Go Back   Team-BHP > Around the Corner > Shifting gears

Shifting gears Off-topic discussions.


Reply
 
Thread Tools
Old 15th April 2006, 10:26   #1 (permalink)
Senior - BHPian
 
viper's Avatar
 
Join Date: Mar 2005
Location: Back in Mumbai
Posts: 2,020
Default Help with Suspected Virus

Hi Guys,

Just received a msg on my MSN Messenger window from one of my contacts with a link leading to msnmessenger profiles with my name and asking if it was me. I clicked on the link and a dos application downloaded.

Now I cannot find the file which got downloaded to my default download folder from where I doubleclicked it.

Within a minute I got a Windows file error message on my screen(XP SP2) asking me to restore my original files as they have been replaced by some other files. I tried running a Norton Antivirus scan but even my NAV is acting up saying that I should register and activate my product which was already activated and valid till Dec 2006.

Please help what should I do.

Viper
__________________
NO ONE DARES COME CLOSE
viper is online now   Reply With Quote
Old 15th April 2006, 11:23   #2 (permalink)
BANNED
 
Join Date: Feb 2005
Location: Bombay
Posts: 628
Default

Viper,
Sometimes Norton does not catch the virus.. try using a WORMKILLER app or something..here's the link.
http://www.freedownloadscenter.com/B...killer-xp.html
Hope it helps!
Cheers
2L8uLoose is offline   Reply With Quote
Old 15th April 2006, 11:25   #3 (permalink)
aZa
Senior - BHPian
 
aZa's Avatar
 
Join Date: Mar 2006
Location: Noida / Delhi
Posts: 1,171
Default

Heya Viper

1. Never download / accept / click on links from unknown ppl
2. Check the authenticity of the url and extention etc.
3. Norton sucks
4. be uptodate with MS patches
5. Get NoD32

if ur faithful norton has been pwn3d then try downloading Stinger from mcafee its a small standalone viruss scanner for latest threats. if u have a firewall then u would know which application is connecting to the net or just use tcpview and check them out.


cheers
__________________
-[ " If the ride is more fly, then you must buy. " - Snoop Dogg ]-
aZa is offline   Reply With Quote
Old 15th April 2006, 11:38   #4 (permalink)
Senior - BHPian
 
viper's Avatar
 
Join Date: Mar 2005
Location: Back in Mumbai
Posts: 2,020
Default

Guys,

I just reinstalled my Windows and the funny thing is I did not log onto MSN. But this window popped up and someone buzzed me. User Called "I will get my revenge Pete".

Am scared since I have a lot of data and no back up. He lp
__________________
NO ONE DARES COME CLOSE
viper is online now   Reply With Quote
Old 15th April 2006, 11:53   #5 (permalink)
Senior - BHPian
 
abhibh's Avatar
 
Join Date: Sep 2005
Location: In the Hood Near You
Posts: 1,520
Default

Hi,

If you have original windows i will suggest you 2 things that will keep you safe each and everytime.

1. Windows one Care Live. You can get it online for free at http://www.windowsonecare.com/purchase/default.aspx . install the beta for free will take around 15 - 30 mins on 256k connection. Its online installation. You should atleast have 256 MB RAM unshared.

2. Windows Defender. http://www.microsoft.com/athome/secu...e/default.mspx .
Its a spyware remover from misrosoft for free for its customers.

I have been using Onecare form past 3 months and not a single problem. Its very light and good. And windows defemder i have been using for past 1 month and it simply rocks. Dont even let you know about any spyware that hits yer computer.

