|
| Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free! |
Avast and Virus
|
Original Message
|
Name: flashstatic
Date: July 30, 2007 at 01:35:09 Pacific
Subject: Avast and VirusOS: XPCPU/Ram: P4 3.2 / 2 GigModel/Manufacturer: Fujitsu Siemens |
Comment: Ok my computer came down with a Virus or somthing yesterday that coursed my computer to run really slow and as soon as i ran Firefox i just heard this strange clicking noise and loads of shortcut icons where on my desktop, I ran Ad-Aware SE Personal and Spybot - Search & Destroy and they found a few things but usually evertime i run one of these programs it finds somthing even if i run it stright after its already finished a scan Anyway I came on here and heard about Avast so just about 30mins ago I download it and installed which went well It then asked me to reboot so it could do a scan, which i did and eventually got a screen that said sanning in progress press an option, so one option was "No 6: place in chest" so i pressed number 6 but i got no responce. Tried pressing Esc and nothing so had to hit the power button and thrn it took me about 20mins after that for the computer to start working but its now running very slow Anyone no whats up and/or could give me any advice to clean up my system.
Cheers in advance -Flash Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Message For Removal
|
|
Response Number 1
|
Name: flashstatic
Date: July 30, 2007 at 02:02:10 Pacific
|
Reply: (edit)ok I'm screwed having to post this on mi mobile cos computer will not work now. I load it up and just see my desktop and no icons. my usuall way out of this one is to format the drive and put a fresh windows on but unable to do that as mi windows cd is dead plus don't no mi serial anymore So plz somone help me Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Follow Up For Removal
|
|
Response Number 2
|
Name: btk1w1
Date: July 30, 2007 at 03:00:53 Pacific
|
Reply: (edit)First thing to try is to boot into safe mode... Tap f8 key during start up and choose "safe mode" Next do a restore to a point before you installed avast or even before icons appeared. Click start > all programs > accessories > system tools > system restore... then choose restore my computer to an earlier time and choose a date before you encountered problems. Let us know when you have done this and if pc restored successfully. Lotsa Freeware
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: flashstatic
Date: July 30, 2007 at 13:13:04 Pacific
|
Reply: (edit)ok I rebooted my computer and I got a few options with safe mode in the name I tried the one that said just *safe mode* but that didn't work then I saw an option that said boot to last known working config so I did that and now I've got it working and I see the icons but its running very slow as if its constantly loading something so what do I do from here it takes me about 5mins to complete an action which should only take a few seconds. So plz I beg of u help me I need this compter for college Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: btk1w1
Date: July 30, 2007 at 23:14:31 Pacific
|
Reply: (edit)Did you uninstall any other antivirus program that might have been on your pc before you downloaded avast and tried to run it? If you have even remnants of a different av program sometimes installiing a new one over the top of it can cause system instability. If you think a program might be trying to load in the background and slowing your pc down, you can right click your taskbar then click task manager and click on the applications tab to see if there are any programs hanging while trying to start up. If there are none you can click on the processes tab and have a look at which program is using up the most cpu. Have a look at whats in start up. Click on start > run and type: msconfig now click on the startup tab and see if there is anything unfamiliar in there. If you are unsure post the details of the startup programs you are unsure of.
Report Offensive Follow Up For Removal
|
|
Response Number 5
|
Name: flashstatic
Date: July 31, 2007 at 00:45:17 Pacific
|
Reply: (edit)Thanks again for replying btk1w1, anyway after I got it working again I thought id try that proccess u mentioned in a previous post (Click start > all programs > accessories > system tools > system restore.) Took a while as after each click I had to wait about 5 mins for a response but finally after abit of rebooting its now working ok, but when I did a reboot scan with Avast but sadly it stops in the middle of the proccess, and comes up with that same darn virus called "win32 swizzor-gen" and then the computer becomes non responsive and I have to hit the power botton as it wont move to chest or delete. So is this a bad virus, I would say it is if avast carnt deal with it, so anyone know how to get rid Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Follow Up For Removal
|
|
Response Number 6
|
Name: btk1w1
Date: July 31, 2007 at 03:05:00 Pacific
|
Reply: (edit)win32 swizzor-gen is lop malware. An effective tool for removing this is a-squared free. You can get this here: http://www.emsisoft.com/en/software... After you install a-squared let it perform the updates. When you run the program select "Scan PC" then "Deep Scan" and start the scan. Once the scan has finished click "Save Report" and save the file to an easy location, e.g. desktop. After this select all files and quarantine them. Repeat the procedure in safe mode (remember to save another report) Once you have finished scanning boot up normally and paste the reports back into this thread. Let me know how your pc is running also.
