Computing.Net > Forums > Security and Virus > Can you help ID this virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Can you help ID this virus?

Reply to Message Icon

Name: matso
Date: September 5, 2006 at 20:48:22 Pacific
OS: WinXP
CPU/Ram: P4 1.8 Ghz/1 Gb PC2700
Comment:

Hi all,

My girlfriend was having some troubles with Norton not working right so I investigated. Can't get it to open (hangs). Can't get it removed/re-installed (shuts down).

More interestingly, can't even navigate into the norton AV directory from explorer/my computer - the screen shuts down right after I open it - while other directories I can peruse without problem.

Even stranger - any internet search for "antivirus" or specific antivirus programs (McAfee/Norton/Nod32/Kaspersky - anything) immediately causes that IE window to shut down. But I can search/navigate to other unrelated websites without any problem.

I even tried getting onto download.com and grabbing a trial of Nod32 just to scan the system - no luck - the window is shut down as soon as I type in Nod 32 into the text input and press enter.

I tried looking through regedit but again as soon as I get the registry open it immediately shuts down.

Her and her mom use the computer and they're still on (yes, it's true) dial-up, so they're not doing anything they shouldn't be. No Peer to peer stuff, no website downloads of weird files. Just email.

Anyone have any idea of what this might be? I can't even formulate a good search on Google because what's happening is so strange. Hoping for some expert advice. Worse comes to worse I'm just gonna format the thing and start over.

BTW her system is an old P3 or P4...running WinXP (probably shouldn't be).

Thanks in advance,
Matt Shaw




Sponsored Link
Ads by Google

Response Number 1
Name: Tufenuf
Date: September 5, 2006 at 21:10:34 Pacific
Reply:

matso< Whatever virus/trojan/malware that computer picked up most probably altered the hosts file (no extension). The hosts file is located in the C:\Windows\System32\drivers\etc folder. Between the lines is the generic Windows Xp hosts file.

____________________________________________

# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

___________________________________________

You can open the hosts file with Notepad and anything below

127.0.0.1 localhost


can be removed in Notepad and after you remove it save the changes and close it. DO NOT remove the 127.0.0.1 localhost

Some viruses place all the Antivirus sites into the hosts file and that's why you can't reach those sites.

Tufenuf


0

Response Number 2
Name: matso
Date: September 6, 2006 at 14:00:51 Pacific
Reply:

Tufenuf,

Thanks for the advice. I'll give it a shot tonight and let you know how it goes.

Matt


0

Response Number 3
Name: bigdirk
Date: September 6, 2006 at 14:04:11 Pacific
Reply:

I can't help with what virus that might be but I do have a couple fixes for you if you want them, but you are going to have to use a friends computer or an open computer at your local library, wherever you can use a computer and download some stuff. You need to go to majorgeeks.com and download Avast virus scanner (make sure you get the free one) and save it to either a jump drive or burn it to a cd. Take it back to your computer and run the setup. Let it do its thing and it will ask if you want to do a boot scan. Allow it to do the boot scan (it will work even if you have to force shut down your computer as long as you allow it) I have used a lot of different virus scanners and have found that Avast works the best and I get into some serious problems sometimes. Damn P2P sharing!!! I have some other ideas but these are a little harder to work with but if you want any additional help get back at me.

Big Daddy Dirk


0

Response Number 4
Name: matso
Date: September 6, 2006 at 19:48:20 Pacific
Reply:

Tufenuf and Big Daddy,

An update:

The hosts file was totally clean. I fully expected to find what I was looking for there, but there was nothing beyond the 127.0.0.1 local host line. Don't know what to make of this other than maybe there is another file somewhere that is hijacking the normal hosts file and denying access to particular websites.

Secondly, I cannot get any antivirus program to load. I tried Avast and it will not progress into the setup wizard. It starts loading, and then just shuts down after a few seconds. Tried this multiple times, both loading from a flash drive and from a CD, in normal mode and in safe mode. I can install non-antivirus programs without difficulty (for example I tried reinstalling some of her camera software and that works fine).

