Welcome to the Australian Ford Forums forum.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and inserts advertising. By joining our free community you will have access to post topics, communicate privately with other members, respond to polls, upload content and access many other special features without post based advertising banners. Registration is simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Please Note: All new registrations go through a manual approval queue to keep spammers out. This is checked twice each day so there will be a delay before your registration is activated.

Go Back   Australian Ford Forums > General Topics > Non Ford Related Community Forums > The Bar

The Bar For non Automotive Related Chat

Reply
 
Thread Tools Display Modes
Old 06-11-2007, 10:13 PM   #1
private9
www.TUFFCARPARTS.com
 
private9's Avatar
 
Join Date: Feb 2006
Posts: 5,221
Default Help please! I think I've got a computer virus but it's not being picked up by AV

Hi All,

Hoping for some help please!

A couple of days ago got a random message box pop up saying I had a worm/virus. Normally I don't click these (but have never had any on this computer, and it looked very authentic!)

So I clicked ok to whatever it said, and now internet explorer just keeps trying to connect to a heap of random anti-virus sites, and it does this continuously if I leave the computer going. I'm also getting constant windows style popups warning of infections, security risks and so on, and my computer is now running extremely slow.

3 icons for antivirus/malware/spyware cleaners have appeared on my desktop, and although I have tried deleting, they reinstall themselves within about 20 minutes of running.

I have also found that my windows task manager (ctrl, alt, del) has been disabled (says, disabled by your system administrator).

Obviously there's something not good going on, but I have run AVG and CA antivirus twice each, and neither has picked anything up.

I have disabled internet explorer (now using firefox) so at least when internet explorer opens, it can't actually connect to the websites it's trying to access.

Would really appreciate any advice anyone has to offer!

Thanks,

Justin.

private9 is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 10:28 PM   #2
Fev
FF.Com.Au Hardcore
 
Fev's Avatar
 
Join Date: Feb 2007
Location: Cattai, Sydney
Posts: 7,701
Default

if you cant find the actual files for the virus which would most probably be in your program files.. re format.. because if you do business on your computer with banking etc if may steal your numbers etc and send them somewhere ie saudi arabia etc and they will steal your account/money etc.. so disconnect it from the next at all times and look around for oddly named files in the program files. delete them if you can, if not you will need to format the computer(which is a )
__________________
1992 EBII Fairmont Ghia 4.0l <---Click for the Gallery!
Insta@mooneye_ghia
White on bright red smoothies with thick whitewalls. Cruising around to some rockabilly
Fev is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 10:30 PM   #3
the_scotsman
MY21.5 Mustang GT
 
the_scotsman's Avatar
 
Join Date: Dec 2004
Location: Shoalhaven, NSW
Posts: 2,450
Default

It sounds more like spyware/adware rather than a virus.

Try running Spybot...it should pik it up and get rid of it.

EDIT: although, it does sound like a virus that has disabled Task manager.
__________________
2021 Mustang GT in Rapid Red | XDA-Developers Assistant Admin
the_scotsman is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 10:45 PM   #4
R0BD0G
FF.Com.Au Hardcore
 
R0BD0G's Avatar
 
Join Date: Feb 2006
Location: Toowoomba
Posts: 2,634
Default

spybot...such a champ program...picked up what avg didnt
__________________
1628 Escort Project Thread
67.3 RWHP - Paramount Performance Dyno
DJ Automotive Tuned with proper jets


http://fordforums.com.au/showthread....4&page=1&pp=25
R0BD0G is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 10:52 PM   #5
paule11
FF.Com.Au Hardcore
 
Join Date: Apr 2007
Location: Townsville
Posts: 1,167
Default

This happened to someone I know same thing trojan got on the computer and then popups for anti virus sites asking for $60 to download antivirus to fix it not reputable
virus sites like norton or macafee etc . The money was paid but it didnt fix the virus try going to norton and find if there is any examples of what is happening to your comnputer on there usually they have information on how to fix your registry and remove the virus and in the past I have downloaded virus removal tools from them . A lot of porn sites bring up those warnings about viruses and then download trojan horses which point you in the direction of fake expensive antivirus sites
paule11 is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 10:58 PM   #6
Nashy86
Regular Member
 
Nashy86's Avatar
 
Join Date: Apr 2006
Location: Eastern Melb.
Posts: 346
Default

Quote:
Originally Posted by Fev
if you cant find the actual files for the virus which would most probably be in your program files.. re format.. because if you do business on your computer with banking etc if may steal your numbers etc and send them somewhere ie saudi arabia etc and they will steal your account/money etc.. so disconnect it from the next at all times and look around for oddly named files in the program files. delete them if you can, if not you will need to format the computer(which is a )
Be careful deleting program files tho, on my old laptop my anti virus (one that I'd actually paid $100 per year to license) started going crazy about this file it had found, but it couldn't delete it so it just kept going crazy. So I went and got the info about the file from it, the file was called something like mr.vgina so I immediately thought "yep its a smart *** virus for sure, no real program would have a file with a name that was so close to mr vagina" so I deleted it. My computer automatically re-booted and the startup process had changed so that it said it was deleting this file (it deleted it while in DOS basically) and the computer was then unable to start windows, I ended up having to re-format it. I did some research later on and found it was actually just an inappropriately named file that was needed by the computer, and it was also re-installed with the re-format.

Why my anti virus started going crazy over it I have no idea, it never did it again, and it was the only file identified by the anti virus too
__________________
FG Mk II XR6T
Lightning Strike, 6 Speed Manual, Dark Tint
Best Toy Ever!
Written off whilst parked!


FG Mk II XR6T
Lightning Strike, 6 Speed Auto,, Dark Tint
Awesome toy for Grown Ups!
Nashy86 is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 11:00 PM   #7
fmc351
let it burn
 
Join Date: Feb 2006
Location: QUEENSLANDER!!!!!
Posts: 2,866
Default

Download

- spybot &
- AdAware SE

Also get CClean to go through your registry. All are free programs.

CClean also has a fuction for deleting files with a nice algorithm overwrite to actually delete their traces. They cant be found by tech savvy people.
fmc351 is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 11:12 PM   #8
DBourne
FF.Com.Au Hardcore
 
DBourne's Avatar
 
Join Date: Mar 2007
Location: sydney.nsw.au
Posts: 6,119
Default

mate, the fact that task manager is gone is a bad bad bad thing.
honestly blow away the OS. its not worth having traces of whatever is on there at the moment hanging around.

had the same on my missus pc thanks to her brother. just backed up what was needed in safe mode to a USB key and then formatted. 1hr re format beats hours of d1cking around and then being paranoid any day
__________________
flickr
DBourne is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 11:43 PM   #9
sarrge2001
SZII in Silhouette
 
sarrge2001's Avatar
 
Join Date: Jul 2005
Location: Darwin NT
Posts: 600
Default

Been there, done that.....

The one I got was called Spy Sherrif - or something similar - VERY nasty piece of work.......apparently the way it works is to instal its own viruses and then detect it and offer to remove it after you have paid your money. These viruses go to work on your computer as well and disable the task manager and usually the virus protection.

After numerous attempts by the guru's at work after which it would just reinstall itself, we ended up doing the re-format.

No fun at all!!

If you can find out what the program is called, you can run a search in Google on how to remove it but it is fairly complex and not always successful.


Good luck......
__________________
.
.

Strangers have the best candy.......
sarrge2001 is offline   Reply With Quote Multi-Quote with this Post
Old 06-11-2007, 11:57 PM   #10
private9
www.TUFFCARPARTS.com
 
private9's Avatar
 
Join Date: Feb 2006
Posts: 5,221
Default

Thanks for all the advice guys very much appreciated.

Running spybot and cclean now. Have been searching through program files, and did find one component of it (just somehow changed my wallpaper to an active link to one of these websites.) so I've deleted that part in my windows files, but the other problems are still occurring.

I think it's best that I don't connect to the internet until I get this sorted, but I'll check this thread at work in the morning.

