PDA

View Full Version : Virus? But which type?


Paris Dakar
13th Jun 2006, 12:15
My system (Win2K + all updates/service packs, Avast Home Edition & Sygate Firewall, Blueyonder 2meg BB) has run rock-steady without a hiccup for almost 2 years......................until last weekend.

I decided to do my twice-weekly run of 'Adaware SE Professional' and 'ASO' and when I clicked on the Adaware shortcut it vanished in front of my eyes. When I went to the location file where the application lives I clicked on the 'install' icon but got a message saying that the file was corrupt? No probs, I'll install it again from my backed-up CD version. I re-loaded the software and ran it but it didn't find anything, when I rebooted the Pc and clicked on the Adaware Icon it disappeared again and I got the same corruption message.

Not wishing to admit defeat I downloaded 'Stinger' and ran that - it found some problems and fixed them but when I restarted the Pc again the icon [Stinger] vanished. Also, after the boot up, I get an Avast message stating that it needs to restart as there is a problem.

I thought I might have the Rbot SU worm but when I follow the instructions to delete certain registry files they do not exist?

Any ideas folks?

Tarq57
30th Jun 2006, 12:48
Not many, I'm afraid. What I would probably do is install and run Ewido, and maybe Asquared scanner. If no luck run a Hijack This scan (see the sticky) and see if anything is sus.
I've read that it's a good idea to have more than one spyware scanner, in addition to AV. I'm running 2 background scanners (Ewido and MS Antispy), 4 prevent-settings-being-changed type scanners, (Spybot's tea-timer, SpywareGuard, SpywareBlaster, and Winpatrol) and also regularly scan with Spybot, AdAware, Asquared, Bazooka, and CWShredder.
Having had to have the OS reinstalled and losing data has caused this ounce-of-prevention approach.

Avtrician
30th Jun 2006, 13:07
Download, but do not install yet AVG or similar.
Reboot into safe mode (no drivers loaded, and hopefully no virus running)
install and run the checker, it should with luck find and kill the bugger. come back and tell us what happens. Hijack this is also a good utility to run.

DBTL
30th Jun 2006, 14:31
http://support.f-secure.com/enu/home/ols3.shtml

http://www.webroot.com/consumer/products/spysweeper/
(information only, no removal services)

BOAC
30th Jun 2006, 15:49
There are at least 2 on-line virus scanners available

1) http://housecall.antivirus.com/housecall/start_corp.asp
2) http://www.kaspersky.com/virusscanner

I suggest you try those first?

Evo
30th Jun 2006, 18:59
I thought I might have the Rbot SU worm but when I follow the instructions to delete certain registry files they do not exist?

Rbot is essentially a template based on SDBot - there are many, many variants of this that morph to try and defeat anti-virus definitions. Specific instructions for one flavour won't necessarily work for another.