PDA

View Full Version : oh well....



gela
09-16-2004, 09:41 AM
...seems that my system has a virus. first my norton internet security shut down itself and since then I'm unable to either uninstall or reactivate it again. plus my IE shuts down itself every time I try to contact the Windows Update site or various sites like Kaspersky, Ad-Aware update etc.
I fear it's a worm maybe, but I don't know if it will help if I format my HD or if I will keep this fucking virus/worm/whatever :evil: . anyone any suggestions please???

gela

logan
09-16-2004, 02:13 PM
Gela if you can connect to this site (its Nortons site) you can check your system http://securityresponse.symantec.com
click "check for security risks" button....then "start" virus detection.

Hope this helps

insight
09-16-2004, 07:51 PM
gela,

A light bulb has turned on. Your computer is compromised by a VERM.

Here are a few things to do. Goto the run box and run "msconfig." Click off all the check boxes under startup. Restart. Run an online virus scan at
http://housecall.trendmicro.com/

You may have a worm, that is a variant and, not identified by any virus scanner. In that case, don't spend lots of unproductive time playing with the worm. Start over by deleting your partition.
:idea:

mayaxiong
09-16-2004, 10:37 PM
I had the same worm, it's a Trojan, it makes your IE non-workable but doesnt affect other browsers like Netscape or the Lexx browser.

Windows has a site that has a list of worms that can be fixed with a patch from them direct. Go there and look for the virus scan detector, it will tell you what you have and how to get rid of it, if it can. If not, you will have to go into your System Restore Temp files, and registry and manually delete the files,(the scan will tell you the name of the worm and exactly which files are affected) dont' click off all the stuff in your startup folder in msconfig before you do this.

After that, disable the system restore function since the worms use that to multiply...If you have to use Mozilla or netscape to get there, its ok, if those dont work, try the Lexx browser, it's built on an IE platform and isnt affected by the worm, it should allow you to download the patches.

I learned the hard way, mine cost me a bundle to extract because it cut right thru my Norton ( a useless program if you ask me) and there was no patch for mine, which was a bitch to get rid of.
I'd recommend Zone Alarm or PC cillin for virus programs, but PC cillin DOES affect you getting into your IRC programs since it has a bitch of a firewall..

Good luck

gela
09-16-2004, 11:39 PM
thank you very much for your kind help, both insight and maya! oh yeah I figured that a virus or worm could be the reason for my problems. I must admit I never had one, it's the very first time, so I am a bit helpless :( . it went worse later when I was online...IE closed itself all the time, no update site works anymore, ICQ shuts down itself as well and when I started to chat with Dee last night I noticed that Yahoo Messenger only gave me blank boxes, so I couldn't even chat with him that way. I shut down the system and plugged in my daughters computer to chat... lol. it's not infected (yet). I have installed Norton Internet Security 2004 to her system before I went online, then did the liveupdate as soon as I was on. I know it's not the best program but what can I do....zonealarm doesn't work for me - some of my d/l programs (nudge nudge say no more) don't work with it, no matter what I try. I have nearly finished all backups from my HD - I didn't know I had such a big music collection and programs installed, lol. I hope I haven't copied the worm to any of my CDs. I will format my HD later this afternoon. :(
oh yes, I tried the windows update page and the virus detection links... as I can't use IE for that I am having trouble using Netscape because the Windows site keeps telling me it needs IE for some checkups :(. Netscape is my default browser, btw, for many many years already. I didn't know there's a lexx browser btw :oops: ...
I hope a format c:*.* will help to clean my HD, if not I am most definitely fucked up, lol.

btw, I'm glad you sorted out your own trouble, maya ;).

gela

XS4Xevr
09-16-2004, 11:53 PM
Hi Gela! The LEXX Browser is by NEOPLANET and is one of the Many Skins for their Browser, btw. ( http://www.neoplanet.com )

'Norton Internet Security + Norton Anti-virus' appear to work well for me so far -except you have to keep the "Virus Defintions" CURRENT and they always STRESS that, because if you fall far behind, your antivirus program may not be able to block the latest viruses, since it uses the definition files to recognize viruses.

I debated if I should add the following but combating Viruses is just too important and is just like fighting another form of Terrorism: ~ Even if your "Subscription" expires you can still install the lastest definitions. BTW http://www.sarc.com is the exact same NORTON site as http://securityresponse.symantec.com/ and the pages are exactly identical. To keep your virus definitions current click "Download Virus Definitions" on either of the above pages. On the NEXT page click "Download Virus Definitions (Intelligent Updater Only)". On the page that follows after that click on the Button "Download Updates" it takes you to yet another page. There is listed an approximately 5 megabyte file you can download (today's is "20040916-018-i32.exe" which you can tell is the date of file "2004 09 16 ...exe). Once you download it, if you double-click it and it says your subscription is expired, simply click the TIME in your system tray to bring up the "DATE and TIME" dialog box and change the year back a few to about when you first installed your Anti-Virus. If you have gone back far enough the file WILL install and your definitions will be current. These change daily and it is probably a good idea to update your definitions weekly or bi-weekly. Before you forget, IMMEDIATELY reset your DATE to the Correct Year. (Viruses are acts of aggression and are Terrorism against the Public. IMHO if you can afford to pay for their subscription service perhaps it is a good idea to show support, but if your finances are too tight you shouldn't be left out in the cold to be shot to death by the terrorists. IMHO)

