Can't get rid of virus

A

Andy Grey

Help anybody! I seem to have picked up a virus that Mcafee antivirus doesn't
pick up and adaware doesn't pick up. What else can I try? IE has been
hijacked - always goes to the same page (an offer for antivirus software -
blackmail marketing). Whenever I boot I get a windows error message that IE
can't load because of a "stealth worm". Icons appear on my desktop without
any action on my part. Various pieces of software won't run, some will. I
really don't want to reformat my drive and reinstall windows XP. Any ideas?

Regards,
Andy
 
L

Lew/+Silat

I recommend you or anyone else who has a problem with hijackers go here
http://help.lockergnome.com/ .Register. You will then be able to post. By
post I mean post a HIJACKTHIS log. After you register click on "PROBLEM
SOLVERS" forums. Then click on "HIJACKTHIS LOGS". Post your problem in the
HIJACKTHIS FORUM. An expert will get to you within a few days to guide you
to a clean machine :)

You may submit your HijackThis log files to any of the below Forums for
expert analysis. I personally like http://help.lockergnome.com/
Note that all Forums require Registration prior to posting

(http://aumha.net/viewforum.php?f=30)
(http://www.bleepingcomputer.com/forums/forum22.html)
(http://castlecops.com/forum67.html)
(http://forums.maddoktor2.com/index.php?showforum=17)
(http://www.spywarewarrior.com/viewforum.php?f=2)
(http://forums.spywareinfo.com/index.php?showforum=18)
(http://www.wilderssecurity.com/forumdisplay.php?f=24)
(http://boards.cexx.org/viewforum.php?f=1)
(http://www.malwarebytes.biz/forums/index.php?showforum=5)
(http://forum.gladiator-antivirus.com/index.php)
(http://www.dslreports.com/forum/security)



http://www.spywareinfo.com/~merijn/downloads.html - Download Hijackthis. Put
it in a new folder named "Hijackthis". Put the folder on c drive. This is
important for proper logging of info when you get hijacked. Do not use this
program unless you completely know what you are doing. FREE


http://www.javacoolsoftware.com/downloads.html - download and install :
SpywareBlaster and SpywareGuard FREE
http://customblockinglist.cjb.net/ - Spyware Blaster Custom Blocking List
Free!



http://www.safer-networking.org/index.php?page=download - Download and
install Spybot - Search & Destroy FREE


http://www.intermute.com/products/cwshredder.html - CWShredder Download the
standalone version. FREE

http://www.lavasoftusa.com/support/download/ - Download the free version of
Adaware and install. Or pay for the advanced version if you want. FREE

http://www.microsoft.com/athome/security/spyware/software/default.mspx -
Windows AntiSpyware (Beta) FREE

ANTI VIRUS PROGRAMS
http://free.grisoft.com/doc/Get+AVG+FREE/lng/us/tpl/v5 - AVG
If you don't have an antivirus program and don't want to pay for one then
get AVG . It is free and good. FREE
http://www.avast.com/eng/down_home.html - AVAST
To use the Home Edition, you should register it. After the installation you
have 60 days to do the registration. The registration process is very easy
and will take you only a couple of minutes.
http://www.free-av.com/ -ANTI-VIR another antivirus FREE

WINDOWS CLEANER
http://www.ccleaner.com/ - Crap Cleaner. Windows system cleaner like Window
Washer FREE

HOST FILE INFORMATION
https://netfiles.uiuc.edu/ehowes/www/resource.htm - IE-SPYAD (IE Restricted
zone list) Free!



If you dont have an antivirus you can do free scans at
Trend Micro - Free online virus Scan
http://housecall.trendmicro.com/
http://housecall.antivirus.com

McAfee Security - FreeScan
http://www.mcafee.com/myapps/mfs/default.asp

Panda ActiveScan - Free online scanner
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Computer Associates:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

DialogueScience:
http://www.antivir.ru/english/www_av/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

BitDefender
http://www.bitdefender.com/scan/license.php

Freedom Online scanner
http://www.freedom.net/viruscenter/index.html

ClamWin
http://www.clamwin.com/index.php?option=content&task=view&id=21&Itemid=56


All the downloaded programs need updating regularly.
 
