| | |
help with virus infection...
![]() |
I'm having this problem with one of my computers. I sure its infected with something but i'm not sure what it is, I think it's a trojan. It keeps sending e-mails to randomly generated users to specific servers. i.e. <random>@aol.com. since the e-mail client's smtp server is not set up, it doesn't send any emails but rather displays an error msg. Another thing is, my windows folder is c:\windows but it keeps on creating a c:\winnt\system folder and creates an .exe file with random file names. i usually delete them but sometimes they can't be deleted coz' the files are in use... any help??
BTW, I'm running win2k with SP4 on an Intel p4 and all of the available updates from MS windows update.
BTW, I'm running win2k with SP4 on an Intel p4 and all of the available updates from MS windows update.
Last edited by oalee; Mar 19th, 2004 at 10:35 pm. Reason: incomplete info... 4got to add something...
*-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
Might be an idea to have an online scan, so go to http://housecall.trendmicro.com/ for an on-line scan & set it to autoclean for you.
•
•
•
•
Originally Posted by crunchie
Might be an idea to have an online scan, so go to http://housecall.trendmicro.com/ for an on-line scan & set it to autoclean for you.
*-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
http://www.pandasoftware.com/actives...2.asp?idlang=2
Go here I always recommand it, it's free easy and works go here do a full system scan I also would recommand Spybot & Adaware.
Go here I always recommand it, it's free easy and works go here do a full system scan I also would recommand Spybot & Adaware.
Jimmy
E-Mail - jimmy@fiberops.net
Chief Information Officer (CIO) of FiberOps
E-Mail - jimmy@fiberops.net
Chief Information Officer (CIO) of FiberOps
I think i got rid of it from Trend Micro's housecall... i'll give the pandasoftware a try just to make sure.
I just hate them s2pid ppl who does those things... what do they get from doing that anyway?
•
•
•
•
Originally Posted by Yzk
that really sounds eery, what those people can do, to your personal data...
*-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
oh boy! the same problem just keeps on coming back... any other suggestions???
*-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
*I am the oceans.. Still, still yet always in constant *
*motion.Quiet but never afraid,Silent but always awake*
*And no God nor Man can control where you roam.. no *
*boundaries cast forever you last.... *
*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=*
No guarentees, as it could be a couple things, but please do these:
Download the latest version of Ad-Aware at http://www.lavasoftusa.com/support/download/
After installing AAW, and before running the program, FIRST update the reference file following these instructions.
http://www.lavahelp.com/howto/updref/index.html
Now do the following:
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."
Press "Scan Now"
- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:
Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"
Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.
Finally, close Ad-Aware, and reboot.
Then:
Download 'Hijack This!'. http://www.computercops.biz/downloads-file-328.html
Unzip (extract) it to a folder of its own. Then Doubleclick HijackThis.exe (in the new folder), and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, then Ctrl-A to Select All, and copy its contents here. for hijackthis,most of what it lists will be harmless or even essential, don't fix anything yet.
Download the latest version of Ad-Aware at http://www.lavasoftusa.com/support/download/
After installing AAW, and before running the program, FIRST update the reference file following these instructions.
http://www.lavahelp.com/howto/updref/index.html
Now do the following:
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Scanning Engine:
check: "Unload recognized processes during scanning."
- Under Ad-aware 6 > Settings (Gear at the top) > Tweaks > Cleaning Engine:
Check: "Let Windows remove files in use after reboot."
Press "Scan Now"
- Check option "Use Custom scanning options"
- Check option "Activate In-Depth Scan"
- Press "Select drives\folders to scan"
- Select the active partition which is usually C:
Now press "Next" to let Ad-aware scan your drives...
It will find a number of "bad" files and registry keys.
Right-click in that pane and choose "select all"
Now press "Next" again.
It will ask you whether you'd like to remove all checked items. Click OK.
Finally, close Ad-Aware, and reboot.
Then:
Download 'Hijack This!'. http://www.computercops.biz/downloads-file-328.html
Unzip (extract) it to a folder of its own. Then Doubleclick HijackThis.exe (in the new folder), and hit "Scan".
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, then Ctrl-A to Select All, and copy its contents here. for hijackthis,most of what it lists will be harmless or even essential, don't fix anything yet.
Linux boot cd http://www.knopper.net/knoppix/index-en.html
Good luck buddy they do it to get credit in pissing you off. So we talk about it like we are now. No reward I would love to do something and have everybody every where on radio on TV and on fourms talk about my spyware/virus. That's just me buddy since you seem to be very techy why not a reformat like I always recommand. Unless this is a business we can get into some work arounds. I tend to help people better over voice not text sorry buddy good luck to you keep us informed.
Jimmy
E-Mail - jimmy@fiberops.net
Chief Information Officer (CIO) of FiberOps
E-Mail - jimmy@fiberops.net
Chief Information Officer (CIO) of FiberOps
•
•
•
•
Originally Posted by MAD_DOG
Good luck buddy they do it to get credit in pissing you off. So we talk about it like we are now. No reward I would love to do something and have everybody every where on radio on TV and on fourms talk about my spyware/virus. That's just me buddy since you seem to be very techy why not a reformat like I always recommand. Unless this is a business we can get into some work arounds. I tend to help people better over voice not text sorry buddy good luck to you keep us informed.
Linux boot cd http://www.knopper.net/knoppix/index-en.html
![]() |
Similar Threads
- News Story: FBI email network down for days after virus attack (Network Security)
- News Story: TomTom still not taking satnav virus issue seriously (Network Security)
- virus infection help, please? (Viruses, Spyware and other Nasties)
- Virus invasion (Viruses, Spyware and other Nasties)
Other Threads in the Windows NT / 2000 / XP Forum
- Previous Thread: Changing File Handling in XP
- Next Thread: Error when trying to Uninstall via Add/Remove Programs
| Thread Tools | Search this Thread |
.net 64bit 2007 2010 a.exe address apache appstore arm automatically black blue book bsod bulletin canonical cellphones codeplex computer crash cursor deployment deployments desktop desktops dns dotnetnuke drive eartlink error errors explorer fax features folder fontmanagers format framework freeze hardware home internet interoperability killprocess laptop linux load login mac memory microsoft monitor motionle1600 netbooks novell nvidia open operatingsystems options osx palm patch printer product program proxy reformat remotedesktop repair replacingraiddrive retail retrieve screen security sharepoint simplifiedchinese sitetositevpn slowperformance technology unreadable update usb verizon videodrivers videogames virus vista visual vpn vulnerability wab win win32/heur windows windows7 windowsxp windowsxpnotstartingup. worm xp xpde






