Thread: Virus
View Single Post
Old 07-02-2008, 09:09 AM   #21 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,735
OS: 2000 Pro; XP Pro; XP Home


Re: Virus

I don't see any IRC/remote admin clients installed on this machine to explain a possible legit reason for these files:

"C:\WINNT\SYSTEM32\RegUID.exe"
"C:\WINNT\SYSTEM32\shelldll.exe"
"C:\WINNT\SYSTEM32\WinOS.hlp"
"C:\WINNT\SYSTEM32\pnc.exe"
"C:\WINNT\SYSTEM32\psexec.exe"

If there is or has been no IRC/remote admin client on the machine, the above files should be deleted.

The other items found by kaspersky are in Symantec quarantine. Symantec quarantine gets purged on a regular schedule, or you can finally remove the items from within the application.

See if this helps:

http://www.d.umn.edu/itss/security/nav/quarantine.html

Can you explain the freezing in a bit more detail? When does it happen? Is it when using the same application? Startup? Shutdown? Internet?

Some of that may be due to this:
Quote:
Total Physical Memory: 254 MiB (256 MiB recommended).
While Windows 2000 is not as demanding on resources as Windows XP is, modern applications such as an AntiVirus can be. You may find that an additional 256MB of memory, or more, would help the machine immensely.

Also, I'm curious how you came to install SpyHunter on the machine. Though no longer listed, it was once listed on the SpywareWarrior rogueware list, and it seems to show up on infected machines. So, I wonder if you installed it in response to an ad you received while infected.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline  
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here