Forum index / Computers / Virus

Virus

20 posts · page 1 of 1

post #1
26 April 2005, 09:13 UTC#1
I got this real nasty virus. Not sure where I got it from...but its fucking my computer up real bad.

I've tried scanning for it with Norton in safe mode and I cant find it. Ive update definitions and everything, so I dont know why Norton can detect it.

Ive tried using those online scanners and they cant find anything either.

It started off just making my computer lagging. Then it started fucking with all my programs. Like when I would click a shortcut to Premiere...my computer would ask "what program would you like to use to open this". So instead of clicking the shortcut, I went straight to the exe file and it said the same thing. One by one it disabled all my programs. My friend told me that the virus probally got into windows.

I reinstalled windows. It seemed like the virus was gone. But it isnt. I got Norton to work again...and as long as I have norton running..the virus doesnt seem to be doing anything. My internet is pretty laggy.

Does anyone know what virus I have or how the fuck to get rid of it? Also...I was gonna copy my video files to an external drive. When I plug the drive into another computer I'm gonna scan it before I copy any of the files...but will Norton even be able to detect it...cause so far nothing has been able to. Thanks for whatever help you guys got.
post #2
26 April 2005, 09:25 UTC#2
my uncle printed me info on a new super virus, it cant be detected yet, but slowly kills off programs and parts of windows, and finaly distroys the harddrive, so it can never been used again, so it sounds like you may have that one. did you open an email from someone you knew and the email was empty?

if I was you I would back up all the shit you need and reformat and just hope you havnt saved it along with your files. or maybe wait till they can kil the virus
post #3
26 April 2005, 09:38 UTC#3
thats one nasty shit there
post #4
26 April 2005, 10:02 UTC#4
yeah im gonna reformat as soon as I get an external drive. But no I didnt open any emails like that as far as I remember. Last thing I remember doing before I got a virus is watching that stupid flash video that tells you your an idiot. But I dont think that is what gave me the virus.
post #5
26 April 2005, 10:25 UTC#5
It could of been, I got a virus from that. Cant remember what virus it was though. AVG picked it up and deleted it
post #6
26 April 2005, 10:35 UTC#6
I'd suggest that you not just reformat the HDD but also delete the partion(s) and recreate it(them). If you have more than one partition you should change the size ratio by a few MB.

Overwriting the complete HDD from a clean read-only boot device would be better, even if it takes much time. 'Killdisk' is such a program: Killdisk download page
If have only used the floppy disk version which worked fine apart from not finding the S-ATA HDDs. Maybe the boot CD version is better. For deleting you should select the root device in the menu not just a partition. Of course you should create the boot disk or CD with a clean PC.

An alternative could be making a low level format if your BIOS capable to do so.
post #7
26 April 2005, 11:26 UTC#7
QUOTE (Jules Winfield @ Apr 26 2005, 12:35 PM) I'd suggest that you not just reformat the HDD but also delete the partion(s) and recreate it(them). If you have more than one partition you should change the size ratio by a few MB.

Overwriting the complete HDD from a clean read-only boot device would be better, even if it takes much time. 'Killdisk' is such a program: Killdisk download page
If have only used the floppy disk version which worked fine apart from not finding the S-ATA HDDs. Maybe the boot CD version is better. For deleting you should select the root device in the menu not just a partition. Of course you should create the boot disk or CD with a clean PC.

An alternative could be making a low level format if your BIOS capable to do so.

Sounds good, he has ATA hardrives I believe, so the SATA problem won't affect him and older BIOS' are not capable of "low level formatting"

But yeah, do as Jules said and delete the partitions and recreate them, the virus could be in the boot sector of the drive which can cause immense slow downs, I once had that problem.

Alternatively, get that gateway ASAP biggrin.gif
post #8
26 April 2005, 11:45 UTC#8
yeah I actually tried to reformat my computer and I deleted the partitions and recreated them...or so I thought. When when I finished reinstalling windows nothing had been deleted. All my programs were uninstalled though. I guess I did it wrong.

I dont have the cd key for windows and its gonna expire soon. I also would like to buy an external hard drive and copy my video files before I try to reformat it again.

When I bought this computer at best buy the clerk was all cool and gave me a free warranty and some other shit for free when the manager wasnt looking. I think I'm just gonna take the computer in and have them deal with it. Thanks for the advice.
post #9
26 April 2005, 11:54 UTC#9
I once had that happen to me, after reinstalling my shit was still on the HDD biggrin.gif

If you have those coupons you may as well use them
post #12
26 April 2005, 12:01 UTC#12
QUOTE (gman @ Apr 26 2005, 11:59 AM) QUOTE (T0M @ Apr 26 2005, 01:58 PM) I had a bad virus a week before the faceoff video was due. Therefore I had to go buy a new HD and put all my footage from my cam onto my pc in a week. Thus why our faceoff video was 1-2 hours late. Shit happens....

Man, I missed HGF. If anyone really didnt noticed, I was gone for almost a week  External image not preserved — inspect source: http://homegrownforums.com/html/emoticons/Copy of unsure.gif

<3
post #13
26 April 2005, 12:27 UTC#13
it's a good idea to let the dealer do the job. hopefully they do not say a virus is a self-inflicted problem so that there might be no warranty.

'boot sector' in gman's post was a catchword bringing up another idea.
with the command 'fixmbr' you can re-wrtite the master boot record. this should not affect the data on the disk including the windows and the programs. I used it once to remove a Linux boot manager and data was not lost. but no warranty from me about that External image not preserved — inspect source: http://homegrownforums.com/html/emoticons/Copy of happy.gif

'fixboot' re-writes the boot sector - not sure what effect that has to the data

these commands can be called from the Recovery Console which might be reached by booting from the XP CD and select 'repair' (not sure if that term translates literally into the english version).

the usage of the commands is
fixmbr [device_name] - I. e. fixmbr \Device\HardDisk0 if you have 1 HDD or booting from the 1st
fixboot [drive] - I.e. fixboot c: if the infected system is on c:

cf. M$ fixmbr
and M$ fixboot

edit: how to access the Recovery Console
post #14
26 April 2005, 12:55 UTC#14
Nice to see I'm not the only computer literate person around here anymore biggrin.gif
post #15
26 April 2005, 13:11 UTC#15
yeah, a problem shared is a problem halved biggrin.gif
post #16
26 April 2005, 13:16 UTC#16
thanks for the tips, its appreciated.
post #17
26 April 2005, 13:31 UTC#17
download hijackthis.exe and post your lig here so I can help :)
post #18
26 April 2005, 13:35 UTC#18
k awesome. brb
post #19
26 April 2005, 13:39 UTC#19
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\Symantec Shared\ccProxy.exe
D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
D:\Program Files\BroadJump\Client Foundation\CFD.exe
D:\Program Files\Yahoo!\browser\ybrwicon.exe
D:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
D:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
D:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
D:\WINDOWS\System32\RUNDLL32.exe
D:\Program Files\Common Files\Symantec Shared\ccApp.exe
D:\PROGRA~1\Yahoo!\browser\ycommon.exe
D:\WINDOWS\ALCXMNTR.EXE
D:\Program Files\Messenger\msmsgs.exe
D:\PROGRA~1\Yahoo!\MESSEN~1\YPAGER.EXE
D:\WINDOWS\System32\wpabaln.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Documents and Settings\Jason Low\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = [IP address redacted]
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - D:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - D:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [BJCFD] D:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] D:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightLAN 01] "D:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 01] "D:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] D:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "D:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [ccApp] "D:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] D:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] D:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [MSConfig] D:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: &AIM Search - res://D:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - D:\WINDOWS\web\related.htm
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - D:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - http://files.member.yahoo.com/dl/installs/sbc/yinst.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secur...loadManager.ocx
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - D:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - D:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe