far.
    Yes, nCASE is an adware.
    Removal instructions HERE
    Now, we'll have to start all over to make sure, you are safe.
    1. I assume, you are not using any antivirus program, running all the time on your computer. Get free AVG
    After installing, run a full scan.
    2. Now, we know, you don't have any firewall. Get free ZoneAlarm
    3. After installing ZoneAlarm, run AVG one more time.
    4. At this time, you should be safe from viruses, trojans, and other garbage.
    5. Make sure, you have all updates for Spybot, Ad-aware, and CWShredder. Run them again.
    6. Post back here, as a happy camper (knock, knock).
     
  17. 2004/01/01
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    You didnt mention, what version of Windows?
     
  18. 2004/01/02
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Now what?

    Ok, I followed the directions to remove nCASE on both the pages they outlined. Now why do I have nCASE still listed in my programs? What a PITA! :mad:
     
  19. 2004/01/02
    Daisy30875

    Daisy30875 Inactive Thread Starter

    Joined:
    2003/12/31
    Messages:
    29
    Likes Received:
    0
    Windows Version

    Sorry I origianally posted my Trojan question in Windows 98 forum so I never did mention the version....so yea I have Windows 98
     
  20. 2004/01/02
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Probably a bad uninstaller which leaves a few traces - right click the entry in Start > Programs > delete - the folder may well be empty and check for any traces in C:\Windows\Program Files and delete those too.

    To get rid of any dubious URLs in the IE Address dropdown list try EDITURLs - freeware - better than ferreting about in the Registry :)
     
  21. 2004/01/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    It may be just an empty folder. Delete it.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.