help me solve my virus problem

Reply

Join Date: Aug 2004
Posts: 18
Reputation: awaz_16 is an unknown quantity at this point 
Solved Threads: 0
awaz_16 awaz_16 is offline Offline
Newbie Poster

help me solve my virus problem

 
0
  #1
Feb 22nd, 2005
Hello,
I would be greatful if anyone help me in this matter.
Can anyone tell separate tools for each of the following.
w32.pinfi ,w32.funlove.int, (FOLDER.HTT)VBS.REDLOF.A,
(folder.htt)vbs.redlof.a .

Actually I want to know about specific tool built for each of the above
virus because that tool will be specialist in dealing with that virus and of course of smaller size as it has to deal with only one virus(so it will be easy to download it from net). Please only tell about free tools.

Thank you very much.I am greatful
awaz
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,996
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 756
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: help me solve my virus problem

 
0
  #2
Feb 22nd, 2005
Go here to TrendMicro for an on-line scan & set it to autoclean for you. When it completes, post back the full filename of any files that cannot be cleaned or deleted.

Try this scan at Panda as well.


The scan here does not require an active X install, but uses java instead.
http://fr.trendmicro-europe.com/cons...all_launch.php


Clear out your Temporary internet files and other temp files.
Go to Start > Settings > Control Panel >Internet Options.

Under the General tab click the Delete temporary internet files,
delete all Offline content as well. Clear out Cookies.

Also, go to Start > Find/search > Files or folders > in the named box, type: *.tmp and choose Edit > select all -> File > delete.

Empty/delete the entire contents of the C:\Windows\temp folder and C:\temp folder, if you have one. (Contents but not the folder itself.)

This one too if Win2K or XP.
C:\Documents and Settings\username\Local Settings\Temp\

In order to view these files you may have to select 'show hidden files/folders.' Instructions on how to here.

Empty the Recycle Bin.

Download HijackThis from here & it will install into it's own, permanent folder.
If you have anything disabled in MsConfig, please re-enable it/them and reboot.
Start HJT & press the "Do a system scan and save a log file" button. When the scan is finished a window will pop up giving you the option of where to save it. Save it to desktop where it is easy to access. Open the log file and copy the entire contents of the file & paste it into the body of your post. DO NOT FIX ANYTHING YET. Most of what is there is necessary for the running of your system.
Reply With Quote Quick reply to this message  
Join Date: Aug 2004
Posts: 18
Reputation: awaz_16 is an unknown quantity at this point 
Solved Threads: 0
awaz_16 awaz_16 is offline Offline
Newbie Poster

Re: help me solve my virus problem

 
0
  #3
Feb 22nd, 2005
thank you sir,
I will report after doing what you have said.
awaz
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,996
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 756
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: help me solve my virus problem

 
0
  #4
Feb 22nd, 2005
OK. I am off to bed now, so if no-one else can assist you. I will get back to you tomorrow .
Reply With Quote Quick reply to this message  
Join Date: Aug 2004
Posts: 18
Reputation: awaz_16 is an unknown quantity at this point 
Solved Threads: 0
awaz_16 awaz_16 is offline Offline
Newbie Poster

Re: help me solve my virus problem

 
0
  #5
Feb 22nd, 2005
Sir I have scanned using online trend micro.
PE Parite.A,PE Funlove.4099 and worm Bagle.H were found.1203 files were infected mostly from drive d and e.Many files are cleaned by trendmicro but system is still infected.
The trend micro scan box is still open before me with all the virus and their files. There is a delete button.Should I delete all the selected 1203 files and viruses shown in box that scanned.


I will be greatful if you help me
awaz
Reply With Quote Quick reply to this message  
Join Date: Aug 2004
Posts: 18
Reputation: awaz_16 is an unknown quantity at this point 
Solved Threads: 0
awaz_16 awaz_16 is offline Offline
Newbie Poster

virus help needed

 
0
  #6
Feb 22nd, 2005
Sir I have scanned using online trend micro.
PE Parite.A,PE Funlove.4099 and worm Bagle.H were found.1203 files were infected mostly from drive d and e.Many files are cleaned by trendmicro but system is still infected.
The trend micro scan box is still open before me with all the virus and their files. There is a delete button.Should I delete all the selected 1203 files and viruses shown in box that scanned.


I will be greatful if you help me
awaz
Reply With Quote Quick reply to this message  
Join Date: Aug 2004
Posts: 18
Reputation: awaz_16 is an unknown quantity at this point 
Solved Threads: 0
awaz_16 awaz_16 is offline Offline
Newbie Poster

Re: help me solve my virus problem

 
0
  #7
Feb 22nd, 2005
Here is my hijack after deleting Worm Bagle.H and 250 clean files.
Some files are still infected. A large number of them are cleaned.
Thank you.

Logfile of HijackThis v1.99.1
Scan saved at 1:30:18 AM, on 2/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\awais\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1F790CA-3CFC-423C-8618-830CF1CE93A7}: NameServer = 202.163.96.3 202.163.96.4
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Reply With Quote Quick reply to this message  
Join Date: Aug 2004
Posts: 18
Reputation: awaz_16 is an unknown quantity at this point 
Solved Threads: 0
awaz_16 awaz_16 is offline Offline
Newbie Poster

Re: help me solve my virus problem

 
0
  #8
Feb 22nd, 2005
I am sorry for being a nonesense as it is my first help on virus issues
Reply With Quote Quick reply to this message  
Join Date: Aug 2004
Posts: 18
Reputation: awaz_16 is an unknown quantity at this point 
Solved Threads: 0
awaz_16 awaz_16 is offline Offline
Newbie Poster

Re: help me solve my virus problem

 
0
  #9
Feb 22nd, 2005
I am sorry for committing mistakes in forum as it is my first help on virus issues
Reply With Quote Quick reply to this message  
Join Date: Feb 2004
Posts: 9,996
Reputation: crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold crunchie is a splendid one to behold 
Solved Threads: 756
Moderator
Featured Poster
crunchie's Avatar
crunchie crunchie is offline Offline
Spyware Killer

Re: help me solve my virus problem

 
0
  #10
Feb 22nd, 2005
Do not worry, you have done no wrong . Try updating Norton on your PC and do a full system scan and see if that cleans it up.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum
Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC