Thread: Virus problem?
View Single Post
Old 12-01-2005, 02:41 PM   #12 (permalink)
alba
Analyst, Security Team
 
alba's Avatar
 
Join Date: Feb 2005
Location: Eire
Posts: 2,006
OS: Vista, Ubuntu 8.04


HiYa rachsrib

The error message
Quote:
i still get a pop up saying that there is suspicous activity as well. thanks
Can you tell me what it says or get a screen shot of it
Press the print Screen key, then paste onto a word document and attach to your next post


You do not appear to have an anti-virus application installed on this machine. Let's start off by getting you a free but yet effective antivirus program. Please choose one from any of these 3 programs which are free for home use:
Once the antivirus is downloaded, please update the virus definitions and run a scan.

===============================================

'UNPLUG'/DISCONNECT YOUR COMPUTER FROM THE INTERNET WHEN YOU HAVE FINISHED DOWNLOADING


This webpage would not be available when you're carrying out the fix. Please save the following instructions in Notepad. I have customed my instructions on the assumption that you are using Notepad. It may lead to some confusion should you choose to do otherwise.

If there's anything that you don't understand, kindly ask your questions before proceeding with the fixes. There should not be any opened browsers when you are carrying out the procedures below.



IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.


===============================================


Next, reboot your computer in SafeMode :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.

CLOSE ALL OTHER PROGRAMS & ALL OPENED WINDOWS


Run a scan with HiJackThis & select/tick the following & click "Fix checked" :

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {7A97B913-C0A6-6EAC-43F1-2AC5E32BFB43} - C:\WINDOWS\system32\appxg.dll (file missing)



Please remember to close all other windows, including browsers then click Fix checked.

===============================================

Run CWShredder & click on Fix.


Run About Buster and click OK. Click Start > OK and then follow the prompts to scan (Choose Yes/OK for all). It will ask you if you want a second scan, choose Yes. ONLY save the log file and post it here if About Buster does not fix all the problems.


===============================================


Start HijackThis & Go to Config> Misc Tools > Open ADS Spy
  1. Checkmark/tick - "Ignore Safe System Info Streams"
  2. Click the "Scan" button
  3. When it has finished scanning,
  4. Click the "save log" button

===============================================

REBOOT TO NORMAL MODE

Please go to at least two of these sites and run an online Virus Scan.
Be sure to have the AutoFix box(es) checked.

http://housecall.trendmicro.com/
http://www3.ca.com/virusinfo/virusscan.aspx
http://www.bitdefender.com/scan/license.php
http://us.mcafee.com/root/mfs/default.asp
http://security.symantec.com/sscv6/d...d=ie&venid=sym
http://www3.ca.com/virusinfo/virusscan.aspx

In your next post, please include fresh logs from:
  1. HiJackThis
  2. Online scan logs
  3. About BusterADS Spy.log
  4. ADS Spy.log
  5. Ewido
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now

Regards

alba
__________________


Member of UNITE

If I have helped you in anyway, please DONATE to TSF Go raibh maith agat
alba is offline