At a loss...thinking her system needs to be formatted but I'm so annoyed by this now that I have a need to beat this virus. I'm by no means an expert but I am an advanced user, and I can usually take care of my own problems...but this thing is taxing me and forcing my hand into at least indentifying it!!

If you or anyone else have any further suggestions I'd love to give them a try.

Thanks for your continued help.

matt


0

Response Number 5
Name: Tufenuf
Date: September 6, 2006 at 20:42:14 Pacific
Reply:

matt, Try running your anti-virus program in SAFE mode.

How to Start Windows in Safe Mode

http://www.pchell.com/support/safemode.shtml

Also bring up Task Manager (Alt/Ctrl/Del) and see if there's some oddball process running and end process on it. You could check the processes by doing a google search which may help locating the culprit.

Tufenuf


0

Related Posts

See More



Response Number 6
Name: matso
Date: September 6, 2006 at 21:13:22 Pacific
Reply:

Tufenuf,

I've tried running Norton in Safe Mode...can't do it. Shuts down every time. I've also checked the running processes but there's nothing that's definitely abnormal looking...but I'll check again tomorrow and google anything I don't recognize.

Matt


0

Response Number 7
Name: the_elder
Date: September 7, 2006 at 02:42:47 Pacific
Reply:

The office worm virus also seems to add the spyware Hide Folders. This software gathers porn related data in one folder. It sometimes gathers content also wich is not porn, probably because it doesn't work "perfect".

Hide Folders uses these files to send spam mail out from your email account(s).

Best thing to do is to format your hardrive.


0

Response Number 8
Name: sydneyb
Date: September 7, 2006 at 16:20:17 Pacific
Reply:

All your processes check out ok IE: files/folders located where they should be?


0

Response Number 9
Name: jtsgellatly09
Date: September 10, 2006 at 17:36:43 Pacific
Reply:

Hi there mr.matso i have the SAME problem, and while i havent solved it completely i have found a temporary cure. Go to your task manage by ctrl alt delete. you say to yourself i cant cause it just closes as it did for me, but this time go to task manage let go of delete but hold ctrl and\or alt and the window will stay open. while holding it open go to processes and look at the ones with your name, not the SYSTEM, NETWORK SERVICE, or LOCAL SERVICE.while looking at these any ones that you cant recognize the program it originates from ie escatyd.exe just let me know the file name. if you can tell what it is such as viewmgr.exe, or dsentry.exe or taskmgr.exe dont bother to list it to me. once you list these i will tell you the ones to end and you will be able to use your computer as normal. note this is a temporary fix, upon every restart you will have to end a new task


0

Response Number 10
Name: Delzac
Date: September 11, 2006 at 06:33:24 Pacific
Reply:

i got this virus too 4 days ago, and u know what i did? anything that didn't come under user name SYSTEM i end it. after that i am able to go to any internet security web sites and type anti-virus will out it shouting down the window. try it, use the task manager, i worked for me.


0

Response Number 11
Name: jtsgellatly09
Date: September 11, 2006 at 12:04:32 Pacific
Reply:

you dont need to end allll of them, and most of them are actually essential parts to other programs. if matso u are still here tell me which programs are under task manager and i will tell you which one to end


0

Response Number 12
Name: kcha123
Date: September 13, 2006 at 02:40:04 Pacific
Reply:

HI,
Virus name is win32.VB.Dj.

find the removal kit in internet or check some of the start up in windows in safe mode with the help of msconfig or thirdparty software.

uncheck or del mscommonitem.exe
" Systemkernelfile.exe

and install kaspersky, avast, nod32 anti virus. Update and run/scan in safe mode.

note:

Installation can be done in normal mode.

best of luck with ur gf computer.


0

Sponsored Link
Ads by Google
Reply to Message Icon

Unkonwn virus/worm? diable spy blaster



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Can you help ID this virus?

Red X on C Drive - Can you Help? www.computing.net/answers/security/red-x-on-c-drive-can-you-help/22472.html

Can you help me? www.computing.net/answers/security/can-you-help-me/27060.html

Potential virus; can you help? www.computing.net/answers/security/potential-virus-can-you-help/3528.html