Computing.Net > Forums > Security and Virus > defender virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

defender virus

Reply to Message Icon

Name: Rudy
Date: September 4, 2002 at 13:27:25 Pacific
OS: **
CPU/Ram: **
Comment:

When i first realized the defender virus was on my pc i did a scan with norton, but norton didn't find a thing. So i went looking in my program files and saw some strange files i never saw before. I deleted the most of them but can't get rid of one. The defscangui.exe file. I'm pretty sure this file creates that link which makes that defender virus pupping up all the time. So i went looking in my reports in norton anti-virus, and i found i had been infected with a js.menger.worm and an w32 kleze@mm. So i put that worm in quarantaine and removed it later on. I'm not sure it's totally gone, but it wans't detected anymore. Then i came on this site and asked if someone could help me with this. They gave me some advice and links to sites which were very helpfull. So i found out that i had to download a removal tool To remove the other virus. I went downloading the klez.gen removal tool and followed the instructions. So i started my computer in safe mode, let the klez removal tool work but it didn't found a thing, i still get that defender virus popping up and that file defscangui.exe still is in my program files under the subdirectory acceleration software\anti-virus. I can't remove it 'cause when i try to remove it in dos, it says i can't get access to that file. I guess norton was infected by that time too 'cause norton didn't worked either so i re-installed it and did a live-update. Then i ran a scan again, but still didn't found a thing. I even downloaded a free scanner of worms, trojans and backdoors, but that scanner didn't find a thing either. So if it's not a w32 kleze@mm what could it be then? And what should i do about it?




Sponsored Link
Ads by Google

Response Number 1
Name: danna
Date: September 4, 2002 at 14:11:53 Pacific
Reply:

did you try scanning on norton's webstie


0

Response Number 2
Name: murve
Date: September 4, 2002 at 14:49:57 Pacific
Reply:

hi rudy,
what scanner are you talking about?
"Then i ran a scan again, but still didn't found a thing. I even downloaded a free scanner of worms, trojans and backdoors, but that scanner didn't find a thing either."
Try downloading from TDS a program called "Worm Guard". If the worm is still in your system it will find and destroy it.
To re-install norton use the norton's RNAV program to remove norton, then re-install norton and get the latest defs, then do a complete scan. if that doesn't work and if you can get into dos, download a free copy of F-Prot for dos from wilders.org and scan in dos. also see if you can remove the file in your registry by doing a find for defscangui.exe. if the find in the registry comes up with any values for that file delete the defscangui.exe value.
hope this helps,
murve


0

Response Number 3
Name: Rudy
Date: September 5, 2002 at 03:46:22 Pacific
Reply:

hi murve,
Those scanners are norton and swat it. I already re-installed norton and did an update, but that still didn't worked. So now i'm going to try the things you told me to do. Downloading those and hoping that'll work. I'll let you know


0

Response Number 4
Name: Rudy
Date: September 5, 2002 at 04:29:55 Pacific
Reply:

Well, i did all of those things. But none of them worked. I downloaded f-prot, but it couldn't find a thing. I searched for that file in my regestry, found two items of it. deleted one value, but couldn't delete the other value in my regestry. It always says it's in use by another user or program, but that's impossible 'cause i'm the only one working on this pc and there wasn't a single program working. I'm realy wondering what that file could be and how i can get rid of it.


0

Response Number 5
Name: murve
Date: September 5, 2002 at 06:36:34 Pacific
Reply:

hi rudy,
sorry to see that you can't find a solution.
can you check your directories and see if you have these files:Ms Spool32 & MS SPOOL32.exe and Ms Spool32.dat and also in your registry. if you do delete them as they are part of the trojan backdoor assasin. also check to see if you have these files in your directories and in your registry. they are hiding somewhere in your registry in a subdirectory in your run files: tvp and mgneyu4 if found delete the subkeys containing these values. for more info on trojans go to www.thepublicworks.com security section and link to simovits consulting>trojans by name, and by file.
hope this helps,all the best,
murve


0

Related Posts

See More



Response Number 6
Name: Rudy
Date: September 7, 2002 at 07:00:50 Pacific
Reply:

checked my directories and registery for those files. But i can't find any of those. And when i do delete the defscangui file in my regestry it keeps coming back all the time. I realy don't know what to do anymore. I can't find any related files to a backdoor asassin or trojan. I guess the only thing to do now is to clean my disc and do a formatation and defragmentation.
Well thx anyhow for your help.


0

Response Number 7
Name: Patton
Date: September 9, 2002 at 16:00:21 Pacific
Reply:

I have contacted eacceleration the creaters of the most horrible program I have come across ..I told them of my problem..the same plroblem every one is having..I had tried to hack it out of my registry..have been unsuccefull in my attempts it just kept coming back...they sent me a uninstall program..it worked ..I still had to manualy remove some files form my registry ones that add-aware did not remove..if you like I can email you the program ..just send me an email with you address and I will get it to you as soon as possible ..or you can contact eacceleration at this site just click on contact us http://www.eacceleration.com
my email address is plumpkin@hotmail.com
hope this helps everyone ..I know what a nightmare this program is ..I've been up all night a couple days trying to hack it out but this is much easyer ..add-aware is a must have to clean up some of the stuff left behind..look for it on Cnet...


0

Response Number 8
Name: Silent
Date: October 11, 2002 at 02:33:06 Pacific
Reply:

This is what worked for me.

In my regedit I got rid of anything to do with Acceleration Software International Corporation / Stopsign / Defscangui / Gator / Raven.exe / webscan and eAnthology

*with that raven.exe, it was in my windows\temp folder. Get rid of anything to do with that.

Once you have gone through each one of those. Right after do a find again, in other words scan twice. (make sure you delete each key and hit F3 to find next)

I got Ad-Aware from a friend installed it and removed everything it found. And have it running at startup.

It took me around an hour and a half to go through all that.

Don't even bother with the remove software in control panel I think it just tells it to hide when you do that.

Also try finding a reg cleaner. I hop that helps.

Silent


0

Response Number 9
Name: Silent
Date: October 11, 2002 at 02:59:13 Pacific
Reply:

Also This folder may be in your windows temp delete it also.

Windows\Temp\msohtml1\01\


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: defender virus

?'s about AVG and Defender Virus Scanner www.computing.net/answers/security/s-about-avg-and-defender-virus-scanner/1010.html

defender virus www.computing.net/answers/security/defender-virus/2020.html

defender virus www.computing.net/answers/security/defender-virus/2357.html