Computer problem...Help..please |
Post Reply | Page 123> |
Author | |
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Topic: Computer problem...Help..please Posted: 07-January-2006 at 13:16 |
Had a bit of a virus/spyware problem over the last couple of days. My AVG antivirus software picked up a virus yesterday which I deleted. Thought no more of it until I logged on today and It picked up another virus. Then loads of pop ups appeared along with a new icon on my desk top and one on my tool bar. I got rid of the pop ups but I was left with this in my tool bar and try as I might I cannot get rid of it.
The system intrusion detected which shows up as 'virus allert' current items is the problem. It continually flips between the red circle with white diagonal cross and the windows update icon (a cunning use of a familar safe icon!!) When I clicked on the message it brought up a web page which offered lots of anti spyware software all of which had a free scan funtion which download software onto the pc. The free scan picked up loads of stuff very quickly (in fact it was the quickest scan i've ever seen). However in order to remove the so called problems the site requires you to buy the full product on line, in fact even hitting the help button takes you to the buy online page. I'm guessing that this is a scam to either relive you of the 50$ (can't even get the dollar sign in the right place) for the product or simply get you card details. Now after my mate did lots of deleting he has stopped the system intrusion detected message opening this web page when it is clicked. He also managed to get rid of a page that came up when I opened internet explorer. Said page informed me that my pc was undere the contol of another pc and my personal documents were being looked at. It listed my i.p address and other info about my pc and had more links to sites where I could buy software to fix my problem. This page however was not online since it came up when my internet connection was disconnected. Oh and pop ups have started appearing, from gambling sites and adult friend finder!! WTF After updating my spybot software, installing zone alarm and adaware se personal things have got a lot better but i can still not remove this virus allert from my tool bar. I can set it to always hide which stops the anoying message popping up but it is still there and I am worried there may also be other files on the pc not being detected. Virus allert doesn't show up when you do a 'ctrl alt del' and if you right click on it nothing happens (btw microsoft antispyware and windows firewall have both been useless, the pair of them being comprehensively bipassed by the virus/spyware ) Sorry for the long waffle but I would really appreciate some advice on this one. Has anyone had this before? Oh two more things, it doesn't appear on other accounts on the pc just mine although it still shows up in safe mode and my mate tried doing a system restore from before the problems started but it fails (a symptom of the problem?) Edited by Peter Fenwick |
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
Sponsored Links | |
spokey
Bavarian-Board Contributor Offensive and obnoxious tub of lard Joined: 02-March-2004 Location: United Kingdom Status: Offline Points: 1948 |
Posted: 07-January-2006 at 13:42 |
I don't know why this guy's AV is better than others but it is very highly recommended (by me and others!)
If that doesn't work, try these guys. Good luck! |
|
Ciao,
Spokey |
|
micky_h
Really Senior Member II Joined: 17-February-2003 Location: United Kingdom Status: Offline Points: 798 |
Posted: 07-January-2006 at 16:56 |
Have you checked to see if theres anything new in your Add/Programs in the Control Panel?
Give Spybot a try and AVG if you havent already got it. Worst case senario is you'll have to format the hard drive and re-install everything. |
|
kbannon
Admin Group E39 525i Sport Individual Joined: 09-October-2002 Location: 64 Zoo Lane Status: Offline Points: 15508 |
Posted: 07-January-2006 at 17:04 |
1. Is AVG up to date - it is black in the pic above. Right click on the bottom right AVG icon and choose 'Check for updates'. Perform a Virus Scan. Maybe do this in safe mode also.
2. Run an online Virus check such as the free one from panda. As Active X is used for these, you need to run it using Internet Explorer 3. Use Firefox instead of Internet Explorer for everything except the following 3 things - Windows Update, the above online virus scan and the BMW CC tetris! 4. Start up in safe mode and run your anti virus and spyware tools. Safe mode is run by pressing the F8 key when the PC is starting. 5. make sure all your important stuff is backed up! |
|
Current: 2009 E60 520d "Sport" tractor
Previous: 1989 E30 320i SE 1997 E39 523i 2003 E39 525i Sport Individual |
|
bmwcrazy
Really Senior Member II 1995 M5,1995 318ISE,1997 325 Joined: 24-October-2005 Location: (glasgow the wee apple) big dazz Status: Offline Points: 661 |
Posted: 07-January-2006 at 17:20 |
try running anty spy ware had same prob turned out to be a dropper virus is it avg 7.1
also service pack 2 has a better firewall the zonealarm try www.tucows.com all free software or majorgeeks.com good luck dazz Edited by bmwcrazy |
|
|
|
spokey
Bavarian-Board Contributor Offensive and obnoxious tub of lard Joined: 02-March-2004 Location: United Kingdom Status: Offline Points: 1948 |
Posted: 07-January-2006 at 17:59 |
Peter, I had an infestation that was a LOT like you're describing, and Dr Web CureIT got rid of it in one go.
|
|
Ciao,
Spokey |
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 18:55 |
Yes, there's nothing at all in add/programs. Or anywhere else for that matter. My mate, who is an works with computers and maintains a network has never seen a virus/spyware that is so hard to find/eliminate. Got Spybot and AVG. Spybot has removed most of the offending files that got dumped on mp PC but these are obviously a few still there. Reformatting the hard drive is the last option. Not something I'm looking forward to |
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 18:57 |
AVG is up to date. It is greyed out because I haven't actived the email scanner since my Email accounts are with btinternet and so emails are not actually stored on my computer. Have tried a scan in safe mode.
|
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 18:59 |
Thanks for the responses guys. A few things for me to try. What I don't get is how come it is only affecting my account. Does that mean that the files are somewhere in my documents? |
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
stephenperry
Bavarian-Board Contributor Joined: 20-April-2004 Location: Elgin Status: Offline Points: 7213 |
Posted: 07-January-2006 at 19:14 |
download "hijackthis" http://www.merijn.org/files/hijackthis.zip do a scan, save the logfile and paste it up here so we can have a look
|
|
2007 Ford Mondeo 2.0 TDCI Titanium X Auto 1983 Ford Sierra XR4i 2000 Alpina B10 3.3 #118 1999 BMW 323Ci 1995 BMW 318i SE 1994 Vauxhall Omega 2.0 GLS 1995 Ford Mondeo 1.8 LX 1990 Honda Concerto 1.6 EX 1986 Ford Orion 1.6 GL 1989 Ford Fiesta 1.1 Firefly |
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 19:16 |
Ok stephen, here you go... Logfile of HijackThis v1.99.1 Running processes: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/ |
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
stephenperry
Bavarian-Board Contributor Joined: 20-April-2004 Location: Elgin Status: Offline Points: 7213 |
Posted: 07-January-2006 at 19:21 |
get rid of these.... C:\WINDOWS\system32\mssearchnet.exe O2 - BHO: HomepageBHO - {27150f81-0877-42e9-af13-55e5a3439a26} - C:\WINDOWS\system32\hpA5B.tmp (file missing) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
|
|
2007 Ford Mondeo 2.0 TDCI Titanium X Auto 1983 Ford Sierra XR4i 2000 Alpina B10 3.3 #118 1999 BMW 323Ci 1995 BMW 318i SE 1994 Vauxhall Omega 2.0 GLS 1995 Ford Mondeo 1.8 LX 1990 Honda Concerto 1.6 EX 1986 Ford Orion 1.6 GL 1989 Ford Fiesta 1.1 Firefly |
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 19:44 |
Got rid of those files except C:\WINDOWS\system32\mssearchnet.exe That file does look like the one though. It's icon is a little yellow triange with an exclamation mark in. Edited by Peter Fenwick |
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
stephenperry
Bavarian-Board Contributor Joined: 20-April-2004 Location: Elgin Status: Offline Points: 7213 |
Posted: 07-January-2006 at 19:48 |
right, next, ctrl-alt-del and check the process list do you see mssearchnet.exe? if so, end process rescan with hijackthis and try removing mssearchnet.exe again |
|
2007 Ford Mondeo 2.0 TDCI Titanium X Auto 1983 Ford Sierra XR4i 2000 Alpina B10 3.3 #118 1999 BMW 323Ci 1995 BMW 318i SE 1994 Vauxhall Omega 2.0 GLS 1995 Ford Mondeo 1.8 LX 1990 Honda Concerto 1.6 EX 1986 Ford Orion 1.6 GL 1989 Ford Fiesta 1.1 Firefly |
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 19:56 |
Not sure how relevant this is but when I run spybot it get a hit. It says that I have to reboot the computer in order to get rid of the problem which I do. Spybot them comes in during start up clicks and wirrs and then i click fix and hey presto probelm sorted. However when I log off and on again and rescan the problem is back.... It says it has sorted them but I just did a rescan and it's back....... |
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
stephenperry
Bavarian-Board Contributor Joined: 20-April-2004 Location: Elgin Status: Offline Points: 7213 |
Posted: 07-January-2006 at 19:57 |
newdotnet will be in add/remove programs, remove it in fact, do a screengrab(s) of your add remove programs list too and paste them up please |
|
2007 Ford Mondeo 2.0 TDCI Titanium X Auto 1983 Ford Sierra XR4i 2000 Alpina B10 3.3 #118 1999 BMW 323Ci 1995 BMW 318i SE 1994 Vauxhall Omega 2.0 GLS 1995 Ford Mondeo 1.8 LX 1990 Honda Concerto 1.6 EX 1986 Ford Orion 1.6 GL 1989 Ford Fiesta 1.1 Firefly |
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 19:57 |
Tried end process and it doesn't do anything ie it doesn't go. It a bit like a bad smell really....
|
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
stephenperry
Bavarian-Board Contributor Joined: 20-April-2004 Location: Elgin Status: Offline Points: 7213 |
Posted: 07-January-2006 at 20:03 |
does it not come up with the warning about ending a process, like this? |
|
2007 Ford Mondeo 2.0 TDCI Titanium X Auto 1983 Ford Sierra XR4i 2000 Alpina B10 3.3 #118 1999 BMW 323Ci 1995 BMW 318i SE 1994 Vauxhall Omega 2.0 GLS 1995 Ford Mondeo 1.8 LX 1990 Honda Concerto 1.6 EX 1986 Ford Orion 1.6 GL 1989 Ford Fiesta 1.1 Firefly |
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 20:05 |
newdotnet isn't there but here's a screen dump. Sorry about the size..
|
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
Peter Fenwick
Bavarian-Board Contributor Joined: 27-August-2003 Location: Lost somewhere in time... Status: Offline Points: 6484 |
Posted: 07-January-2006 at 20:05 |
Yes, so I clicked yes anyway |
|
Entering an age of Austerity and now driving a Focus Diesel.
|
|
Post Reply | Page 123> |
|
Forum Jump | Forum Permissions You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |