Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old August 27th, 2006, 11:33 PM
trumley's Avatar
trumley trumley is offline
Professional Lay-A-Bout
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Location: Ann Arbor, Michigan
Posts: 302 trumley User rank is Corporal (100 - 500 Reputation Level)trumley User rank is Corporal (100 - 500 Reputation Level)trumley User rank is Corporal (100 - 500 Reputation Level)trumley User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 Days 19 h 30 sec
Reputation Power: 6
Send a message via Yahoo to trumley
Unhappy It's a virus or somthing malicious - help!!!

A couple of days ago I started getting this icon in my server tray. It's persistant and I can't get it to go away. I ran AVG and it turned up 2 viruses that is can't quartine or heal or deleate.

Whenever I click on the icon, it's a yellow triangle with an exclamation point in the middle, it opens a web page to different anti-virus program pages. Some of these pages are: Anti Virus Golden, spy gaurd, pest trap, and the safety home page.

Whatever it is, it has also loaded a new tool bar on my IE browser than I can not delete. I can not uncheck the tool bar in the internet options menu eithier.

Could someone pleasetell me what I can do?
__________________
Thomas

Dogs and computers both do everything you tell them.
But computers don't like their tummies rubbed.

Reply With Quote
  #2  
Old August 28th, 2006, 03:39 AM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
Hi,

firstly dont install ANY of these products, they are all spyware.

Firstly update your virus scanner with its latest definitions. If you dont have an antivirus product then download and update AVG

Also download the following tools:
Ewido
Adaware
Spybot
Hijackthis
Smitfraudfix

After downloading these, update ewido,spybot and adaware.

Disable system restore

Reboot into safemode, press F8 after rebooting before getting the windows loading screen.

Run full system scans with your virus scanner or avg. Then run full system scans with Ewido, adaware and spybot. Make a note of anything they cannot clean (if there is anything).

This can take a while depending on the size of your hard-drive and the number of files on it. Then run smitfraudfix and pick the option "Clean". Keep a copy of its log. After this reboot back into windows and run hijackthis. Scan and then post the hijackthis log and smitfraudfix log here for us to look at. Also describe the sympthoms after running all these.

It may be valuable to print out these instructions before rebooting into safemode.

Hope this helps.
Displeaser
Comments on this post
aitken325i agrees!
__________________
Vi Veri Veniversum Vivus Vici.

Reply With Quote
  #3  
Old August 28th, 2006, 11:05 AM
trumley's Avatar
trumley trumley is offline
Professional Lay-A-Bout
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jul 2004
Location: Ann Arbor, Michigan
Posts: 302 trumley User rank is Corporal (100 - 500 Reputation Level)trumley User rank is Corporal (100 - 500 Reputation Level)trumley User rank is Corporal (100 - 500 Reputation Level)trumley User rank is Corporal (100 - 500 Reputation Level) 
Time spent in forums: 2 Days 19 h 30 sec
Reputation Power: 6
Send a message via Yahoo to trumley
Quote:
Originally Posted by displeaser
Also download the following tools:
Ewido
Adaware
Spybot
Hijackthis
Smitfraudfix

After downloading these, update ewido,spybot and adaware.



I downloaded the software and ran full scans with ewido and ad-aware. 207 objects with spyware and then 72 with ad-aware. Took care of it plus another mystery server which had been sitting in my server tray for about a year that I couldn't budge.

I'm definitely going to be using ewido instead of "spyware doctore". The doctor found nothiing and fixed nothing.

Thanks for the help!

Reply With Quote
  #4  
Old August 28th, 2006, 11:10 AM
displeaser's Avatar
displeaser displeaser is offline
Periodically energetic Perler
Dev Shed Regular (2000 - 2499 posts)
 
Join Date: May 2005
Location: Dublin, Ireland
Posts: 2,266 displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)displeaser User rank is Colonel (50000 - 60000 Reputation Level)  Folding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate FolderFolding Points: 76661 Folding Title: Intermediate Folder
Time spent in forums: 4 Weeks 5 h 23 m 13 sec
Reputation Power: 532
Cool,

if you run into problems again, update them all (eqido, antivirus, adaware and spybot), run full system scans and then reboot and post a hijackthis log here.

Glad we could help.
Displeaser

Reply With Quote
  #5  
Old August 28th, 2006, 11:20 AM
tj_nt tj_nt is offline
Contributing User
Dev Shed Intermediate (1500 - 1999 posts)
 
Join Date: Feb 2004
Posts: 1,708 tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level)tj_nt User rank is Brigadier General (60000 - 70000 Reputation Level) 
Time spent in forums: 1 Month 1 Week 4 Days 3 h 52 m 18 sec
Reputation Power: 675
Something else you might rememeber to keep an eye on...

open C:\ or whatever drive the Windows root folder is on... open the 'System 32' folder and from the right click menu choose "arrange icons by date"...scroll down to the bottom and look for new entries (especially those with .exe extensions) you can find the creation dates by clicking Properties from the right click menu.

many forms of malware, trojans and other intrusive items etc will be there...check the Task Manager's "Processes" tab to try and to stop any malicious looking services... sometimes you may have to start the system in Safe Mode to be able to delete these intrusions...

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > It's a virus or somthing malicious - help!!!


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT