Virus Problem Solved !?

  • Thread starter Thread starter Mike S
  • Start date Start date
M

Mike S

Andy!

I think I have got it.

I have been following Ed/Edwin's post of a day earlier
who seemed to have the same problem and he wrote:

"I FOUND A SOLUTION!

Go to Control panel, appearance and themes, change the
desktop background, click 'customize desktop, click web
tab and unclick any of the options that are ticked. it
worked for me and that annoying flashing grey background
went away."

It worked for me which furthers my belief that I had
deleted the virus with your earlier suggestions but that
it had left a switch tripped (my primative understanding
of computers)and I continued to get that yellow warning
sign for my background.

I deleted PSGuard believing it to be a pop-up from the
warning sign.

It seems to me I should follow through with your Killbox
suggestion just to be thorough. Or should I not press my
luck and quit here?

Maybe I do one more check with Ewido in safe mode?

Thanks for all your help.
 
Hi Mike ,

Nice to hear you may be nearly clean again,I did notice
the post by edwin but wanted to make sure its not changed
the registry on yours,If you have your desktop back and
it doesnt switch back when you reboot then hopefully
you've fixed that problem.

With killbox this is quite important to make sure your
system is clean,I remembered you saying in a earlier post
that you searched for some of the bad files and they
appeared but wouldnt let you delete them,then the next
time you searched you couldnt find them

If any of the malware files still exist using killbox
will take them out when you reboot.Killbox is a great
tool for files that just refuse to be deleted,

Most of the names i put should not exist anymore as they
are not showing in the Hijack log its just a way to clean
up and confirm there's no traces left,for example these
entries below that were in your log:

O4 - HKLM\..\Run: [MSN Messenger] C:\WINDOWS\system32
\msmsgs.exe

O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\system32
\hookdump.exe

Fixing these with hijack will not remove the file from
c/drive it will delete the registry run command thats
making the file start up when you reboot.Once you fix
them in Hijack this,Its best to enable hidden files and
folders and boot into safe mode then remove the malware
files.With the malware files being in the Windows System
32 folder they are running with Windows so using killbox
could be a easier option to delete all the crap when you
reboot.



If you think your clean again now you may not need to do
this but running Microworlds escan is probably better at
this stage than runnin Ewido again.Escan doesnt delete
malware but its very precise and will let you know if
anything remains.

Microworld's Escan

ftp://ftp.microworldsystems.com/download/tools/mwav.exe


Download to desktop,double click to extract & run .Tick
all possible scan locations ( all folders and all
drives ) then press scan . When its finished scanning it
will display the results in the lower pane.You can copy n
paste that by left clicking and covering all the text
then press Control & C to copy it.


If it says malware was found and you need to pay to
remove it just shut it down and let it carry on
scanning.With the results only remove files your sure
about as Escan will tag anything suspicious as a virus
riskware,Adware and other things like built in tools such
as W32.reboot that AOL and other companies use to reboot
your system when your upgrading their products.


If there's any crap left this scanner should find it for
you but it does take a very long time so only use it if
you think its needed .




To help you stay clean here some links to free programs
that protect your system :
----------------------------------------------------------
----------------------------------------------------------

Spybot Search & Destroy 1.4

http://fileforum.betanews.com/download/Spybot_Search_and_D
estroy/1043809773/1

(Use all updates and the immunize feature to block known
malicious sites)
----------------------------------------------------------
----------------------------------------------------------

Ad-Aware SE


http://www.download.com/Ad-Aware-SE-Personal-Edition/3000-
8022_4-10399602.html?tag=sptlt_s

----------------------------------------------------------
----------------------------------------------------------

Spyware Blaster

http://downloads.net-
integration.net/spywareblastersetup34.exe

Prevents the installation of ActiveX-based spyware,
adware, browser hijackers, dialers, and other potentially
unwanted pests.
Block spyware/tracking cookies in Internet Explorer and
Mozilla/Firefox.
Restrict the actions of potentially dangerous sites in
Internet Explorer.

----------------------------------------------------------
----------------------------------------------------------

Spyware Guard


http://www.javacoolsoftware.net/downloads/spywareguardsetu
p.exe


SpywareGuard provides a real-time protection solution
against spyware that is a great addition to
SpywareBlaster's protection method.

----------------------------------------------------------
----------------------------------------------------------

CWShredder

http://cwshredder.net/bin/CWShredder.exe


To remove Cool Web Search Variants

----------------------------------------------------------
----------------------------------------------------------

Spyware Doctor :

http://www.freewebtown.com/sphecter/spydoc.exe


Once downloaded install -

Secondly visit this link for a free one year subscription
license:

http://www.pctools.com/spyware-doctor/free/pcuserau/

Once installed and you have entered your license code run
live update to get the most recent spyware defs. Once
updated do a full system scan with Spyware Doctor and
remove anything it finds.

