Computing.Net > Forums > Security and Virus > do i have a virus?

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

do i have a virus?

Reply to Message Icon

Name: Derrick Hambly
Date: May 19, 2002 at 19:28:30 Pacific
Comment:

For the last few months I have been noticing that the amount of free space on my hard drive has been dropping for no reason at all (anywhere from around 500mb to 1gb). Every time I have noticed this, I have not recently downloaded or created any files that would use up even remotely close to that amount of space.

Also, I'm not sure if this is related or not, but I have two files in my windows directory called winserv.exe and winserv0.exe so are these supposed to be there or not?

This is leading me to think that I may have a virus or trojan, but when I run my virus scanner (InnoculateIT, most recent update) it finds no viruses anywhere. Any help would be appreciated. Oh yeah and I'm using Windows 98 SE.

Thanks.



Sponsored Link
Ads by Google

Response Number 1
Name: WhitPhil
Date: May 19, 2002 at 19:51:45 Pacific
Reply:

Winserv is a trojan. See this link.

http://www.computing.net/security/wwwboard/forum/385.html

Also you should install a firewall. www.zonealarm.com

And, I guess, an antivirus program.


0

Response Number 2
Name: murve
Date: May 19, 2002 at 20:43:20 Pacific
Reply:

Hi Derek,
Yes! you have a trojan.
Please follow Whitphil's plan and also download a 30 day trial of anti-trojan prog trojan hunter or purchase Boclean. Here's some info on the Trojan horse you've got-----Name: SoftWAR
Aliases: Shadow Thief, Softwarst, Softwar ShadowThieft,
Ports: 1207 (???)
Files: Softwar.zip - 327,765 bytes Soft-war.zip - 266,469 bytes Softwar.exe - 228,352 bytes Softwarst.exe - 357,738 bytes Trojan.exe - 60,928 bytes Swizard.exe - 79,872 bytes Winserv.exe - Infect1.exe - 16,896 bytes Infect2.exe - 21,504 bytes Sample1.exe - 4,096 bytes Sample2.exe - 8,192 bytes Pkzip.exe - 42,166 bytes Pegraft.exe - 72,192 bytes Mspr.dll - Server - 8,192 bytes Client - 94,720 bytes
Created: Oct 1999
Requires:
Actions: Remote Access / Keylogger

Versions:
Registers: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Notes: Works on Windows 95 and 98. English and French versions. Password=
Country: written in France
Program: Written in Assembler (Win32asm).
You can get more info on trojans from www.thepublicworks.com security section and click on simovits consulting. to remove it click on trojan removal to find out how to manually remove it, but i suggest downloading a copy of the progs i mentioned.
cheers,
murve


0

Response Number 3
Name: Derrick Hambly
Date: May 20, 2002 at 09:02:34 Pacific
Reply:

When I went to follow Whitphil's instructions, I did not have NetApp = C:\windows\system\winserv.exe in HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\

But I did see Win Server = C:\windows\winserv.exe so do I need to remove this entry from the registry?

I also downloaded Trojan Hunter and ran full virus scans with both HouseCall and InnoculateIT and none of these found anything. Also, it wouldnt hurt anything if I just deleted winserv.exe and winserv0.exe from my windows directory would it?

Any ideas? Thanks.


0

Response Number 4
Name: H Bezuidenhout
Date: May 20, 2002 at 17:25:32 Pacific
Reply:

Derrick,
Go to http://www.vbuster.com. Dr. Looi has one of the best anti-virus programs that can detect any virus. Read all about it on that site.
Cheers
Herman.


0

Response Number 5
Name: tinkerbong
Date: May 20, 2002 at 18:45:51 Pacific
Reply:

Addendum

Once you clear the keylogger from your system, CHANGE all your passwords.
If you use the net for banking or buying, check your statements for any fraudulent transactions. Your ID info MAY have been stolen.


0

Related Posts

See More



Response Number 6
Name: WhitPhil
Date: May 20, 2002 at 19:14:43 Pacific
Reply:

"But I did see Win Server = C:\windows\winserv.exe so do I need to remove this entry from the registry?"

YES


0

Response Number 7
Name: Derrick
Date: May 20, 2002 at 19:33:19 Pacific
Reply:

ok I removed the registry items and winserv.exe, but when I reboot my hard drive space is still down to 500 mb which it shouldnt be because I just deleted another gb of files before rebooting. Could this be another problem?


0

Response Number 8
Name: ]SpIkE[
Date: May 21, 2002 at 10:03:16 Pacific
Reply:

my answer to you.

Format, do a full format
and re-install.

i can give you an answer to fix ur problem.
but the best thing to do is just do a full format
and find some program that can check if your bios or cmos can be infected with the virus also.


0

Response Number 9
Name: Derrick
Date: May 21, 2002 at 16:58:11 Pacific
Reply:

alright I might reformat...but what is your other idea?


0

Response Number 10
Name: Regale
Date: May 22, 2002 at 17:14:38 Pacific
Reply:

IncoculateIt expired on the 15th. Did you buy E-Trust which is the program to replace it. I would say go where Herman said and download the antivirus program if you have not.


0

Response Number 11
Name: the Wop
Date: July 2, 2002 at 16:09:38 Pacific
Reply:

Winserve is a Trojan, here's the solution:

It comes from a IE Plugin named Net Search, it includes 4 files and the instructions for removal follow:
Manual Uninstall
1. Close Internet Explorer
2. Click Start
3. Click Run
4. type "regsvr32 systb.dll /u" (without the ")
5. Press "enter" OR "return"
6. type "regsvr32 winobject.dll /u" (without the ")
7. Press "enter" OR "return"
8. Type "msconfig" (without the ", msconfig is usually located in your windows/system directory)
9. Click on "Start Up"
10. "untick" Win Server
11. "untick" Win Server Updt
12. Restart your computer
== once computer restarted ==
13. Click Start
14. Click Search
15. Click For Files or Folders
16. Search for "systb.dll" (without the ")
17. Click on systb.dll on your right once it's found
18. Right mouse click and click on delete
19. Search for "winserv.exe" (without the ")
20. Click on winserv.exe on your right once it's found
21. Right mouse click and click on delete
22. Search for "wupdt.exe" (without the ")
20. Click on wupdt.exe on your right once it's found
21. Right mouse click and click on delete
20. Search for "winobject.dll" (without the ")
21. Click on winobject.dll on your right once it's found
22. Right mouse click and click on delete



0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: do i have a virus?

do i have a virus? www.computing.net/answers/security/do-i-have-a-virus-/1338.html

do i have a virus www.computing.net/answers/security/do-i-have-a-virus/4681.html

Do i have a virus please www.computing.net/answers/security/do-i-have-a-virus-please/18260.html