Jump to content

Viruses


JesseJ1935
 Share

Recommended Posts

After my computer slowed down, and when I started getting getting emaails from Porn sites, I decided that something nasty had managed to slip past my anti virus programme, namely PC Security's VI Robot.

I ran Hijack this and posted it on the site recommended by Nellie. After I had done various things that was suggested, there was nothing in the log that suggested that I had been infected, but the problems persisted, one of which was that I could be typing something andd the egg timer came on suggesting that some process had interupted what I was doing, trouble being that it did not stay long enough for me to find out what from the Task Manager.

I scanned the computer with VI Robot, nothing found so went to various online scans, starting with Trend Micro's Housecall. That discovered the following:

ADWARE_EBATES

SPYWARE_TRAK_MSNSPYMONITOR

SPYWARE_TRAK_ESPYNOW.200

DIALER_PORNDIAL

ADWARE_ABETTERINTERNET

2 HTP cookies.

None of the other scanners found anything, which were Panda and Symantec, nor have any spyware/malware programmes such as Spybot; Adware, and others.

The problem with using Housecall to delete them is that it also tries to delete AOL locations and AOL promptly crashes without anything being done. Having just ran yet another anti spyware programmes which found a number of cookies, but none that Housecall found, I am wondering if Housecall is being over aggresive and finding items that are not viruses at all. Having said that, I looked at the registry, regedit, and found ADWARE_EBATES which, rightly or wrongly, deleted, but could not find any of the others.

I would be very grateful for any suggestions/advice/comments, etc. If the viruses do exist then how do I get rid of them?

Link to comment
Share on other sites

Thank you andsome.

I already have done, there was only a result with an odd one or two, the rest couldn't be found.

One suggestion I've had was to do another scan in safe mode with Trend Micro Housecall. That's all very well but, as I said previously, housecall tries to delete the AOL locations, surely this will be the same in safe mode.

Still, I'll give it a try and see what happens.

Thanks again for your reply.

Link to comment
Share on other sites

You should post a HijackThis! log. See links in my signature.

Thank you for your reply Scarecrow Man.

Maybe I'm a bit dim today but I can't see a link in your signature for posting a Hijack this log. Do you want me to include it in a reply on the board? Or as a personal message?

Link to comment
Share on other sites

You should post a HijackThis! log. See links in my signature.

Thank you for your reply Scarecrow Man.

Maybe I'm a bit dim today but I can't see a link in your signature for posting a Hijack this log. Do you want me to include it in a reply on the board? Or as a personal message?

Look for Hijack this just under the blue bar in his post.

Link to comment
Share on other sites

Thank you andsome, I tried that and got the following message:

Board Message

Sorry, an error occurred. If you are unsure on how to use a feature, or don't know why you got this error message, try looking through the help files for more information.

The error returned was:

Sorry, the link that brought you to this page seems to be out of date or broken.

Link to comment
Share on other sites

I wonder if this is the same place where I would have sent you, because that also appears to be down at present.

Try here later on.

Just checked SCM's link and in fact it is broken because we no longer have HJT experts on the forum. My link is to an Anti Malware site. So try it now and then I don't suppose it will be off for too long.

Just checked again, it is up and running now.

Link to comment
Share on other sites

Hi again andsome.

I think I said in my original post that I had sent a Highjack This log elsewhere. When I first tried to post it on this site I was redirected by Nellie's post to that site and that was where it was examined, admittedly by a learner under instruction from an expert. The final result was that nothing nasty was found, only suggestions about various things I could do and get rid of, none of which affected these so-called viruses. I think I also said that I had received another suggestion to run a scan in safe mode, fine except for one thing, that wouldn't stop Trend Micro's Housecall from trying to interfere with the AOL locations.

Having done scans using other online scanners, all of which did not find anything, I am thinking that maybe Housecall is being a little too aggresive.

As for the porn emails I was getting, these have now stopped.

Just to be on the safe side though, is there anywhere else that you know of where the log can be examined?

Thanks for your help.

Link to comment
Share on other sites

Update.

Following the other suggestion I have just scanned my computer yet again, this time with the McAfee online scanner, results = nothing found. Having now scanned it with just about every online scanner, except for Housecall, none of them have found anything which suggests to me at least, that Housecall is being just a wee bit over aggresive.

Your comments, if any, will be appreciated. Meanwhile many thanks to all who replied.

Link to comment
Share on other sites

Rong: Yes, Housecall does show what it wants to delete, but I have not been able to identify anything that is to do with AOL, which is what has got me flummoxed.

andsome: Thank you for the link, I've now registered with them. Hope they can shed some some light on the mystery.

Link to comment
Share on other sites

may I just say that if you have posted your log over here malware the learners DO post, yes, BUT under STRICT supervision from the admin and tutors and they are NOT allowed to post ANYTHING to the HJT log threads unless it has been completely checked out as correct and valid instructions BY a teacher ; if you read through that forums rules and regs you will see what they have to say about it;if you have had a log over there and have any queries about the finding do ask them and they will clarigy things for you :) I was in the uni there and had to withdraw due to pressure of work so I have some grasp of how strenous and particular the training is and how meticulous the trainers are in their teaching methods :flowers:

it may be that Housecall IS showing false positives; if you are in ANY doubt then post a fresh log for review

?? do you also have a squared ,spybot and adaware scanners on there? (my zip back through this thread cannot locate them if you have said that you do :( )

Link to comment
Share on other sites

P;3 I hope you haven't misunderstood me, I've got no complaints about the Malware forum, in fact I was quite happy with it, I was given some very good advice. But they couldn't find what Trend's Housecall was on about which made me wonder if Housecall is telling porkies. From the advice given on that forum, and another, I'm overloaded with Spyware/Malware programmes, I'll have to get rid of some of them. I been paranoid about security in the past but I think I'm way over the top with what's on this machine at the moment. Adaware; Spybot, and a lot of others but not A-squared.

Nellie 2: I'll run Housecall again as soon as I can, it will be later this afternoon as the computer is busy until 4.00pm with it's weekly maintenance jobs.

Link to comment
Share on other sites

once you have posted your Log it will be inappropriate for me to comment as Nellie will be on it for you; however, as you may be finding, you CAN HAVE too much protection on a computer that slows it to a snails pace;and, yes, I did think you were showing some concerns about the other forum's advice ;believe you me they are well- trained over there :D

you could even have a software clash going on it you have overdone it with protection

let Nellie check out your log and advise you :flowers:

Link to comment
Share on other sites

P;3 Thanks for your reply, I'm pleased it was just a small misunderstanding, probably the way I worded it.

Nellie, here is the best I can manage as far as a log is concerned from Housecall.

There doesn't seem to be a way of saving a log, if there is I can't find it so I've had to write out all the information that Housecall gave me.

When I first ran Housecall I found ADWARE_EBATES in the Registry and deleted it but it's back again.

Also, as I said in my first post, as soon as I click on 'Clean Now' the connection to AOL is dropped.

The infections Housecall says I've got are as below, with all the info. it gave me.

ADWARE_EBATES.

Aliasnames: ADebates money maker (Webroot), Win 32, Trojan-gen. Other (Alwil), Adware.Web Rebates. R (Ikarus)

Platform: Not specified

First occurence: Not specified

General Risk rate: Low

This adware generates pop-up advertisements. It runs every time it is turned on by modifying the RUN key of the system registry. It hijacks the Internet browser settings. Hence the start page or search page of the browser may be changed from the usual user-defined setting.

SPYWARE_TRAK_ESPYNOW.200

SPYWARE_TRAK_MSNMONITOR

There is currently no more information available for this grayware/spyware.

DIALER_PORNDIAL

Aliasnames: Win32.Sdbot.BQ (Pest Patrol), Trojan-Spy.Win32.Silent Log.A (Ikarus), PSW.Silent Log.A (Grisoft), Trojan/Spy.Silent Log (Jiang Min), Win32/Silent Log trojan (CAV), Win32/Logger.A! Trojan (CAI)

Platform: Not specified

First occurence: Not specified

General risk rate: Low

This dialer either does not have, or has a deceptive, End-User License Agreement (EULA). It adds unwanted shortcuts; favorites or icons in a computer and/or Internet browser. It creates dial-up settings without the users permission or intervention.

ABETTERINTERNET

Aliasnames: Adware-abetterintrn (McAfee), not-a-virus: AdWare.Win32.BetterInternet.az (Kaspersky)

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

First occurence: Not specified

General risk rate: Medium

This adware may arrive on a system bundled with other grayware. It may also be downloaded from the Internet when users visit malicious Web sites. Once installed, it monitors Internet browsing habits andd displays pop-up advertisements related to the Web sites visited by the user.

TSPY_JOINER.AV

This only showed up once, and not long enough to get any information about it at all.

HTTP cookies (BLUESTREAK)

Cookies are generally used to save user-specific data from Internet transactions with a Web server via a browser. The cookies listed are "profiling cookies" that are only used to monitor your Internet usage.

At first look, by me, it appears as though most, if not all, these so-called viruses are something to do with various scanners/spyware/malware programmes which, as I said before, I downloaded and ran, or installed, on the advice received from another forum.

Hope you can sort something out from this, and look forward to hearing from you.

Link to comment
Share on other sites

The scan results you showed, are all mal-, ad- or spyware.

These can easily be removed with AdAware.

You should try to remove them with AdAware SE Pro, you can download it for free here

Limitations: Real time protection disabled {i think they mean AdWatch}

Do you know if Trend Micro Housecall also noted the Location of the virusses?

if so, please share them > if they are located in an archive, it could be very good possible that your programs arent able of scanning archives [that is very good possible]

try that

you could also try McAfee Stinger, which is a little tool which scans and removes certain virusses from you computer

you can find a readme/manual/tutorial how to use Stinger here

another great program is XoftSpySE > its fast and finds most threads

Link to comment
Share on other sites

Thank you for your replies.

I should have said before I suppose, but neither AdAware or SpyBot picked these viruses up. Nor did any other anti spy/malware programmes or other online virus scanners. Those tried include:

Symantec; McAfee; Panda and Kaspersky for the online scans.

Super Anti-Spyware; Windows Live One Care safety scanner; AVG Anti-Spyware; Windows Defender and AOL Spy Zapper. The only programme that identified them was Trend Housecall, which is why I began to think that Housecall was being too aggresive and finding non-existent threats. By that I mean some of those programmes listed above having a report back to base programme attached to it.

I will try one or more of the programmes mentioned above to see if they pick anything up but meanwhile most of the ones I had installed have been removed, all I have running now is AdAware; SpyBot; Windows Defender and SpySweeper, the only reason SpySweeper is still there is because I've subscribed to it, that does not necessarily mean that it will stay, one of the so-called viruses had an alias, Webroot, who, as you probably know, are the people behind SpySweeper.

I'll report back after running those other programmes, and maybe Housecall again.

Many thanks for all your help and suggestions.

Link to comment
Share on other sites

why dont you try registering for and running the a squared program

asquared; take it on board , fully update it and run a full scan and see what IT throws up; be aware it too will give false possitives so you need to know what is legit on your system ;

give that a go and let us know how it reports for you but DONT delete ANYTHING you are in the least uncertain of; run a full scan and even post the results here for someone to check them out for you ;)

Link to comment
Share on other sites

Very ,amy thanks for all your replies. Kaspersky online scanner was one of the online scanners I tried, also a-squared, I tried so many, and my memory is not so clever these days so can't remember them all until somebody else mentions them.

Seeing as three or four of them seemed to be tied in, the aliasnames, to some of the prrogrammes I ran, last night I removed AVG Anti-Spyware; Kaspersky Online Scanner; Super Anti-Spyware and Windows Live One Care safety scanner just for starters. Also one of the AOL Spyware programmes. All I have left now is AdAware; SpyBot; Windows Defender and Webroot's SpySweeper. Maybe still too many. Unfortunately, as somebody asked, Housecall does not show the location of these viruses, I've done a search of the Registry and the only one I could find was the EBATES one which, rightly or wrongly, I deleted. Waste of time as it's back there again. Having removed those programmes shown above I have just ran Housecall again, they are all still there.

By the way Nellie, I haven't changed sex, not that I know of anyhow and I'm sure my wife would have said something by now if I had. (Don't take that wrong, I have not taken offence) It's an easy mistake to make I suppose but Jesse has been a very old family name given as a middle name to a boy in alternate generations. Funnily enough, the alternate name is James. I often wonder who started it as it goes back long before Jesse James became famous.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy