Jump to content

Recommended Posts

Here's a very short and clear officialish forum thread concurring in the belief that it's a false positive. http://answers.microsoft.com/en-us/protect/forum/mse-protect_scanning/microsoft-essentials-shows-trojan-dropper-on-dell/2134f8e4-9b89-406c-a672-2f94bc6f7dc4


I can see why MSE isn't putting a 3.5GB file into its quarantine folder. Embedded within that is one small file, uninst.exe, for uninstalling the AOL Connectivity Service (ACS), that triggered the alarm.

Loz Wrote:

-------------------------------------------------------

>

> Can you actually see your D drive from explorer?

> On my Dell, I can only see the C drive and the E

> drive (my dvd drive). The recovery partition is

> not actually mounted, so it's not accessible (and

> therefore my AV doesn't scan it).

>



Yes I can see the D drive. Never actually looked at it very closely before :) or indeed at all :)


I think ianr may be right.


Though I have no idea what the AOL Connectivity Service is.


I still have two AOL email accounts which I occasionally check, but I haven't used AOL as a browser for some years. Do I still need ACS or could I just uninstall it and then delete the uninst.exe file?


Also, given that the PC status is now showing as protected, am I OK or not?

As I said, Sue, that partition is just to reinstall the operating system. You can't delete an individual file from it, as it's all packaged up into one big file.


And deleting the corresponding file from the C drive would almost certainly cause other issues, and not solve this one.

Latest version of CCleaner has some startup items management. You can research the items and disable/delete them if they look suspicious. 'Experts' will use tools like Autoruns in the Sysinternals Suite or do a scan with Malwarebytes.


A common way you get these things in the first place is from visiting bootleg websites eg. live sports channels, that trick you into installing a 'required plugin' which of course is infected with said trojan.

Twoddle Wrote:

-------------------------------------------------------

> Latest version of CCleaner has some startup items

> management. You can research the items and

> disable/delete them if they look suspicious.

> 'Experts' will use tools like Autoruns in the

> Sysinternals Suite or do a scan with

> Malwarebytes.

>

A common way you get these things in the first place is from visiting bootleg websites

eg. live sports channels, that trick you into installing a 'required plugin' which of course is infected with said trojan.


This is very true... Watch Live Football for FREE is a classic example...


DulwichFox

AVG is not the worst AV out there - I just find it a bit naggy, as it keeps pestering you to buy the non-free version. That was the big reason I switched to MSE.


Not sure what you mean by for 'online banking / purchasing'. An AV (should) protect you at all times.


Ditto with browsers - I don't think any of them is better/worse in terms of security. I use Firefox as a rule, but often switch to Chrome simply because I don't have any add-ons there, which can seriously reduce your security. The big one is not to let your browser store any login/passwords for anything you want to keep secure. It's a trivial job to see them.

Loz Wrote:

-------------------------------------------------------

> AVG is not the worst AV out there - I just find it

> a bit naggy, as it keeps pestering you to buy the

> non-free version. That was the big reason I

> switched to MSE.


I does pop up and pester, I agree, but would, on balance, prefer to be pestered by something that worked than something that didn't.


Thank you for mentioning MSE, I hadn't previously heard of it but will look into it.

>

> Not sure what you mean by for 'online banking /

> purchasing'. An AV (should) protect you at all times


By online banking I mean giving passwords, answering security questions, where there are bogus websites that say they are rated as 'official' when amending standing orders or setting up direct debits or merely sighning in to check an account balence


by purchasing I mean buying on ebay or amazon etc

>

>

> Ditto with browsers - I don't think any of them is

> better/worse in terms of security. I use Firefox

> as a rule, but often switch to Chrome simply

> because I don't have any add-ons there, which can

> seriously reduce your security. The big one is

> not to let your browser store any login/passwords

> for anything you want to keep secure. It's a

> trivial job to see them.


I never let a browser store my password even for an email address password, however for some sites, even my bank, my browser doesn't automatically ask me, as does yahoo for example when signing into email. I am awaiting a written response from my bank regarding this.


Thank you for your reply Loz

pipsky2008 Wrote:

-------------------------------------------------------

> Thank you for mentioning MSE, I hadn't previously heard of it but will look into it.


MSE is Microsoft Security Essentials, their version of antivirus. Normally I shy away from MS stuff like this, but MSE is pretty damn good and ties in quite nicely with the Windows Firewall. And it's free.


> > Not sure what you mean by for 'online banking / purchasing'. An AV (should) protect you at all

> > times

>

> By online banking I mean giving passwords, answering security questions, where there are

> bogus websites that say they are rated as 'official' when amending standing orders or

> setting up direct debits or merely sighning in to check an account balence


Ah. Whilst some AV's can help, that's not really what they do. The usual advice is NEVER go somewhere like that via clicking on an email or similar. Keep the links in your bookmarks. Personally, I use KeePass, which allows me to store and use a known URL/link to my banking/ebay/paypal/etc.


Malware can, however, redirect even a real URL to a bad site. That's where AV usually should help.


If in doubt, check the security certificate. When you are on the banking site, the URL should start with 'https://' If it doesn't, get out of there. If it does, you should be able to click on the padlock to the left of there and the security certificate details should come up. The Common Name on the certificate should be the expected URL.


Although I don't use it myself, I understand the Trusteer Rapport software that most banks offer to you helps weed out such things.


> I never let a browser store my password even for an email address password, however for some

> sites, even my bank, my browser doesn't automatically ask me, as does yahoo for example when signing into email.


That sounds like something's wrong. I have never encountered that. You can go into the browser's password area and delete them.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Latest Discussions

    • I’m not a Gail’s fan but there’s no reason a business shouldn’t open on Christmas Day. However, nobody should be compelled to work the day which, given the widespread coverage of Gail’s questionable employment practices, has to be a possibility here.  The only business I ever use on the 25th is maybe a pub and that’s a rarity these days but buses running would be very welcome for visiting etc. But the swings in the park should definitely remain chained up. Are parks even open on Christmas Day?
    • To be honest, pal, it's not good being a fan of a local business and then not go there. One on hand, the barber shop literally next door to Romeo Jones started serving coffee. The Crown and Greyhound and Rocca serve coffee. Redemption Coffee opened up not far away, and then also Megan's next door to that. DVillage was serving coffee (but wasn't very popular), as was Au Ciel (which is). Maybe also Heritage Cheese, I don't know. There's also Flotsam and Jetsam doing coffee and sandwiches at Dulwich Picture Gallery in the other direction. The whole of Dulwich Village serves coffee. And yet on the other hand, there are enough punters to support all good coffee shops. With the exception of Rocca and Megan's (which are both big spaces) and C&G (which does coffee like everything else - slow and with bad service), all these places regularly get queues out the door. Gail's often has big queues and yet very few people crossed the street to Romeo Jones (which was much better)... Half the staff at Gail's are perfectly fine and efficient. The other half are pretty offhand and rude. It's certainly not welcoming or friendly service. But they're certainly hard working, and no doubt raking the money in for Luke Johnson...
    • Well according to a newspaper article, Gail’s is opening 10 shops in London,,, yup Dulwich is named 10/5 I seem to recall with others in London opening at 7 am…!, Guess that is to capture workers coming off all night shift. Offering free mince pies until they run out.. So very sad to hear about Romeo Jones… been a customer since the opening, any idea where Patrick has gone or details… please pm me.    What is going to be in its place…. Will be around in Jan…umm village is changing….
    • interesting the police said "the car was in demand at the moment" what make/model is that?
Home
Events
Sign In

Sign In



Or sign in with one of these services

Search
×
    Search In
×
×
  • Create New...