NOTE: If you use the "Check for Security Risks" it will stop after finding 99 infected files. It just stops. It doesn't mean you only had 99 (btw, one of my experiences). You have to manually delete those 99 and run the scan again and again until the Blood runs CLEAR. (I had a case where a virus made about 2 dozens copies of itself in a folder and copied those dozens to over a dozen other places, other folders for a grand total of several hundred infected files. I eventually did get them all but don't think that 99 is all there is just because the program stops there at 99.)

gela
09-17-2004, 12:16 AM
thank you very much, XS4Xevr!!! I will check that later when I'm at home :). a Lexx browser, sounds great :D.
I should mention that I ALWAYS kept my virus definitions current; I use the automatic liveupdate and sometimes even click on liveupdate manually just to make sure my system is perfectly protected by the latest virus definitions. while ppl had infections by this virus that kept shutting down systems every 30 seconds (or so) my system was safe, and as I said before, I NEVER had any worms etc. I also NEVER went online without having my firewall on. that's why I am so desperate :(. I will see if I can sort it out without formatting my HD then.... what else could happen than a system crash - after all, my HD is already fucked up, lol. I just have to do a backup of 2 more files and then I don't care for anything that's on my HD anymore, so I can "play" a bit ;). I never edited the registry before so I am not sure if I'll be sucessful or not. I will see if I can clean my system without deleting everything, if not, there's still my Windows XP Installation CD waiting for me to format evreything ;). I hope eva (my daughter) allows me to use her computer for some more days ;). (did I ever mention that I love her computer? it's much slower than mine but ALWAYS works perfectly, lol.)

anyway, thanks so much for your help too, I will print out everything to use it later at home :).

gela

XS4Xevr
09-17-2004, 09:24 AM
P.S.
You didn't by chance notice if you had just installed "WINDOWS XP SERVICE PACK 2" or perhaps your computer did automatically, did you?

I was just checking updates to XP at work and came across some major issues including programs that have altered or changed performance with specifically XP Service pack 2.

Every program on your list (except windows update) is at:
http://support.microsoft.com/default.aspx?kbid=884130&product=windowsxpsp2
Entitiled: "Programs that are known to experience a loss of functionality when they run on a Windows XP Service Pack 2-based computer"

The main page for the Service Pack:
http://support.microsoft.com/default.aspx?scid=fh;ln;xpsp2swhw

"To help provide security for your Windows XP SP2-based computer, Windows Firewall blocks unsolicited connections to your computer. However, sometimes you might want to make an exception and permit someone to connect to your computer. For example, the following scenarios describe occasions when you might want someone to be able to connect to your computer:
You are playing a multiplayer game over the Internet.
You are expecting to receive a file that is sent through an instant message program.
After you install Windows XP SP2, client applications may not successfully receive data from a server. Following are some examples:
An FTP client
Multimedia streaming software
New mail notifications in some e-mail programs
Alternatively, server applications that are running on a Windows XP SP2-based computer may not respond to client requests. Following are some examples:
A Web server such as Internet Information Services (IIS)
Remote Desktop
File Sharing"

If you want to look at something really scary look at the BUG FIXES page for Windows XP Service Pack 2 and look at the super long, long, long, really long list:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;811113

I am downloading the single executable file version of the SP2 and it is 266 megabytes!!!! (I will be reading more into it to see if I really want to do that final double-click to run it!)

gela
09-17-2004, 09:28 AM
helllo XS4Xevr,

nope, I never downloaded or installed SP2. I avoided to do so ;). I checked my system and it still says Win XP SP1 :D.

gela

p.s. tonight I'm going to visit a friend, he said he'll be able to fix my system. I really hope so...if not we're going to format the HD. I will show him the suggestions you all kindly posted :)

ILyekkaKai
09-20-2004, 04:32 PM
Heya XS4Xevr,
Man, I downloaded that service pack2...it startred to screw my things up on here so I did a system restore and it seemed to take care of the problem*crosses fingers*

and Gela,
..how did you check your system to see if you still had WIN XP SP1?

gela
09-20-2004, 10:45 PM
and Gela,
..how did you check your system to see if you still had WIN XP SP1?

I use "TuneUp Utilities 2004" to optimize my HD, clean the Registry etc etc and also to check what hardware I use. but you also find this information in your control panel :). if you click on "system" (I think) you'll get a page telling you your current WIN version etc. (I have WIN NT at work so I'm not quite sure right now if it was "system" but I think so ;). I still use WIN XP SP1 and I'm not going to change that (not until they have a final SP2 version out that is absolutely bug free...which will prolly never happen, sooooo...I'll stick with my SP1 ;))

gela

ILyekkaKai
09-20-2004, 10:58 PM
Thank you very much, Gela :-D ....
...I looked and to my relief, I still have my SP1 :-D

...good thing I did a system restore :P

gela
09-20-2004, 11:00 PM
Thank you very much, Gela :-D ....
...I looked and to my relief, I still have my SP1 :-D

...good thing I did a system restore :P

hi ILK,
glad to hear that ;). yeah, I think that's the only way to get rid of SP2, right ;)...

gela

ILyekkaKai
09-20-2004, 11:05 PM
Thank you very much, Gela :-D ....
...I looked and to my relief, I still have my SP1 :-D

...good thing I did a system restore :P

hi ILK,
glad to hear that ;). yeah, I think that's the only way to get rid of SP2, right ;)...

gela

Hi Gela :-D
..I was'nt sure if it would work, but I did know I did'nt like the SP2 and wanted it gone fast :wink: :P :evil: