Bavarian-Board.co.uk - BMW Owners Discussion Forum Homepage
Forum Home Forum Home > General Forums > General Off Topic Forum
  New Posts New Posts RSS Feed - Computer problem...Help..please
  FAQ FAQ  Forum Search   Register Register  Login Login

Forum LockedComputer problem...Help..please

 Post Reply Post Reply Page  123>
Author
Message
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Topic: Computer problem...Help..please
    Posted: 07-January-2006 at 13:16

Had a bit of a virus/spyware problem over the last couple of days.

My AVG antivirus software picked up a virus yesterday which I deleted. Thought no more of it until I logged on today and It picked up another virus. Then loads of pop ups appeared along with a new icon on my desk top and one on my tool bar.

I got rid of the pop ups but I was left with this in my tool bar and try as I might I cannot get rid of it.

 

The system intrusion detected which shows up as 'virus allert' current items is the problem. It continually flips between the red circle with white diagonal cross and the windows update icon (a cunning use of a familar safe icon!!) When I clicked on the message it brought up a web page which offered lots of anti spyware software all of which had a free scan funtion which download software onto the pc. The free scan picked up loads of stuff very quickly (in fact it was the quickest scan i've ever seen). However in order to remove the so called problems the site requires you to buy the full product on line, in fact even hitting the help button takes you to the buy online page. I'm guessing that this is a scam to either relive you of the 50$ (can't even get the dollar sign in the right place) for the product or simply get you card details. Now after my mate did lots of deleting he has stopped the system intrusion detected message opening this web page when it is clicked. He also managed to get rid of a page that came up when I opened internet explorer. Said page informed me that my pc was undere the contol of another pc and my personal documents were being looked at. It listed my i.p address and other info about my pc and had more links to sites where I could buy software to fix my problem. This page however was not online since it came up when my internet connection was disconnected.

Oh and pop ups have started appearing, from gambling sites and adult friend finder!! WTF

After updating my spybot software, installing zone alarm and adaware se personal things have got a lot better but i can still not remove this virus allert from my tool bar. I can set it to always hide which stops the anoying message popping up but it is still there and I am worried there may also be other files on the pc not being detected. Virus allert doesn't show up when you do a 'ctrl alt del' and if you right click on it nothing happens (btw microsoft antispyware and windows firewall have both been useless, the pair of them being comprehensively bipassed by the virus/spyware )

Sorry for the long waffle but I would really appreciate some advice on this one. Has anyone had this before?

Oh two more things, it doesn't appear on other accounts on the pc just mine although it still shows up in safe mode and my mate tried doing a system restore from before the problems started but it fails (a symptom of the problem?) 



Edited by Peter Fenwick
Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
Sponsored Links


Back to Top
spokey View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar
Offensive and obnoxious tub of lard

Joined: 02-March-2004
Location: United Kingdom
Status: Offline
Points: 1948
Direct Link To This Post Posted: 07-January-2006 at 13:42
I don't know why this guy's AV is better than others but it is very highly recommended (by me and others!)

If that doesn't work, try these guys.

Good luck!
Ciao,
Spokey

Back to Top
micky_h View Drop Down
Really Senior Member II
Really Senior Member II


Joined: 17-February-2003
Location: United Kingdom
Status: Offline
Points: 798
Direct Link To This Post Posted: 07-January-2006 at 16:56
Have you checked to see if theres anything new in your Add/Programs in the Control Panel?

Give Spybot a try and AVG if you havent already got it.

Worst case senario is you'll have to format the hard drive and re-install everything.
Back to Top
kbannon View Drop Down
Admin Group
Admin Group
Avatar
E39 525i Sport Individual

Joined: 09-October-2002
Location: 64 Zoo Lane
Status: Offline
Points: 15508
Direct Link To This Post Posted: 07-January-2006 at 17:04
1. Is AVG up to date - it is black in the pic above. Right click on the bottom right AVG icon and choose 'Check for updates'. Perform a Virus Scan. Maybe do this in safe mode also.
2. Run an online Virus check such as the free one from panda. As Active X is used for these, you need to run it using Internet Explorer
3. Use Firefox instead of Internet Explorer for everything except the following 3 things - Windows Update, the above online virus scan and the BMW CC tetris!
4. Start up in safe mode and run your anti virus and spyware tools. Safe mode is run by pressing the F8 key when the PC is starting.
5. make sure all your important stuff is backed up!

Current: 2009 E60 520d "Sport" tractor
Previous: 1989 E30 320i SE
1997 E39 523i
2003 E39 525i Sport Individual
Back to Top
bmwcrazy View Drop Down
Really Senior Member II
Really Senior Member II
Avatar
1995 M5,1995 318ISE,1997 325

Joined: 24-October-2005
Location: (glasgow the wee apple) big dazz
Status: Offline
Points: 661
Direct Link To This Post Posted: 07-January-2006 at 17:20
try running anty spy ware had same prob turned out to be a dropper virus  is it avg 7.1
also service pack 2 has a better firewall the zonealarm

try www.tucows.com all free software or majorgeeks.com

good luck dazz


Edited by bmwcrazy
Back to Top
spokey View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar
Offensive and obnoxious tub of lard

Joined: 02-March-2004
Location: United Kingdom
Status: Offline
Points: 1948
Direct Link To This Post Posted: 07-January-2006 at 17:59
Peter, I had an infestation that was a LOT like you're describing, and Dr Web CureIT got rid of it in one go. 
Ciao,
Spokey

Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 18:55

Originally posted by micky_h micky_h wrote:

Have you checked to see if theres anything new in your Add/Programs in the Control Panel?

Give Spybot a try and AVG if you havent already got it.

Worst case senario is you'll have to format the hard drive and re-install everything.

Yes, there's nothing at all in add/programs. Or anywhere else for that matter. My mate, who is an works with computers and maintains a network has never seen a virus/spyware that is so hard to find/eliminate. Got Spybot and AVG. Spybot has removed most of the offending files that got dumped on mp PC but these are obviously a few still there.

Reformatting the hard drive is the last option. Not something I'm looking forward to  

Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 18:57

Originally posted by kbannon kbannon wrote:

1. Is AVG up to date - it is black in the pic above. Right click on the bottom right AVG icon and choose 'Check for updates'. Perform a Virus Scan. Maybe do this in safe mode also.

AVG is up to date. It is greyed out because I haven't actived the email scanner since my Email accounts are with btinternet and so emails are not actually stored on my computer. Have tried a scan in safe mode.


 

Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 18:59

Thanks for the responses guys.

A few things for me to try. What I don't get is how come it is only affecting my account. Does that mean that the files are somewhere in my documents?

Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
stephenperry View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 20-April-2004
Location: Elgin
Status: Offline
Points: 7213
Direct Link To This Post Posted: 07-January-2006 at 19:14

download "hijackthis"

http://www.merijn.org/files/hijackthis.zip

do a scan, save the logfile and paste it up here so we can have a look

 


    2007 Ford Mondeo 2.0 TDCI Titanium X Auto

    1983 Ford Sierra XR4i
    2000 Alpina B10 3.3 #118
    1999 BMW 323Ci
    1995 BMW 318i SE
    1994 Vauxhall Omega 2.0 GLS
    1995 Ford Mondeo 1.8 LX
    1990 Honda Concerto 1.6 EX
    1986 Ford Orion 1.6 GL
    1989 Ford Fiesta 1.1 Firefly
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 19:16

Ok stephen, here you go...

Logfile of HijackThis v1.99.1
Scan saved at 00:14:56, on 08/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mssearchnet.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOCUME~1\PETERF~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: HomepageBHO - {27150f81-0877-42e9-af13-55e5a3439a26} - C:\WINDOWS\system32\hpA5B.tmp (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Filter: application/x-internet-signup - {A173B69A-1F9B-4823-9FDA-412F641E65D6} - C:\Program Files\Tiscali\Tiscali Internet\dlls\tiscalifilter.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
stephenperry View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 20-April-2004
Location: Elgin
Status: Offline
Points: 7213
Direct Link To This Post Posted: 07-January-2006 at 19:21

get rid of these....

C:\WINDOWS\system32\mssearchnet.exe

O2 - BHO: HomepageBHO - {27150f81-0877-42e9-af13-55e5a3439a26} - C:\WINDOWS\system32\hpA5B.tmp (file missing)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll

 

 


    2007 Ford Mondeo 2.0 TDCI Titanium X Auto

    1983 Ford Sierra XR4i
    2000 Alpina B10 3.3 #118
    1999 BMW 323Ci
    1995 BMW 318i SE
    1994 Vauxhall Omega 2.0 GLS
    1995 Ford Mondeo 1.8 LX
    1990 Honda Concerto 1.6 EX
    1986 Ford Orion 1.6 GL
    1989 Ford Fiesta 1.1 Firefly
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 19:44

Got rid of those files except

C:\WINDOWS\system32\mssearchnet.exe
Which it would let me delete, because it was being used by another program......

That file does look like the one though. It's icon is a little yellow triange with an exclamation mark in.



Edited by Peter Fenwick
Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
stephenperry View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 20-April-2004
Location: Elgin
Status: Offline
Points: 7213
Direct Link To This Post Posted: 07-January-2006 at 19:48

right, next, ctrl-alt-del and check the process list

do you see mssearchnet.exe?  if so, end process

rescan with hijackthis and try removing mssearchnet.exe again


    2007 Ford Mondeo 2.0 TDCI Titanium X Auto

    1983 Ford Sierra XR4i
    2000 Alpina B10 3.3 #118
    1999 BMW 323Ci
    1995 BMW 318i SE
    1994 Vauxhall Omega 2.0 GLS
    1995 Ford Mondeo 1.8 LX
    1990 Honda Concerto 1.6 EX
    1986 Ford Orion 1.6 GL
    1989 Ford Fiesta 1.1 Firefly
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 19:56

Not sure how relevant this is but when I run spybot it get a hit. It says that I have to reboot the computer in order to get rid of the problem which I do. Spybot them comes in during start up clicks and wirrs and then i click fix and hey presto probelm sorted. However when I log off and on again and rescan the problem is back.... 

It says it has sorted them but I just did a rescan and it's back.......

Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
stephenperry View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 20-April-2004
Location: Elgin
Status: Offline
Points: 7213
Direct Link To This Post Posted: 07-January-2006 at 19:57

newdotnet will be in add/remove programs, remove it

in fact, do a screengrab(s) of your add remove programs list too and paste them up please


    2007 Ford Mondeo 2.0 TDCI Titanium X Auto

    1983 Ford Sierra XR4i
    2000 Alpina B10 3.3 #118
    1999 BMW 323Ci
    1995 BMW 318i SE
    1994 Vauxhall Omega 2.0 GLS
    1995 Ford Mondeo 1.8 LX
    1990 Honda Concerto 1.6 EX
    1986 Ford Orion 1.6 GL
    1989 Ford Fiesta 1.1 Firefly
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 19:57
Tried end process and it doesn't do anything ie it doesn't go. It a bit like a bad smell really....
Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
stephenperry View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 20-April-2004
Location: Elgin
Status: Offline
Points: 7213
Direct Link To This Post Posted: 07-January-2006 at 20:03

does it not come up with the warning about ending a process, like this?


    2007 Ford Mondeo 2.0 TDCI Titanium X Auto

    1983 Ford Sierra XR4i
    2000 Alpina B10 3.3 #118
    1999 BMW 323Ci
    1995 BMW 318i SE
    1994 Vauxhall Omega 2.0 GLS
    1995 Ford Mondeo 1.8 LX
    1990 Honda Concerto 1.6 EX
    1986 Ford Orion 1.6 GL
    1989 Ford Fiesta 1.1 Firefly
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 20:05

newdotnet isn't there but here's a screen dump. Sorry about the size..

 

 

 

 

 

 

Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
Peter Fenwick View Drop Down
Bavarian-Board Contributor
Bavarian-Board Contributor
Avatar

Joined: 27-August-2003
Location: Lost somewhere in time...
Status: Offline
Points: 6484
Direct Link To This Post Posted: 07-January-2006 at 20:05
Originally posted by stephenperry stephenperry wrote:

does it not come up with the warning about ending a process, like this?

Yes, so I clicked yes anyway

Entering an age of Austerity and now driving a Focus Diesel.
Back to Top
 Post Reply Post Reply Page  123>
  Share Topic   

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.188 seconds.