PDA

View Full Version : Help I got a virus



skip
07-28-2005, 01:42 AM
Hey anyone help me with the bloodhound virus. Norton Anti virus is not getting it. I am frustrated. Help...

Jordon
07-28-2005, 01:44 AM
http://housecall.antivirus.com run the free online scan, it will prolly get it , or google the virus and find instructions on how to remove it manually , your gonna have to most likely boot in safe mode and delete a few files somewhere and take a few entries out of your registry, not too bad if you know how to attack it.. :) gl

skip
07-28-2005, 02:18 AM
yeah I followed you right up to googling the virus and then I'm lost. haha WTF safe mode Reboot >>? Thats the part I am having a hard time How do I know which files to delete>? I did a print out of suspicious files using something called Hijacker I think...But I dont know how to decipher it, Anyone familiar with>?

medicatedMELTDOWN
07-28-2005, 02:32 AM
try this....... http://www.pandasoftware.com/activescan/

skip
07-28-2005, 02:42 AM
thats a beautiful picture there in your avatar haha I'll check that panda....

jiminyrootkit
07-28-2005, 04:53 AM
panda is good shit, avg works pretty well......avg is free, as far as i know, panda isn't.
-f

Udai Hussien
07-28-2005, 08:10 AM
panda is good shit, avg works pretty well......avg is free, as far as i know, panda isn't.
-f
the full version of panda isnt.. they have a free scan on;ine, and a scan for PC, it just dosent work 24-7

Dale M.
07-28-2005, 09:27 AM
Safe Mode boot is a minimal system boot with only necessary files and system feature operational to do minimal work system work.... Press F8 during boot process (several times) and you get a screen asking you how to proceed with boot process... Procedure will vary according to what version of Windows you are running (I assume Windows) and what options computer manufacturere made available to you in this mode...BE careful!

I use AGV free version and it seems to work pretty well... It also scans incoming and out going e-mail.....

If it cant remove virus, at least it will quarentine file virus is in and tell you what process it requires to romove it... it also checks web site daily for new virus profiles and daily system can if you schedule it to do so...

http://www.grisoft.com/doc/1

Seems to work better than Nortans or McAfee for me...

Dale

Udai Hussien
07-28-2005, 10:02 AM
Safe Mode boot is a minimal system boot with only necessary files and system feature operational to do minimal work system work.... Press F8 during boot process (several times) and you get a screen asking you how to proceed with boot process... Procedure will vary according to what version of Windows you are running (I assume Windows) and what options computer manufacturere made available to you in this mode...BE careful!

I use AGV free version and it seems to work pretty well... It also scans incoming and out going e-mail.....

If it cant remove virus, at least it will quarentine file virus is in and tell you what process it requires to romove it... it also checks web site daily for new virus profiles and daily system can if you schedule it to do so...

http://www.grisoft.com/doc/1

Seems to work better than Nortans or McAfee for me...

Dale

Instead of going into safe mode, all you have to do is turn system restore off, then do the scan, but remember to turn the system restore back on after you reboot

Dale M.
07-28-2005, 11:19 AM
Instead of going into safe mode, all you have to do is turn system restore off, then do the scan, but remember to turn the system restore back on after you reboot

HUH?........ And what does that do for you? Though system restore took you back to last know safe operating condition. And It really does no good IF you have not done a safe restore point in past..... Some people never initalize safe restor point(s) so they have NOTHING to go back to....

Dale

phab
07-28-2005, 12:05 PM
....download and run the free avg. i had 12 virus' on my laptop, it killed 11 and quanenteened one. they also have fee updates always available since the virus thing keeps changing

...d/l the free 7.338 http://free.grisoft.com/doc/Get+AVG+FREE/lng/us/tpl/v5

Udai Hussien
07-28-2005, 12:24 PM
HUH?........ And what does that do for you? Though system restore took you back to last know safe operating condition. And It really does no good IF you have not done a safe restore point in past..... Some people never initalize safe restor point(s) so they have NOTHING to go back to....