**Note the free licence only works with spyware doctor
3.0 which is posted above,it doesnt work on the latest 3.2

----------------------------------------------------------
----------------------------------------------------------

Trend Micro Anti-Virus (3 month free trial)

http://www.trendmicro.com/offers/ms-wsc/english.asp

----------------------------------------------------------
----------------------------------------------------------

Mcafee Anti virus (3 month free trial)

http://us.mcafee.com/root/landingpages/default.asp?
lpname=ms_mpfp&cid=8437

----------------------------------------------------------
----------------------------------------------------------

Norton Antivirus (3 month free trial)

http://www.symantecstore.com/dr/v2/ec_dynamic.main?
sp=1&pn=47&sid=27674&cache_id=0

----------------------------------------------------------
----------------------------------------------------------



Regards


Andy Manc
 
Thanks Andy,

I think I will run killbox and escan later today to be
sure. I think it is taking a little longer for my
computer to start up. But, I am just a little fearful of
deleting something I need and not being able to restart
the computer.

I normally run Adaware and Spybot frequently but now
realize I would be best to run them in safe mode.
Certainly running Ccleaner and housecall would be better
in safe mode as I suspect they would have been able to
get into many of the files that were they said were
locked.

I used the free version of AVG which is kept updated so I
am not sure how I got this. AVG seemed to recognize the
virus, said it healed it, but did not.

I see from this site:

http://www.windowsforumz.com/Help-Support-Hijacked-
AntiVirus-Gold-ftopict376880.html

That many people have been hit by this and some have not
recognized that AV Gold is just malware and not a real
antivirus program. I wonder how many have sent money to
get the virus fixed.

Thanks again,

Mike
Calgary, Canada

-----Original Message-----



Hi Mike ,

Nice to hear you may be nearly clean again,I did notice
the post by edwin but wanted to make sure its not changed
the registry on yours,If you have your desktop back and
it doesnt switch back when you reboot then hopefully
you've fixed that problem.

With killbox this is quite important to make sure your
system is clean,I remembered you saying in a earlier post
that you searched for some of the bad files and they
appeared but wouldnt let you delete them,then the next
time you searched you couldnt find them

If any of the malware files still exist using killbox
will take them out when you reboot.Killbox is a great
tool for files that just refuse to be deleted,

Most of the names i put should not exist anymore as they
are not showing in the Hijack log its just a way to clean
up and confirm there's no traces left,for example these
entries below that were in your log:

O4 - HKLM\..\Run: [MSN Messenger] C:\WINDOWS\system32
\msmsgs.exe

O4 - HKCU\..\Run: [Intel system tool] C:\WINDOWS\system32
\hookdump.exe

Fixing these with hijack will not remove the file from
c/drive it will delete the registry run command thats
making the file start up when you reboot.Once you fix
them in Hijack this,Its best to enable hidden files and
folders and boot into safe mode then remove the malware
files.With the malware files being in the Windows System
32 folder they are running with Windows so using killbox
could be a easier option to delete all the crap when you
reboot.



If you think your clean again now you may not need to do
this but running Microworlds escan is probably better at
this stage than runnin Ewido again.Escan doesnt delete
malware but its very precise and will let you know if
anything remains.

Microworld's Escan

ftp://ftp.microworldsystems.com/download/tools/mwav.exe


Download to desktop,double click to extract & run .Tick
all possible scan locations ( all folders and all
drives ) then press scan . When its finished scanning it
will display the results in the lower pane.You can copy n
paste that by left clicking and covering all the text
then press Control & C to copy it.


If it says malware was found and you need to pay to
remove it just shut it down and let it carry on
scanning.With the results only remove files your sure
about as Escan will tag anything suspicious as a virus
riskware,Adware and other things like built in tools such
as W32.reboot that AOL and other companies use to reboot
your system when your upgrading their products.


If there's any crap left this scanner should find it for
you but it does take a very long time so only use it if
you think its needed .




To help you stay clean here some links to free programs
that protect your system :
--------------------------------------------------------- -
---------------------------------------------------------
-

Spybot Search & Destroy 1.4

http://fileforum.betanews.com/download/Spybot_Search_and_ D
estroy/1043809773/1

(Use all updates and the immunize feature to block known
malicious sites)
--------------------------------------------------------- -
---------------------------------------------------------
-

Ad-Aware SE


http://www.download.com/Ad-Aware-SE-Personal- Edition/3000-
8022_4-10399602.html?tag=sptlt_s

---------------------------------------------------------
-
---------------------------------------------------------
-

Spyware Blaster

http://downloads.net-
integration.net/spywareblastersetup34.exe

Prevents the installation of ActiveX-based spyware,
adware, browser hijackers, dialers, and other potentially
unwanted pests.
Block spyware/tracking cookies in Internet Explorer and
Mozilla/Firefox.
Restrict the actions of potentially dangerous sites in
Internet Explorer.

--------------------------------------------------------- -
---------------------------------------------------------
-

Spyware Guard


http://www.javacoolsoftware.net/downloads/spywareguardset u
p.exe


SpywareGuard provides a real-time protection solution
against spyware that is a great addition to
SpywareBlaster's protection method.

--------------------------------------------------------- -
---------------------------------------------------------
-

CWShredder

http://cwshredder.net/bin/CWShredder.exe


To remove Cool Web Search Variants

--------------------------------------------------------- -
---------------------------------------------------------
-

Spyware Doctor :

http://www.freewebtown.com/sphecter/spydoc.exe


Once downloaded install -

Secondly visit this link for a free one year subscription
license:

http://www.pctools.com/spyware-doctor/free/pcuserau/

Once installed and you have entered your license code run
live update to get the most recent spyware defs. Once
updated do a full system scan with Spyware Doctor and
remove anything it finds.

**Note the free licence only works with spyware doctor
3.0 which is posted above,it doesnt work on the latest 3.2
---------------------------------------------------------
-
---------------------------------------------------------
-

Trend Micro Anti-Virus (3 month free trial)

http://www.trendmicro.com/offers/ms-wsc/english.asp

--------------------------------------------------------- -
---------------------------------------------------------
-

Mcafee Anti virus (3 month free trial)

http://us.mcafee.com/root/landingpages/default.asp?
lpname=ms_mpfp&cid=8437

--------------------------------------------------------- -
---------------------------------------------------------
-

Norton Antivirus (3 month free trial)

http://www.symantecstore.com/dr/v2/ec_dynamic.main?
sp=1&pn=47&sid=27674&cache_id=0

--------------------------------------------------------- -
---------------------------------------------------------
-



Regards


Andy Manc
.
 
Its like you say mike it does seem to be causing alot of
problems,very similar to the smitfraud virus.Smitfraud
installs Security iguard and then the program keeps
giving you false positives to try trick people into
paying them money plus overwrites the desktop with a
error message thats difficult to remove.

I've not used AGV before but im suprised it let you get
so infected maybe installing a strong firewall would
prevent that happening again.


Here's some good firewall sites if needed (Im not sure if
AGV has a firewall so you may not need these)


http://www.kerio.com/kpf_download.html

http://soho.sygate.com/products/spf_standard.htm

http://www.agnitum.com/download/

http://www.symantecstore.com/dr/sat5/ec_MAIN.Entry16?
V1=648702&PN=1&SP=10023&xid=49997&V5=11031981&S1=&S2=&S3=&
S4=&S5=&V2=&V3=&V4=&DSP=0&CUR=840&PGRP=0&CACHE_ID=0




All The Best



Andy Manc
 
AndyManc presented the following explanation :
Its like you say mike it does seem to be causing alot of
problems,very similar to the smitfraud virus.Smitfraud
installs Security iguard and then the program keeps
giving you false positives to try trick people into
paying them money plus overwrites the desktop with a
error message thats difficult to remove.
I've not used AGV before but im suprised it let you get
so infected maybe installing a strong firewall would
prevent that happening again.

This is a trojan and spyware not a virus I believe, therefore
a lot of users have problem with this.

Here's some good firewall sites if needed (Im not sure if
AGV has a firewall so you may not need these)


http://www.kerio.com/kpf_download.html

http://soho.sygate.com/products/spf_standard.htm

http://www.agnitum.com/download/

http://www.symantecstore.com/dr/sat5/ec_MAIN.Entry16?
V1=648702&PN=1&SP=10023&xid=49997&V5=11031981&S1=&S2=&S3=&
S4=&S5=&V2=&V3=&V4=&DSP=0&CUR=840&PGRP=0&CACHE_ID=0

Must add ZoneAlarm to the list: ;)
http://www.zonelabs.com/store/content/company/products/znalm/freeDownload.jsp

I am very pleased with TrendMicros PCillin for the moment (both virus,
firewall and manual
spyware detection: (not free)

http://www.trendmicro.com/en/products/desktop/pc-cillin/evaluate/overview.htm


A good firewall test:
https://www.grc.com/x/ne.dll?bh0bkyd2
Press "Proceed" and then "Common ports" or "All service ports".
 
Back
Top