D

David H. Lipman

From: "Andy Grey" <[email protected]>

| Help anybody! I seem to have picked up a virus that Mcafee antivirus doesn't
| pick up and adaware doesn't pick up. What else can I try? IE has been
| hijacked - always goes to the same page (an offer for antivirus software -
| blackmail marketing). Whenever I boot I get a windows error message that IE
| can't load because of a "stealth worm". Icons appear on my desktop without
| any action on my part. Various pieces of software won't run, some will. I
| really don't want to reformat my drive and reinstall windows XP. Any ideas?
|
| Regards,
| Andy
|

Sounds like the acctivityu of adware/spyware NOT a virus. You need you use non-viral anti
malware software such as Ad-aware SE v1.06 and SpyBot Search and Destroy v1.4 and if it is a
Browser Helper Object use BHODemon.
 
A

Andy Grey

Thanks for the info...

Andy

Lew/+Silat said:
I recommend you or anyone else who has a problem with hijackers go here
http://help.lockergnome.com/ .Register. You will then be able to post. By
post I mean post a HIJACKTHIS log. After you register click on "PROBLEM
SOLVERS" forums. Then click on "HIJACKTHIS LOGS". Post your problem in the
HIJACKTHIS FORUM. An expert will get to you within a few days to guide you
to a clean machine :)

You may submit your HijackThis log files to any of the below Forums for
expert analysis. I personally like http://help.lockergnome.com/
Note that all Forums require Registration prior to posting

(http://aumha.net/viewforum.php?f=30)
(http://www.bleepingcomputer.com/forums/forum22.html)
(http://castlecops.com/forum67.html)
(http://forums.maddoktor2.com/index.php?showforum=17)
(http://www.spywarewarrior.com/viewforum.php?f=2)
(http://forums.spywareinfo.com/index.php?showforum=18)
(http://www.wilderssecurity.com/forumdisplay.php?f=24)
(http://boards.cexx.org/viewforum.php?f=1)
(http://www.malwarebytes.biz/forums/index.php?showforum=5)
(http://forum.gladiator-antivirus.com/index.php)
(http://www.dslreports.com/forum/security)



http://www.spywareinfo.com/~merijn/downloads.html - Download Hijackthis.
Put it in a new folder named "Hijackthis". Put the folder on c drive.
This is important for proper logging of info when you get hijacked. Do not
use this program unless you completely know what you are doing. FREE


http://www.javacoolsoftware.com/downloads.html - download and install :
SpywareBlaster and SpywareGuard FREE
http://customblockinglist.cjb.net/ - Spyware Blaster Custom Blocking List
Free!



http://www.safer-networking.org/index.php?page=download - Download and
install Spybot - Search & Destroy FREE


http://www.intermute.com/products/cwshredder.html - CWShredder Download
the standalone version. FREE

http://www.lavasoftusa.com/support/download/ - Download the free version
of Adaware and install. Or pay for the advanced version if you want. FREE

http://www.microsoft.com/athome/security/spyware/software/default.mspx -
Windows AntiSpyware (Beta) FREE

ANTI VIRUS PROGRAMS
http://free.grisoft.com/doc/Get+AVG+FREE/lng/us/tpl/v5 - AVG
If you don't have an antivirus program and don't want to pay for one then
get AVG . It is free and good. FREE
http://www.avast.com/eng/down_home.html - AVAST
To use the Home Edition, you should register it. After the installation
you have 60 days to do the registration. The registration process is very
easy and will take you only a couple of minutes.
http://www.free-av.com/ -ANTI-VIR another antivirus FREE

WINDOWS CLEANER
http://www.ccleaner.com/ - Crap Cleaner. Windows system cleaner like
Window Washer FREE

HOST FILE INFORMATION
https://netfiles.uiuc.edu/ehowes/www/resource.htm - IE-SPYAD (IE
Restricted zone list) Free!



If you dont have an antivirus you can do free scans at
Trend Micro - Free online virus Scan
http://housecall.trendmicro.com/
http://housecall.antivirus.com

McAfee Security - FreeScan
http://www.mcafee.com/myapps/mfs/default.asp

Panda ActiveScan - Free online scanner
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Computer Associates:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

DialogueScience:
http://www.antivir.ru/english/www_av/

F-Secure:
http://support.f-secure.com/enu/home/ols.shtml

BitDefender
http://www.bitdefender.com/scan/license.php

Freedom Online scanner
http://www.freedom.net/viruscenter/index.html

ClamWin
http://www.clamwin.com/index.php?option=content&task=view&id=21&Itemid=56


All the downloaded programs need updating regularly.
 
A

Andy Grey

Thanks for the response. I have used ad-aware and it dowsn't detect
anything. I have another spyware checker and it won't run. Just paid $20 for
it...