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: flashstatic
Date: August 1, 2007 at 01:18:56 Pacific
|
Reply: (edit)Ok I installed that prog and running the deep scan now, but im kinda getting worried because it found somthing called trojan-dropper.win32.VB.ul and now it just keeps adding/or finding othere files too it constantly, its now at 16204 files surly this carnt be right I think theres somthing amiss here because the deep scan has been running like 45mins now and does'nt look like its gona stop at all. i even disconected my internet to see what that did but nothing. Is this what should happen? Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Follow Up For Removal
|
|
Response Number 8
|
Name: btk1w1
Date: August 1, 2007 at 01:52:08 Pacific
|
Reply: (edit)Let a-squared select which files need to be quarantined (it will auto-select them). Only quarantine these for now I and will have a look at a hijackthis log instead as the a-squared reports will be far too big. If you have other files on there that allow xp tweaks it also detects these and it can detect various spyware removal and anti-trojan programs because of the scripts they use. If you select quarantine we can always restore vasious files upon inspection but the main thing first is to get your pc running smoothly so we can do an avast boot-time scan.
Report Offensive Follow Up For Removal
|
|
Response Number 9
|
Name: btk1w1
Date: August 1, 2007 at 02:34:07 Pacific
|
Reply: (edit)The lop malware infection has been found on messenger plus 3 and both instances of these infections (win32 swizzor-gen & trojan-dropper.win32.VB.ul) have been found on various internet program downloads. If you installed anything just prior to having these problems it would be advisable to uninstall it. After your a-squared scan is done download hijackthis from here: http://www.spywareinfo.com/~merijn/... Create a folder named hjt in C:\Program Files and save it there. Navigate to the file you downloaded and open it. "Do a system scan and save a logfile" and when the text document is open, copy and paste the contents into this thread.
Report Offensive Follow Up For Removal
|
|
Response Number 10
|
Name: flashstatic
Date: August 1, 2007 at 13:10:38 Pacific
|
Reply: (edit)Ok sorry about the deley in replying only got home from work at 7pm GMT, anyway a-squared as finished and I have the option to delete, quarantine or save report. So I saved a report, but just like u said its way too big to post on here. So now I need to know, do I quarantine for now, or just delete the things its found? Ok u also mention doing the same scan in "safe mode" should I do that after ive deleted/or quarantined or shall I just download hijackthis and run a scan with that oh and cheers for the replys really appreciate it Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Follow Up For Removal
|
|
Response Number 11
|
Name: btk1w1
Date: August 1, 2007 at 22:19:13 Pacific
|
Reply: (edit)Only quarantine the items a-squared automatically puts a tick against. 16,000+ files is a huge amount and I want to be sure we only disable for now what we need to. Before you run a hijackthis log download update and run these two programs. Firstly ccleaner: http://www.ccleaner.com/ this program will clean all your cached and temp files. Run this in normal mode after you download it. Second download SUPERAntispyware: http://www.snapfiles.com/reviews/Su... this is a malware removal application that scans the memory, registry and harddrive(s). Once downloaded, open and "check for updates". New lop malware definitions have been added. Now boot into safe mode and run the SUPERAntispyware scan. Select "Perform Complete Scan". Quarantine everything it finds. After this is done boot up normlly and open Avast from the desktop. Go to the menu button at the top left and "Schedule A Boot-time scan". Once the scan is complete post back how it went.
Report Offensive Follow Up For Removal
|
|
Response Number 12
|
Name: flashstatic
Date: August 2, 2007 at 02:31:01 Pacific
|
Reply: (edit)Ok ran that Ccleaner and that deleter about 9 meg in files. I then googled SUPERAntispyware but on just about ever site I reserched it on they say its a really bad program to download somthing about having its own spyware with it and a very hard program to delete as its leaves a load of junk behind. So though id just check back and get yr opinion on it first befor downloading it. Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Follow Up For Removal
|
|
Response Number 13
|
Name: btk1w1
Date: August 2, 2007 at 03:18:31 Pacific
|
Reply: (edit)Personally I use SUPERAntispyware and have never had a problem. Not to say others opinions don't count. I always take into account what users experiences have been. I'm glad you researched it and can only offer my personal experience. I have recomended this application on other occasions and it has worked a treat, not one negative feedback in fact. Also I use it myself regularly alongside spybot s&d, adaware and Avast antivirus (also I do run an online scan occasionally) and nothing unbecoming about this app has ever been detected. The team at snapfiles test all programs they host on their site for any spyware or adware (about halfway down the page is their guarantee). Also the page the link will direct you to has user opinions that you can read also: SUPERAntispyware from snapfiles with guarantee, user revews and download option: http://www.snapfiles.com/reviews/Su... If ever you are unsure about something you are going to install there are methods to do this safely. You can create a restore point (not always successful in the event something nasty was downloaded). You can scan the downloaded file with an av prog before installing (also not 100% risk free). But the best thing you can do is research. Which is what you've done. If you are still uncomfortable with going ahead with SAS you can always run a couple of online scans. A highly recommended malware one is xscan:
http://www.spywareinfo.com/xscan.php Other options are online virus scanners. Here are three of the most popular. Housecall.Trendmicro: http://housecall.trendmicro.com/ BitDefender http://www.bitdefender.com/scan8/ie... Panda http://www.pandasoftware.com/produc...
Report Offensive Follow Up For Removal
|
|
Response Number 14
|
Name: flashstatic
Date: August 2, 2007 at 15:07:06 Pacific
|
Reply: (edit)Ok 6 hours of scanning later SUPERAntispyware finally came to a stop so I quarentined all the items it found, and then did a system boot with Avast, which went great it didnt detect the swizzor virus anymore so I was very happy, but that all came crashing down infront of my eyes when it detects somthing called Win32:trojano-G [trj] and i get the same respose as the swizzor one it just locks up my computer and im unable to move to chest or delete even though there the options that it brings up So now im bk to square one and I get the feeling your gona tell me im screwed for some reason lol. any idears what to do next or is it a cast of ive been beaten? Mobo - ASUS P5GD1 GC - Radeon X600 CPU - P4 3.2 Ram - 1Gig
Report Offensive Follow Up For Removal
|
|
Response Number 15
|
Name: btk1w1
Date: August 2, 2007 at 20:27:14 Pacific
|
Reply: (edit)There are always ways to rid malware from your system, even if it is heavily infected. Only in extreme cases people sometimes have to resort to reformatting their hdd, but we're not there yet. First check for and install updates for SAS, spybot s&d and adaware. Now turn off system restore, click "start" > "all programs" > "accessories" > "system tools" > "system restore", click on "system restore settings" and put a tick in the box next to "turn off system restore" click "apply" and then "yes". This is prevent any malware re-infecting from the restore folders. Boot into safe mode and run SAS, complete scan. Ad-aware full system scan and then spybot s&d. Remove all they find. After they have finished boot up normally and run these online scanners. xscan: http://www.spywareinfo.com/xscan.php Housecall.Trendmicro: http://housecall.trendmicro.com/ BitDefender: http://www.bitdefender.com/scan8/ie... Keep a watch at the top of your screen for a yellow bar at the top of your screen from these sites requesting they run add-ons. Right click and allow. Once these scans are run I will need you to turn your system restore back on. Next download hijack this from link in response 9. Create a folder named "hjt" in C:\Program Files and save it there. Navigate to the .exe file you downloaded right click it and rename it to scanme.exe (this is just a random name to prevent detection). "Do a system scan and save a logfile" copy and paste the details from the logfile back here so I can analyse it and see whats lurking.
Report Offensive Follow Up For Removal
|

|

|

Post Locked
This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
Go to Security and Virus Forum Home
|
|
|