Dale


Yeah I know, but most Virii now try to create bad sectors, and infect restore points. Espicailly spyware. Thats the reason why I switched from AVG to panda... Panda is the best on the market. It costs though too..I have 3 liscenses left to hook a few people up.. Avast is good, but if you get Wintroj other, it wont remove it

medicatedMELTDOWN
07-28-2005, 12:31 PM
I have 3 liscenses left to hook a few people up..


hahah hey bro......i wouldnt mind achieving this "hooked up" status :smokin: :glasses:

PyroChixRock
07-28-2005, 02:18 PM
This is the vulnerability being exploited:

Microsoft Security Bulletin MS05-037
Vulnerability in JView Profiler Could Allow Remote Code Execution (903235)

http://www.microsoft.com/technet/security/bulletin/ms05-037.mspx

you need to download the patch from windows update, it affects all systems.
(link above)


Viruses being reported: (removal tools can be found there)
http://securityresponse.symantec.com/avcenter/venc/data/download.trojan.html

How to remove a trojan - from Sophos:
http://www.sophos.com/support/disinfection/trojan.html

Removal tool
http://securityresponse.symantec.com/avcenter/venc/data/w32.mydoom@mm.removal.tool.html



The best thing is to update the anti-virus. See what kind of virus it detects and then look for info on it on the symantec site in case the anti-virus could not handle it
also look for the followin files on the system (root of C drive and windows dir mainly):
1.exe
w.exe
asdf.exe
delete them and delete any JAVA files cached. Java cache files can be accessed from the JAVA console. also look on the windows dir for modified files on the last two days, if there's any random names files then delete them. for window XP make sure to disable system restore first or after you reboot they will be back, after you reboot and make sure the files are deleted you can enable system restore again.

Udai Hussien
07-28-2005, 02:45 PM
hahah hey bro......i wouldnt mind achieving this "hooked up" status :smokin: :glasses:


Check your PM's my man

diglassworks
07-28-2005, 06:50 PM
I feel bad you have a virus, but I'm wondering why this thread is in this section when all the others get moved?

PyroChixRock
07-28-2005, 08:02 PM
You ever tried to browse with a virus? :lol I'm sure it'll get moved when skip is ok, but he's our bro so lend him a hand...

diglassworks
07-28-2005, 08:03 PM
I wasn't trying to sound like an ass, I'd help if I could...

skip
07-29-2005, 02:06 AM
Hey thanks for all your guys help I'm still tryiing . Downloding shit when you have a virus takes fucking years. I have some help coming to look tommorow. I'll keep you updated.

Oh and Diglass to answer your question
I'm wondering why this thread is in this section when all the others get moved?

Umm if you really are perplexed, It's cause I put it here. heh now go worry bout something else

Udai Hussien
07-29-2005, 02:21 AM
Get me a list of the virii you are having beef with, Ill help if I can

IrieGuy05
07-29-2005, 02:41 AM
Save everything you really need. Then do a complete restoral of windows like delete your hd basically and redo it all, it will be gone.

Udai Hussien
07-29-2005, 03:32 AM
Save everything you really need. Then do a complete restoral of windows like delete your hd basically and redo it all, it will be gone.

Well, thats not nesicarlly true, if its a worm, and it infected boot sectors, it could run dormant in programs, so when you re-install that program, it re-infects. Only way to format is to wipe the whole HD and Format... thats always a last resort..

brettodie
07-29-2005, 06:01 AM
try www.stop-sign.com :) its a pay one but it removes anything ive ever found. its has several nice features and works well even for the complete computer idiot. also to avoid viruses try a different mail broweser other then outllok express that helps a ton. i have to say aol sux if you use it for your connection but as a browser and mail client its great,ive only had 3 viruses in almost 10 yrs of geeking out online and i never see a pop up,not even on places like myspace i didnt even know there was popups on there till someone mentioned it in another thread :) any ways good luck,if you need help removing by hand pm me your number and ill walk you thru it. peace brett

Dale M.
07-29-2005, 09:52 AM
Save everything you really need. Then do a complete restoral of windows like delete your hd basically and redo it all, it will be gone.


Nothing like a sledge hammer approach when a fly swatter will do....

All the utilities and tools are out there are for a reason.... Generally a reformat and reinstall causes you grief from the stand point that all those neat graphics and obscure programs you very rarely use will be wiped out..... Usually takes at least 6 months to recover from a reformat and reload....

Just quit being so cheap... spend $30-40 on anti virus tools, fix problem in 30 minutes and be done with it and move on... To many other things to do in life that screw with cranky computer....

Also try and get away from MS browsers and mail clients... They are magnets for viruses and worms...

If you have not already done so try FIREFOX as browser,. They are continually coming out with new versions that fix security problems (something MS rarely does) ..

http://www.mozilla.org/products/firefox/

For a mail client try THUNDERBIRD... Does not have a lot of bells and whistles, but does not have security holes that OUTLOOK or OUTLOOK EXPRESS has...

http://www.mozilla.org/products/thunderbird/

Both applications are snappier in performance that microstuff.


Dale

phab
07-29-2005, 11:40 AM
..i had a hard time too getting avg to load all the way too, so i downloaded mozilla, opened it for my browser, closed ie6, cause mozilla incorporates ie favorites, and when i went back to the saved avg download page to start loading it again it went thru on mozilla without a hitch.

im not sooper pc literate but i was told its hard for mozilla to get hacked into. anyone else hear that?

Udai Hussien
07-29-2005, 11:47 AM
man Firefox is the Shizzy... Does anyone use Opera or Nutscraper anymore?

Udai Hussien
07-29-2005, 11:48 AM
..i had a hard time too getting avg to load all the way too, so i downloaded mozilla, opened it for my browser, closed ie6, cause mozilla incorporates ie favorites, and when i went back to the saved avg download page to start loading it again it went thru on mozilla without a hitch.

im not sooper pc literate but i was told its hard for mozilla to get hacked into. anyone else hear that?


What do you mean by hacked into? Firefox is openend software, so you can modify it as you seem fit

Dale M.
07-29-2005, 01:55 PM
What do you mean by hacked into? Firefox is openend software, so you can modify it as you seem fit

Actually FIREFOX is (basically) the old NETSCAPE..... But much faster and slimmed down..

For your own purpose.... Mozilla org. controls official releases and I would bet security is pretty tight since I have had 6 upgrades (secuirty related) in last year and IE is about 5 years old... and.... MS has always been sucking hind tit when it comes to secirity... Look how long it took them to incorperate a Firewall...

Dale

Udai Hussien
07-29-2005, 02:06 PM
Actually FIREFOX is (basically) the old NETSCAPE..... But much faster and slimmed down..

For your own purpose.... Mozilla org. controls official releases and I would bet security is pretty tight since I have had 6 upgrades (secuirty related) in last year and IE is about 5 years old... and.... MS has always been sucking hind tit when it comes to secirity... Look how long it took them to incorperate a Firewall...

Dale


Exactly!!

phab
07-29-2005, 10:13 PM
What do you mean by hacked into? Firefox is openend software, so you can modify it as you seem fit


...what i meant was i was told that virus programs dont work as well in mozilla as they do in ie because of encryption? sumthing like that. since i loaded in the avg, im back to useing ie and not worrying anymore but my faithfull laptop was really fuggedup till i got the avg going. pretty darn good for freeware.

also just before i did all the virus crap, someone hooked me up with xp. way better than that windows millenium crap. my pc is running good again.

Udai Hussien
07-30-2005, 04:07 AM
Yeah Im not quite sure what windows was thinking when they made ME... and operating system without a Kernal or DOS :-/ .. the first "critcal update" ME downloads now is DOS.. I think they named it "Stability Upgrade Pack #1"

Mr. "Awesome!"
07-30-2005, 07:56 AM
Wow, just got firefox. It's pretty nice.

Udai Hussien
07-30-2005, 08:32 AM
Yeah I love firefox, it dosent crash like In-eard-net Exploder, or nutscrape.. I liked Opera , well until they started with the ads