PC Review Forums Newsgroups Hardware Anti-Virus help please possible virus

Reply

help please possible virus

 
Thread Tools Rate Thread
Old 16-03-2004, 04:17 PM   #1
simon archer
Guest
 
Posts: n/a
Default help please possible virus


my brother seems to think he has detected a virus the following happens
winow appears saying system shut down in one minute
and also disables virus scan on the computer
any ides as to what it could be
thanks in advance
si


  Reply With Quote
Old 16-03-2004, 04:38 PM   #2
null@zilch.com
Guest
 
Posts: n/a
Default Re: help please possible virus

On Tue, 16 Mar 2004 16:17:55 -0000, "simon archer"
<simonarcher@blueyonder.co.uk> wrote:

>my brother seems to think he has detected a virus the following happens
>winow appears saying system shut down in one minute
>and also disables virus scan on the computer
>any ides as to what it could be
>thanks in advance


There are a number of malwares that disable av scanners. He could take
a shot at the use of McAfee's Stinger:

http://vil.nai.com/vil/stinger/

And also the Sys-Up download from my web site.


Art
http://www.epix.net/~artnpeg
  Reply With Quote
Old 16-03-2004, 05:08 PM   #3
simon archer
Guest
 
Posts: n/a
Default Re: help please possible virus

tried the stinger but to no avail comes on disconnecting from the net
to but ill download the file from your site and give that a whirl
thanks for the help
si
<null@zilch.com> wrote in message
news:ktae50pnh0e0s2sbgt5s65hf6ii7sk4d1m@4ax.com...
> On Tue, 16 Mar 2004 16:17:55 -0000, "simon archer"
> <simonarcher@blueyonder.co.uk> wrote:
>
> >my brother seems to think he has detected a virus the following happens
> >winow appears saying system shut down in one minute
> >and also disables virus scan on the computer
> >any ides as to what it could be
> >thanks in advance

>
> There are a number of malwares that disable av scanners. He could take
> a shot at the use of McAfee's Stinger:
>
> http://vil.nai.com/vil/stinger/
>
> And also the Sys-Up download from my web site.
>
>
> Art
> http://www.epix.net/~artnpeg



  Reply With Quote
Old 16-03-2004, 06:00 PM   #4
GSV Three Minds in a Can
Guest
 
Posts: n/a
Default Re: help please possible virus

Bitstring <MwG5c.13738$ra4.7484@news-binary.blueyonder.co.uk>, from the
wonderful person simon archer <simonarcher@blueyonder.co.uk> said
>tried the stinger but to no avail comes on disconnecting from the net
>to but ill download the file from your site and give that a whirl
>thanks for the help


Sounds to me like the side effects of an infection ATTEMPT (not
necessarily successful) by MSBLASTER or similar worm. Does your brother
have his firewall switched on?

--
GSV Three Minds in a Can
Outgoing Msgs are Turing Tested,and indistinguishable from human typing.
  Reply With Quote
Old 16-03-2004, 06:33 PM   #5
FromTheRafters
Guest
 
Posts: n/a
Default Re: help please possible virus


"GSV Three Minds in a Can" <GSV@quik.clara.co.uk> wrote in message news:ev1QpBBVD0VAFAC1@from.is.invalid...
> Bitstring <MwG5c.13738$ra4.7484@news-binary.blueyonder.co.uk>, from the
> wonderful person simon archer <simonarcher@blueyonder.co.uk> said
> >tried the stinger but to no avail comes on disconnecting from the net
> >to but ill download the file from your site and give that a whirl
> >thanks for the help

>
> Sounds to me like the side effects of an infection ATTEMPT (not
> necessarily successful) by MSBLASTER or similar worm.


Unsuccessful attempts wouldn't necessarily appkill security
software.


  Reply With Quote
Old 16-03-2004, 06:59 PM   #6
polly tito
Guest
 
Posts: n/a
Default Re: help please possible virus


"FromTheRafters" <!0000@nomad.fake> wrote in message
news:105ei2b195v1de8@corp.supernews.com...
>
> "GSV Three Minds in a Can" <GSV@quik.clara.co.uk> wrote in message

news:ev1QpBBVD0VAFAC1@from.is.invalid...
> > Bitstring <MwG5c.13738$ra4.7484@news-binary.blueyonder.co.uk>, from the
> > wonderful person simon archer <simonarcher@blueyonder.co.uk> said
> > >tried the stinger but to no avail comes on disconnecting from the

net
> > >to but ill download the file from your site and give that a whirl
> > >thanks for the help

> >
> > Sounds to me like the side effects of an infection ATTEMPT (not
> > necessarily successful) by MSBLASTER or similar worm.

>
> Unsuccessful attempts wouldn't necessarily appkill security
> software.
>

disconnect from the internet connection, reboot, start\run type
'shutdown -a'

re-connect to the web and go download the blaster removal tool, and then the
MS patch

run them both in that order

polly


  Reply With Quote
Old 16-03-2004, 07:29 PM   #7
Conny
Guest
 
Posts: n/a
Default Re: help please possible virus


"polly tito" <deepthoukus@kneeclappers.com> skrev i meddelandet
news:c37iqg$djl$1@news6.svr.pol.co.uk...
>
> "FromTheRafters" <!0000@nomad.fake> wrote in message
> news:105ei2b195v1de8@corp.supernews.com...
> >
> > "GSV Three Minds in a Can" <GSV@quik.clara.co.uk> wrote in message

> news:ev1QpBBVD0VAFAC1@from.is.invalid...
> > > Bitstring <MwG5c.13738$ra4.7484@news-binary.blueyonder.co.uk>, from

the
> > > wonderful person simon archer <simonarcher@blueyonder.co.uk> said
> > > >tried the stinger but to no avail comes on disconnecting from

the
> net
> > > >to but ill download the file from your site and give that a whirl
> > > >thanks for the help
> > >
> > > Sounds to me like the side effects of an infection ATTEMPT (not
> > > necessarily successful) by MSBLASTER or similar worm.