I would love to reformat, but I have absolutely no idea on how to do it! I think that it definitely should be done though, so was going to take the laptop to a computer place in the next few days to get it done.

Thanks,

Justin.
private9 is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 12:02 AM   #11
fmc351
let it burn
 
Join Date: Feb 2006
Location: QUEENSLANDER!!!!!
Posts: 2,866
Default

Quote:
Originally Posted by private9
Thanks for all the advice guys very much appreciated.

Running spybot and cclean now. Have been searching through program files, and did find one component of it (just somehow changed my wallpaper to an active link to one of these websites.) so I've deleted that part in my windows files, but the other problems are still occurring.

I think it's best that I don't connect to the internet until I get this sorted, but I'll check this thread at work in the morning.

I would love to reformat, but I have absolutely no idea on how to do it! I think that it definitely should be done though, so was going to take the laptop to a computer place in the next few days to get it done.

Thanks,

Justin.
Run AdAware too. There are things spybot doesnt find occasionally that AdAware does, and vice versa. Regularly running these together you should have very few problems.
fmc351 is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 12:10 AM   #12
private9
www.TUFFCARPARTS.com
 
private9's Avatar
 
Join Date: Feb 2006
Posts: 5,221
Default

Quote:
Originally Posted by fmc351
Run AdAware too. There are things spybot doesnt find occasionally that AdAware does, and vice versa. Regularly running these together you should have very few problems.
Cool, downloading now! Thanks!
private9 is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 12:26 AM   #13
dave351cid
playing in my big shed
 
dave351cid's Avatar
 
Join Date: Sep 2005
Location: miriam vale , qld
Posts: 3,302
Default

i had the same thing happen last week with the pop ups warning of a virus or something.

i use AVG anti virus free edition and this is the first time i have had any of these bugs get through.

i also run SPYBOT and ADAWARE every month or so just to be sure.
i gave both of these a run and have`nt had any more issues.
__________________
`75 XB FAIRMONT sedan . mushroom beige, injected 351, toploader, 9inch
`10 FG XR50 Turbo ute. Nitro blue, 6 sp Auto, Leather trim.
`04 BA RTV tray back, Red, V8 auto,
`04 BA XR6 Turbo sedan. Blueprint. auto, Leather trim.
`03 BA XLS ute . Acid Rush, factory lpg, auto,
`48 TEA20 Grey Ferguson,
`62 Willys 6-230 , 4x4 light truck
`04 Yamaha TTR 250
dave351cid is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 12:47 AM   #14
fmc351
let it burn
 
Join Date: Feb 2006
Location: QUEENSLANDER!!!!!
Posts: 2,866
Default

Quote:
Originally Posted by dave351cid
i had the same thing happen last week with the pop ups warning of a virus or something.

i use AVG anti virus free edition and this is the first time i have had any of these bugs get through.

i also run SPYBOT and ADAWARE every month or so just to be sure.
i gave both of these a run and have`nt had any more issues.
AVG picks up virus' and trojans etc. These things are 'spyware' or 'malware' which are different ballgames and AVG isnt designed to pick them up, although I believe the pro version does.

spybot and AdAawre are designed for that, they dont pick up virus' or trojans.

Its why you run all 3.
fmc351 is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 07:39 AM   #15
DBourne
FF.Com.Au Hardcore
 
DBourne's Avatar
 
Join Date: Mar 2007
Location: sydney.nsw.au
Posts: 6,119
Default

Quote:
Originally Posted by private9

I would love to reformat, but I have absolutely no idea on how to do it! I think that it definitely should be done though, so was going to take the laptop to a computer place in the next few days to get it done.

Thanks,

Justin.
hey mate, reformatting is really, really simple.

Boot up in safe mode and just transfer any files u want to keep to either another computer or portable hard drive.

restart

put in windows xp (assuming you're running xp) and press a key to boot to cd (you'll see that instruction).

then follow the prompts to install a NEW (not repair) version of windows.

1hr later.. done! you have a brand new system
__________________
flickr
DBourne is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 07:51 AM   #16
crochunter
440cube Dart
 
crochunter's Avatar
 
Join Date: Sep 2006
Location: Australia
Posts: 956
Default

Easiest way is do a system restore. Just go back to a date where computer was working fine.
__________________
Facebook
crochunter is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 07:53 AM   #17
DBourne
FF.Com.Au Hardcore
 
DBourne's Avatar
 
Join Date: Mar 2007
Location: sydney.nsw.au
Posts: 6,119
Default

thats assuming he has a restore point...also he'd still have to back up what he wants
__________________
flickr
DBourne is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 08:06 AM   #18
the_scotsman
MY21.5 Mustang GT
 
the_scotsman's Avatar
 
Join Date: Dec 2004
Location: Shoalhaven, NSW
Posts: 2,450
Default

I'd also just back up anything you want kept, then format and reinstall.

I always point people to this guide for doing a format/reinstall of XP:

http://web.mit.edu/ist/products/winx...ll-format.html

It has screenshots etc to help make it very easy to understand.

EDIT: Restore points can also store the virus...so I wouldn't do that.
__________________
2021 Mustang GT in Rapid Red | XDA-Developers Assistant Admin
the_scotsman is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 09:03 AM   #19
MYVYSS
Back where I belong
 
MYVYSS's Avatar
 
Join Date: Jan 2005
Location: Mexico - Victoria
Posts: 947
Default

Run a program called Housecall by Trendmicro, its one of the best on the net thats free, it could take up to a couple of hours to run...

http://housecall.trendmicro.com/ if this doesnt pick it up and or remove it then you would be looking at a re format...
__________________
Regards

Craig
MYVYSS is offline   Reply With Quote Multi-Quote with this Post
Old 07-11-2007, 10:06 AM   #20
Perana
FF.Com.Au Hardcore
 
Perana's Avatar
 
Join Date: Dec 2004
Location: South Australia
Posts: 3,173
Default

Don't use system restore.. in fact disable it. Viruses love hiding in there..
Perana is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:03 PM   #21
private9
www.TUFFCARPARTS.com
 
private9's Avatar
 
Join Date: Feb 2006
Posts: 5,221
Default

Thanks for all the advice, very much appreciated!

Spybot did pickup and remove part of it, then I ran adaware, which successfully removed all of it, or so I thought! All was good for about 15 minutes, but it promptly reinstalled itself! Oh, and adaware now doesn't pick it up! - great work on the virus designers behalf.


I might give housecall a try, but obviously either way reformat must be done.


Quote:
Originally Posted by the_scotsman
I'd also just back up anything you want kept, then format and reinstall.

I always point people to this guide for doing a format/reinstall of XP:

http://web.mit.edu/ist/products/winx...ll-format.html

It has screenshots etc to help make it very easy to understand.

EDIT: Restore points can also store the virus...so I wouldn't do that.
Thanks for that link, it's very helpful!

Hopefully borrowing a friends harddrive, and will backup and reformat in the next day or so.

Does anyone know where I'll find the backup file for Microsoft Outlook (email) - my wife uses this for work, and cannot afford to lose all of the emails!

Thanks,

Justin.
private9 is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:06 PM   #22
EA2BA
PM me if you want
 
EA2BA's Avatar
 
Join Date: Dec 2004
Location: Pk Ranger Modding - QLD 👍
Posts: 7,498
Default

download smitfraud as well, that will be the main thing you infected yourself with.
__________________
Owner of first ever car to retrofit BA SSS - the EA2BA

Send me a PM if you want to know anything

2010 Ford Ranger PK High Rider (Auto) - 2011 Ford Fiesta (Auto)
EA2BA is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:25 PM   #23
DBourne
FF.Com.Au Hardcore
 
DBourne's Avatar
 
Join Date: Mar 2007
Location: sydney.nsw.au
Posts: 6,119
Default

Quote:
Does anyone know where I'll find the backup file for Microsoft Outlook (email) - my wife uses this for work, and cannot afford to lose all of the emails!
hi mate, make sure u can view hidden files (tools > options > view, tick the view hidden files folders)

then go my computer > C: > documents and settings > (username that she logs on with > local settings > application data > microsoft > outlook and then its the .pst file
__________________
flickr
DBourne is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:30 PM   #24
private9
www.TUFFCARPARTS.com
 
private9's Avatar
 
Join Date: Feb 2006
Posts: 5,221
Default

Quote:
Originally Posted by SgtBourne
hi mate, make sure u can view hidden files (tools > options > view, tick the view hidden files folders)

then go my computer > C: > documents and settings > (username that she logs on with > local settings > application data > microsoft > outlook and then its the .pst file
Awesome, thanks mate!
private9 is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:32 PM   #25
DBourne
FF.Com.Au Hardcore
 
DBourne's Avatar
 
Join Date: Mar 2007
Location: sydney.nsw.au
Posts: 6,119
Default

no worries mate.

once u get your computer up and running again, to restore all the emails you set up the account thru outlook, then simply navagiate to that folder and drop in the back up .pst and ull see all the emails come back as normal.
__________________
flickr
DBourne is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:32 PM   #26
private9
www.TUFFCARPARTS.com
 
private9's Avatar
 
Join Date: Feb 2006
Posts: 5,221
Default

Quote:
Originally Posted by EA2BA
download smitfraud as well, that will be the main thing you infected yourself with.
Cool. I think smitfraud is one of the things that spybot was flagging as an issue. Not sure why though.
private9 is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:36 PM   #27
DBourne
FF.Com.Au Hardcore
 
DBourne's Avatar
 
Join Date: Mar 2007
Location: sydney.nsw.au
Posts: 6,119
Default

sometimes applications like adawre etc find each other as a threat cos of the scripts they use etc plus anything they might have in quarentine etc.
__________________
flickr
DBourne is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:37 PM   #28
DJL351
XR & FPV Owner
 
DJL351's Avatar
 
Join Date: Apr 2005
Location: On the Dark Side of The Moon
Posts: 2,355
Default

Quote:
Originally Posted by SgtBourne
hi mate, make sure u can view hidden files (tools > options > view, tick the view hidden files folders)

then go my computer > C: > documents and settings > (username that she logs on with > local settings > application data > microsoft > outlook and then its the .pst file
There may be more than one pst file if you use the auto archive system in Outlook.
__________________
2005 BF GT (6sp manual - Build #183)
2015 SZ MkII Territory Titanium
2016.75 LZ Focus Sport

Quote:
probably the stupidist post on aff - congrats
Quote:
Originally Posted by flappist
There was once a time when every young man in this country was familiar with firearms and many owned them privately along with a stock of ammo and some bush gear.

Now the best we can hope for is to unfriend them on facebook then SMS their commanders with !!!1!!!!!!11!1!! and then finally plank a tank.......
DJL351 is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 01:48 PM   #29
BlackLS
yum
 
Join Date: Jan 2005
Posts: 1,417
Default

Do the scans in windows Safe Mode.

Theres probably a system process somewhere which is making the actual spyware run.

Doing it in safe mode will most likely get rid of tihs.
__________________
2005 LS Focus LX
Nov05 | Manual | Black Sapphire
250,000kms.

BlackLS is offline   Reply With Quote Multi-Quote with this Post
Old 08-11-2007, 02:03 PM   #30
DBourne
FF.Com.Au Hardcore
 
DBourne's Avatar
 
Join Date: Mar 2007
Location: sydney.nsw.au
Posts: 6,119
Default

Quote:
Originally Posted by DJL351
There may be more than one pst file if you use the auto archive system in Outlook.
true, shoudl be the one named outlook.pst unless you renamed it at some point. archives will be named archive.pst

can copy them too if you like
__________________
flickr
DBourne is offline   Reply With Quote Multi-Quote with this Post
Reply


Forum Jump


All times are GMT +11. The time now is 02:30 PM.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Other than what is legally copyrighted by the respective owners, this site is copyright www.fordforums.com.au
Positive SSL