PC Review


Reply
Thread Tools Rate Thread

Is this avirus?

 
 
Peter
Guest
Posts: n/a
 
      19th Nov 2004
A friend asked me to look at his computer (WIN XP Prof). SP2 is not
installed. A message appears saying that a process wishes to use his Default
IP connection and connect to one of the following:
morfline.Iwas2.net
www.wincustomize.com
irc.dal.net
www.w3.org
www.google.com
www.warez.com
www.msn.com
When connected to the net his computer appears to be sending large amounts
of data but I can't work out which program is sending. It is not possible to
use msconfig and avg cannot be opened. Both avg and msconfig appear briefly
on the screen and then the window disappears.
Any help appreciated.

Peter


 
Reply With Quote
 
 
 
 
David H. Lipman
Guest
Posts: n/a
 
      19th Nov 2004
Sounds like malware, perform the following and find out...

1) Download the following three items...

Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp

Adaware SE (free personal version v1.05)
http://www.lavasoftusa.com/

Create a directory.
On drive "C:\"
(e.g., "c:\New Folder")
or the desktop
(e.g., "C:\Documents and Settings\lipman\Desktop\New Folder")

Download SYSCLEAN.COM and place it in that directory.
Download the Trend Pattern File by obtaining the ZIP file.
For example; lpt255.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

2) Update Adaware with the latest definitions.
3) If you are using WinME or WinXP, disable System Restore
http://vil.nai.com/vil/SystemHelpDoc...SysRestore.htm
4) Reboot your PC into Safe Mode
5) Using both the Trend Sysclean utility and Adaware, perform a Full Scan of your
platform and clean/delete any infectors/parasites found.
(a few cycles may be needed)
6) Restart your PC and perform a "final" Full Scan of your platform using both the
Trend Sysclean utility and Adaware
7) If you are using WinME or WinXP,Re-enable System Restore and re-apply any
System Restore preferences, (e.g. HD space to use suggested 400 ~ 600MB),
8) Reboot your PC.
9) If you are using WinXP, create a new Restore point

* * * Please report back your results * * *

Dave




"Peter" <(E-Mail Removed)> wrote in message news:cnlspm$ni8$(E-Mail Removed)...
| A friend asked me to look at his computer (WIN XP Prof). SP2 is not
| installed. A message appears saying that a process wishes to use his Default
| IP connection and connect to one of the following:
| morfline.Iwas2.net
| www.wincustomize.com
| irc.dal.net
| www.w3.org
| www.google.com
| www.warez.com
| www.msn.com
| When connected to the net his computer appears to be sending large amounts
| of data but I can't work out which program is sending. It is not possible to
| use msconfig and avg cannot be opened. Both avg and msconfig appear briefly
| on the screen and then the window disappears.
| Any help appreciated.
|
| Peter
|
|


 
Reply With Quote
 
Beauregard T. Shagnasty
Guest
Posts: n/a
 
      19th Nov 2004
Peter wrote:

> When connected to the net his computer appears to be sending large
> amounts of data but I can't work out which program is sending.


Sounds to me like he is a zombie, sending spam via a trojanized SMTP
engine. In addition to the other recommendations, try:

A-Squared anti-trojan program: http://www.emsisoft.com/en/

--
-bts
-This space intentionally left blank.
 
Reply With Quote
 
Peter
Guest
Posts: n/a
 
      21st Nov 2004
David,
Thanks for the info. tried it out but, although some spyware removed, as
soon as the computer is connected to the net it starts sending. This
restricts bandwidth (dialup modem) and makes it impossible to download Zone
Alarm etc. Still unable to open AVG or run MSCONFIG. I tried to install SP2
but this does not appear to have installed properly. I have suggested he
returns his system to supplier and get XP reinstalled etc.

Many thanks for your help.

Peter


 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
HOW TO REMOVE AVIRUS FROM THE AVG VIRUS VAULT Peter Windows XP General 5 26th Oct 2004 04:49 PM
Problem with avirus? =?Utf-8?B?YmFycm93aW5ob3Zl?= Windows XP Security 2 4th May 2004 01:39 PM
Avirus that attaches to MS Win =?Utf-8?B?RG9ubmE=?= Windows XP Embedded 1 20th Feb 2004 11:34 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 11:33 PM.