internet / virus scan

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Hi, we have recently encountered a problem with our PC. when we connect to the internet we now get a lot of unwanted pop ups and the homepage has changed to something that we didn't request. Also, out virus scan (McAfee V8) keeps finding 'potentially unwanted programs' and a trojan. It deletes the trojan and 'quarantines' the files as they cannot be deleted. Now, the virus scan will continue to pick up these files, including the deleted trojan. I have tried to delete the files manually, some I can't find and the others I cannot delete as they are either locked or in use. Is there anyway to get these off the machine or will we have to do a system restore

Please help ...
 
Hi Andrew,

Spy and ad programs are the most likely suspects.

1) Install and run Adaware from www.lavasoft.de

2) Install and run Spybot from www.safer-networking.org

3) Install and run Spyware Blaster from
http://www.javacoolsoftware.com/spywareblaster.html

4) Turn on the native firewall or install a third-party one (a third party
firewall will notify you of outgoing traffic as spyware programs "phone
home", the native one won't).

http://www.kerio.com/kpf_home.html
http://www.zonelabs.com/store/content/home.jsp
http://www.tinysoftware.com/home/tiny2?la=EN

5) Also check these links for helpful advice on removing garbage:
http://aumha.org/a/noads.htm
http://aumha.org/win5/a/parasite.htm
http://www.mvps.org/inetexplorer/Darnit.htm

--
Best of Luck,

Rick Rogers aka "Nutcase" MS-MVP - Windows
Windows isn't rocket science! That's my other hobby!

Associate Expert - WinXP - Expert Zone
 
Hi, we have recently encountered a problem with our PC. when we connect to the internet we now get a lot of unwanted pop ups and the homepage has changed to something that we didn't request. Also, out virus scan (McAfee V8) keeps finding 'potentially unwanted programs' and a trojan. It deletes the trojan and 'quarantines' the files as they cannot be deleted. Now, the virus scan will continue to pick up these files, including the deleted trojan. I have tried to delete the files manually, some I can't find and the others I cannot delete as they are either locked or in use. Is there anyway to get these off the machine or will we have to do a system restore?

Please help ...

More info about parasites:
http://www.aumha.org/a/parasite.htm

Download the utility CWshredder:
http://www.spywareinfo.com/~merijn/files/cwshredder.zip

Unzip - close *all* instances of IE & OE, hit the executable and
follow
the prompts.

You can also download Hijack This from here:

http://www.mjc1.com/files/merijn/hijackthis.exe

Go here:
http://mjc1.com/mirror/hjt/

For instructions on how to use it; you have to post the log it
produces

here:
http://www.spywareinfo.com/forums/
so experts tell you what is good and what is malware
HijackThis Log Tutorial
http://www.aumha.org/a/hjttutor.php
HiJack This is a program that simply searches for programs that run at
boot

time, and checks for browser plug-ins. The results this program gives
you

are generally just informative. Most of the programs it will come up
with

are valid programs that you actually want running. You'll have to go

through the results and tell the program to delete unwanted programs.
If

you can't figure out what some of the programs are, don't just delete
them,

research them and/or post them so experts can let you know what the
program

does. Just type the program name into google which gets a decent
answer

pretty quickly.


Try downloading, installing and updating the
spyware removers from the links below. Run both of them.

Ad-aware
http://www.lavasoftusa.com/support/download/

Spybot S&D
http://www.safer-networking.org/index.php?lang=en&page=download


If these don't correct the problem, then get yourself a copy of
BHODemon,

available at
http://www.definitivesolutions.com/bhodemon.htm .

It does not need installing - simply unzip and run the EXE program. It
is

easy to use. It will find the hijackware DLL files, and give you the

ability to disable them.

Hope this helps.
 
Hi, we have recently encountered a problem with our PC. when we connect to the internet we now get a lot of unwanted pop ups and the homepage has changed to something that we didn't request. Also, out virus scan (McAfee V8) keeps finding 'potentially unwanted programs' and a trojan. It deletes the trojan and 'quarantines' the files as they cannot be deleted. Now, the virus scan will continue to pick up these files, including the deleted trojan. I have tried to delete the files manually, some I can't find and the others I cannot delete as they are either locked or in use. Is there anyway to get these off the machine or will we have to do a system restore?

Please help ...

Andrew,

How current is your virus protection? Try these free online virus scans, to
complement McAfee:
<http://www.bitdefender.com/scan/license.php>
<http://www.pandasoftware.com/activescan/com/activescan_principal.htm>
<http://www.ravantivirus.com/scan/>
<http://security.symantec.com/ssc/home.asp>
<http://housecall.trendmicro.com/housecall/start_corp.asp>

Now check for, and learn to defend against, additional carriers of infection.
Have you downloaded these programs before? Download them again, as many are
revised frequently, to keep up with the current level of malware being attempted
constantly - get the absolutely most current version of each product listed.
They're all free - and most pretty small, so they download quickly enough.

First, download LSP-Fix and WinsockXPFIx from <http://www.cexx.org/lspfix.htm>,
and CWShredder from <http://www.majorgeeks.com/download4086.html>. All are
free.

Next, close all Internet Explorer and Outlook windows, then run CWShredder.
Have it fix all variants.

Now check for, and remove, spyware. Get HijackThis
<http://www.majorgeeks.com/download.php?det=3155> and Spybot S&D
<http://www.safer-networking.org/index.php?page=download>. Both free.
1) Install and run Spybot. First update it ("Search for updates"), then run a
scan ("Check for problems"). Trust Spybot, and make all recommended deletions.
2) Install and run HijackThis. Do NOT make any changes immediately. Save the
HJT Log.
3) Have your HJT log interpreted by experts at one or more of the following
forums (and post it here):
<http://forums.net-integration.net/>
<http://forums.spywareinfo.com/>
<http://forums.tomcoyote.org/>
<http://www.wilderssecurity.com/>

If removal of any spyware affects your ability to access the internet (some
spyware builds itself into the network software, and its removal may damage your
network), run LSP-Fix and / or WinsockXPFIx.

Finally, improve your chances for the future.

Harden your browser. There are various websites which will check for
vulnerabilities, here are three which I use.
http://www.jasons-toolbox.com/BrowserSecurity/
http://bcheck.scanit.be/bcheck/
https://testzone.secunia.com/browser_checker/

Harden your operating system. Check at least monthly for security updates.
http://windowsupdate.microsoft.com/

Block possibly dangerous websites with a Hosts file. Three Hosts file sources I
use:
http://www.accs-net.com/hosts/get_hosts.html
http://www.mvps.org/winhelp2002/hosts.htm
(The third is included, and updated, with Spybot (see above)).

Maintain your Hosts file (merge / eliminate duplicate entries) with:
eDexter <http://www.accs-net.com/hosts/get_hosts.html>
Hostess <http://accs-net.com/hostess/>

Cheers,
Chuck
Paranoia comes from experience - and is not necessarily a bad thing.
 
Back
Top