Andy
 
V

Virus Guy

Andy said:
Help anybody!

Remove the hard drive and connect it (ie "slave" it) to another
computer (running the same shitty XP operating system that you have,
remember XP stands for eXtra Processes (that home users don't need but
are there because XP was designed for corporate use on big lan's).

Once you slave the drive to a trusted (virus-free) computer, use that
computer to scan the drive with suitable anti-virus software.

Other people will tell you to perform all sorts of complicated stuff
(which is sorta like performing car maintenance while you're driving
your car).

Once your system has been infected by something, you can never really
trust that you've gotten everything off of it unless you scan it while
being slaved to a trusted computer. You will never detect root-kits
or hidden directories (being used as someone's private FTP music or
movie server) unless you scan your drive in this essentially
"off-line" mode.

Remember people, now that the supreme court has essentially killed P2P
services, there ->WILL<- be an increase in the clandestine use of home
computers as FTP servers for hacker groups. They will use your
computer to store software, music, and movie files and you won't even
know it's happening. The media remain ignorant of this major use of
infected home computers. The recycler directory (which you basically
don't have access to) is a favorite place to store these files.

But again, the only effective way to rid your computer of nasty shit
is to scan it while it's slaved as a secondary drive on a trusted
second computer. It's very easy to do, and will take less time than
following instructions to obtain this software and generate that log
file and post those results etc etc.
 
D

David H. Lipman

From: "Virus Guy" <[email protected]>

| Andy Grey wrote:
||
| Remove the hard drive and connect it (ie "slave" it) to another
| computer (running the same shitty XP operating system that you have,
| remember XP stands for eXtra Processes (that home users don't need but
| are there because XP was designed for corporate use on big lan's).
|
| Once you slave the drive to a trusted (virus-free) computer, use that
| computer to scan the drive with suitable anti-virus software.
|
| Other people will tell you to perform all sorts of complicated stuff
| (which is sorta like performing car maintenance while you're driving
| your car).
|
| Once your system has been infected by something, you can never really
| trust that you've gotten everything off of it unless you scan it while
| being slaved to a trusted computer. You will never detect root-kits
| or hidden directories (being used as someone's private FTP music or
| movie server) unless you scan your drive in this essentially
| "off-line" mode.
|
| Remember people, now that the supreme court has essentially killed P2P
| services, there ->WILL<- be an increase in the clandestine use of home
| computers as FTP servers for hacker groups. They will use your
| computer to store software, music, and movie files and you won't even
| know it's happening. The media remain ignorant of this major use of
| infected home computers. The recycler directory (which you basically
| don't have access to) is a favorite place to store these files.
|
| But again, the only effective way to rid your computer of nasty shit
| is to scan it while it's slaved as a secondary drive on a trusted
| second computer. It's very easy to do, and will take less time than
| following instructions to obtain this software and generate that log
| file and post those results etc etc.

Remeber this...

If you do slave a hard disk then when the scanner scans the Registry and other OS files it
will make corrections to the surrogate and NOT the OS and Registry of the slaved hard disk.
It will only remove the file(s) on the slaved hard disk.
 
K

kurt wismer

Virus said:
Remove the hard drive and connect it (ie "slave" it) to another
computer (running the same shitty XP operating system that you have,
remember XP stands for eXtra Processes (that home users don't need but
are there because XP was designed for corporate use on big lan's).

Once you slave the drive to a trusted (virus-free) computer, use that
computer to scan the drive with suitable anti-virus software.

that would be all well and good if his problem was that he can't remove
identified malware due to it being in use by windows - however, he has
malware that his anti-virus and anti-adware software can't detect...
that's a different problem and it's not one that is magically solved by
slaving the drive in another computer...
Other people will tell you to perform all sorts of complicated stuff
(which is sorta like performing car maintenance while you're driving
your car).

other people will look at what he's described and hopefully give him
advice pertinent to his *actual* problem...

[snip]
Remember people, now that the supreme court has essentially killed P2P
services,

they haven't killed p2p services - they ruled against the 'business
model' of 2 p2p companies... there are plenty of other business models -
and open source projects generally don't even have business models...