> >
> > Unsuccessful attempts wouldn't necessarily appkill security
> > software.
> >

> disconnect from the internet connection, reboot, start\run type
> 'shutdown -a'
>
> re-connect to the web and go download the blaster removal tool, and then

the
> MS patch
>
> run them both in that order
>
> polly
>
>


Don't always help, I have seen brand new XP installations
get infected in less than 20 sec if the patch is not applied.

Better to have the patch on a floppy and patch xp before connecting to
internet.


  Reply With Quote
Old 16-03-2004, 08:30 PM   #8
simon archer
Guest
 
Posts: n/a
Default Re: help please possible virus

thanks all for your help il pass on all the info to him
thanks again
si
"Conny" <NOSPAMuncurbed@swipnet.se> wrote in message
news:1AI5c.86435$dP1.246804@newsc.telia.net...
>
> "polly tito" <deepthoukus@kneeclappers.com> skrev i meddelandet
> news:c37iqg$djl$1@news6.svr.pol.co.uk...
> >
> > "FromTheRafters" <!0000@nomad.fake> wrote in message
> > news:105ei2b195v1de8@corp.supernews.com...
> > >
> > > "GSV Three Minds in a Can" <GSV@quik.clara.co.uk> wrote in message

> > news:ev1QpBBVD0VAFAC1@from.is.invalid...
> > > > Bitstring <MwG5c.13738$ra4.7484@news-binary.blueyonder.co.uk>, from

> the
> > > > wonderful person simon archer <simonarcher@blueyonder.co.uk> said
> > > > >tried the stinger but to no avail comes on disconnecting from

> the
> > net
> > > > >to but ill download the file from your site and give that a whirl
> > > > >thanks for the help
> > > >
> > > > Sounds to me like the side effects of an infection ATTEMPT (not
> > > > necessarily successful) by MSBLASTER or similar worm.
> > >
> > > Unsuccessful attempts wouldn't necessarily appkill security
> > > software.
> > >

> > disconnect from the internet connection, reboot, start\run type
> > 'shutdown -a'
> >
> > re-connect to the web and go download the blaster removal tool, and then

> the
> > MS patch
> >
> > run them both in that order
> >
> > polly
> >
> >

>
> Don't always help, I have seen brand new XP installations
> get infected in less than 20 sec if the patch is not applied.
>
> Better to have the patch on a floppy and patch xp before connecting to
> internet.
>
>



  Reply With Quote
Old 16-03-2004, 09:31 PM   #9
FromTheRafters
Guest
 
Posts: n/a
Default Re: help please possible virus


"Conny" <NOSPAMuncurbed@swipnet.se> wrote in message news:1AI5c.86435$dP1.246804@newsc.telia.net...
>
> "polly tito" <deepthoukus@kneeclappers.com> skrev i meddelandet
> news:c37iqg$djl$1@news6.svr.pol.co.uk...
> >
> > "FromTheRafters" <!0000@nomad.fake> wrote in message
> > news:105ei2b195v1de8@corp.supernews.com...
> > >
> > > "GSV Three Minds in a Can" <GSV@quik.clara.co.uk> wrote in message

> > news:ev1QpBBVD0VAFAC1@from.is.invalid...
> > > > Bitstring <MwG5c.13738$ra4.7484@news-binary.blueyonder.co.uk>, from

> the
> > > > wonderful person simon archer <simonarcher@blueyonder.co.uk> said
> > > > >tried the stinger but to no avail comes on disconnecting from

> the
> > net
> > > > >to but ill download the file from your site and give that a whirl
> > > > >thanks for the help
> > > >
> > > > Sounds to me like the side effects of an infection ATTEMPT (not
> > > > necessarily successful) by MSBLASTER or similar worm.
> > >
> > > Unsuccessful attempts wouldn't necessarily appkill security
> > > software.
> > >

> > disconnect from the internet connection, reboot, start\run type
> > 'shutdown -a'
> >
> > re-connect to the web and go download the blaster removal tool, and then

> the
> > MS patch
> >
> > run them both in that order
> >
> > polly
> >
> >

>
> Don't always help, I have seen brand new XP installations
> get infected in less than 20 sec if the patch is not applied.


True.

> Better to have the patch on a floppy and patch xp before connecting to
> internet.


Maybe the OP should search for "xpsurvivalguide" for suggestions.
I have only seen it in PDF format, but it is good information for XP
installation.


  Reply With Quote
Old 16-03-2004, 10:05 PM   #10
polly tito
Guest
 
Posts: n/a
Default Re: help please possible virus


> > > >
> > > disconnect from the internet connection, reboot, start\run type
> > > 'shutdown -a'
> > >
> > > re-connect to the web and go download the blaster removal tool, and

then
> > the
> > > MS patch
> > >
> > > run them both in that order
> > >
> > > polly
> > >
> > >

> >
> > Don't always help, I have seen brand new XP installations
> > get infected in less than 20 sec if the patch is not applied.
> >
> > Better to have the patch on a floppy and patch xp before connecting to
> > internet.
> >

yes, brand new installations can get infected immediately that is why I
specified getting the -removal tool- first. It doesn't matter if your system
is infected you are able to clean it and patch it without the system
shutting down by following the instructions above. If in your case it didn't
help then maybe you forgot to disconnect from the web once you had the
removal tool/patch?

possibly?

polly



  Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off