P.S. I have 1 Gb ram and used to use norton and Mcaffe. Norton was so heavy and mcafee was so buggy at times. Used NOD but was not uptomark. Though Kaspersky was good but used to update defination everyday

Cheers.
__________________
For every idiot there is an equal and opposite gender idiot. Singles are people with incomparable intelligence!
abhibh is offline   Reply With Quote
Old 15th April 2006, 11:57   #6 (permalink)
Senior - BHPian
 
abhibh's Avatar
 
Join Date: Sep 2005
Location: In the Hood Near You
Posts: 1,520
Default

Hi,

Are yo on lan. If yes then one can netsend you these messgaes easily if they know yer computername. But if you are not on lan then it must be a Trojan.
http://windowsupdate.microsoft.com/ Go here and update yer windows and i m sure problem will go away. Do rememerb to install windows onecare and defender.
__________________
For every idiot there is an equal and opposite gender idiot. Singles are people with incomparable intelligence!
abhibh is offline   Reply With Quote
Old 15th April 2006, 12:05   #7 (permalink)
BHPian
 
freakrz's Avatar
 
Join Date: Nov 2004
Location: NewYork/Bangalore
Posts: 90
Default

you reinstalled windows and still got infected.did you format your hard drive.or just upgraded on the existing system.

ok..first check all the processes that are running in the background.
hit CTRL + ALT + DEL and check for the processes.it will be helpful to give you a clear idea if you could provide the process names running.

Do this in safemode..you can enter safemode by pressing F8 just after you start your p.c and before the starting windows screen pops up..

check your start up.to do that --> click start menu --> run --> type msconfig
-->enter..->a window will be displayed in that check the start up .remove all the unnecessary stuff.all that you dont want to start when windows starts up..like winamp,yahoo messenger,msn etc..you can start up after you start windows..they dont require to be in the start up.

since you have stated msn messenger,through which ur being threatend..i would like to suggest you to disable the messenger service.that would protect you to a certain extent.till you clean up the system.

step 1 : Right click on My Computer
Click Manage
Click on Services & Applications
Click on Services
Step 2: On the right side of the same window scroll down .you will find "messenger"
Double Click that --> a window pops open
stop the service
in the start up type --> select "Disabled"

If you have a service named messenger sharing...Follow the same steps as above..and disable it.

now get a firewall, something like zone alarm or outpost,which is available free online.install it..and just watch the logs..i know this is getting complicated..but do that only if you want to find who 's bothering you..well i could give you more details..if you want to..just p.m me..

AVG is a better antivirus and its available free online...you can download it here...

http://free.grisoft.com/doc/2/lng/us/tpl/v5

if you could give me some more details about the virus or what ever errors you r encountring..i could give you more detail about the cleaning procedure...
__________________
REDLINING LiFe.....
freakrz is offline   Reply With Quote
Old 15th April 2006, 12:52   #8 (permalink)
Senior - BHPian
 
viper's Avatar
 
Join Date: Mar 2005
Location: Back in Mumbai
Posts: 2,020
Default

Hi Guys,

What I have figured out is that it is a Trojan. Got detected by a older version of Panda anti virus. Norton i snot getting completely uninstalled and all antivirus programs are not working. it says expired. The virus is in System win32/hosts or something like that.

Viper
__________________
NO ONE DARES COME CLOSE
viper is online now   Reply With Quote
Old 15th April 2006, 15:31   #9 (permalink)
Senior - BHPian
 
viper's Avatar
 
Join Date: Mar 2005
Location: Back in Mumbai
Posts: 2,020
Default

Hi Guys,

Have finally identified the problem. It is a FakeMSN8Beta virus which from one file has multiplied into 90 files in 20 mins.

It is located in C:\WINDOWS\System32\taskkill.com
and C:\WINDOWS\System32\netstat.com.

AM now formatting my comp to prevent any further problems as my whole comp is acting up.

Viper
__________________
NO ONE DARES COME CLOSE
viper is online now   Reply With Quote
Reply




Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Which Anti-virus software do you use ? adityapd Gadgets, Computers & Software 210 2nd July 2008 01:35
Virus Alert !!! Ford Rocam Gadgets, Computers & Software 0 13th July 2006 12:02
Virus on Bluetooth mobiles DRC Shifting gears 11 19th February 2006 14:35
Suspected street racing leaves 3 dead: Again amit Street Experiences 4 30th January 2006 10:34
Spybot virus Deeps Shifting gears 4 9th October 2004 23:03


All times are GMT +5.5. The time now is 13:50.


Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright ©2000 - 2008, Team-BHP.com

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445