[snip]
But again, the only effective way to rid your computer of nasty shit
is to scan it while it's slaved as a secondary drive on a trusted
second computer.

there are other options... pe disks, ntfs dos pro, etc...
It's very easy to do, and will take less time than
following instructions to obtain this software and generate that log
file and post those results etc etc.

and won't make his malware automagically become detectable... it's much
more likely that he's got non-viral malware and is faced with the
problem that there are no products that deal with non-viral malware as
thoroughly as anti-virus products deal with viruses... slaving the drive
won't help if he doesn't have the right tool for the job once the drive
is slaved...
 
V

Virus Guy

David H. Lipman said:
Remeber this...

If you do slave a hard disk then when the scanner scans the
Registry and other OS files it will make corrections to the
surrogate and NOT the OS and Registry of the slaved hard disk.
It will only remove the file(s) on the slaved hard disk.

True.

But once any nasty files have been put out of action (or removed) from
the slaved drive, you can then put the drive back in the original
computer and run some basic registry integrity tools (norton) or AV
software that should find and delete any offending registry entries
(which have been rendered useless because of the prior removal of the
viral executables).

When slaving a second hard drive to a trusted (master) computer, note
the following:

1) the trusted (master) computer should be running the same
operating system as is on the slave drive. If they are not
the same, then the operating system on the master must be
more recent (chronologically) than what exists on the slave.

2) if slaving an NT4 drive to a Win-2K system, or if slaving a
win-2K drive to a Win-XP system, note that the particular
version of NTFS on the slave drive will be changed to match
the version of NTFS on the master. This change is
irreversable. This may (or will) result in the non-
functionality of system tools (such as chkdsk) on the slave
once it is returned to it's native computer. If the slave
drive has not been formatted as an NTFS drive (ie if it is
a FAT or FAT-32 drive) or if the slave drive is a Windows-9x
(or ME?) operating system then this issue is not applicable.

3) the best way to connect the slave drive to the master
system is to connect the slave to the secondary IDE
connector or channel, and configure it as the master
(and only) drive connected to that channel. That will
usually mean un-plugging the optical (CD/DVD) drive on
the master computer and connecting the slave drive to
that same connector. When performing such a temporary
connection, do not rest the slave drive directly on the
metal chasis or frame of the open case of the master
system (you could short it out). Place something like a
magazine or at least a few pieces of paper between the
slave drive and what-ever it is resting on.

4) if the master computer is running XP, note that you may
invalidate your installation of XP by simply starting
the master without it's native CD or DVD drive being
connected to it. This situation may exist if you have
changed several hardware components of the master system
since XP was installed on it originally (such as the
amount of installed memory, the CPU model, the graphics
card, or the network adapter). This is known as "Windows
Product Activation" (wpa). Obtain and run a program called
"XPINFO.EXE" to check if the XP installation on the master
system will invalidate itself if it is started without
it's CD/DVD drive connected to the system.
 
J

James Egan

True.

But once any nasty files have been put out of action (or removed) from
the slaved drive, you can then put the drive back in the original
computer and run some basic registry integrity tools (norton) or AV
software that should find and delete any offending registry entries
(which have been rendered useless because of the prior removal of the
viral executables).

Seems like a lot more effort than booting from a BartPE cd.


Jim.
 
A

Andy Grey

That would be an oiption I guess but I don't have another machine to slave
it to...

Andy
 
A

Andy Grey

I downloaded and ran adaware se. I had an earlier version. It detects all
sorts of stuff and removes it but when I reboot the stuff is back again...

ANdy
 
A

Andy Grey

I downloaded and ran adaware se. I had an earlier version. It detects all
sorts of stuff and removes it but when I reboot the stuff is back again...

Andy
 
A

Andy Grey

Another thing I noticed is that if I run windows in safe mode adaware se
doesn't detect anything...
 
A

Andy Grey

Another thing I noticed is that if I run windows in safe mode adaware se
doesn't detect anything...
 
L

Lew/+Silat

In
Andy Grey said:
That would be an oiption I guess but I don't have another machine to
slave it to...

Andy


Please follow my previous advise to a clean machine.
 
G

Gaz

Andy Grey said:
I downloaded and ran adaware se. I had an earlier version. It detects all
sorts of stuff and removes it but when I reboot the stuff is back again...

ANdy

Good chance you have a file loading up on startup reinstalling itself.
in Hijack this look for .exe files, they arent all viruses, but there is a
good chance they are. Do a google search on the ones that look suspicious,
anything that looks like a random collection is dodgy....

Make sure you are firewalled, otherwise you will jsut get reinfected.

If hijack this it to intimidating, then try msconfig for dodgy looking
files....

Gaz
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top