Computing.Net > Forums > Security and Virus > Screenshot Virus

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Screenshot Virus

Reply to Message Icon

Name: daytripper
Date: March 13, 2005 at 15:51:42 Pacific
OS: Windows XP Professional
CPU/Ram: Pentium 4/448MB
Comment:

I've tried for the past two months to get rid of a virus that has been plauging me so I decided to get some outside help. This virus basically takes a screenshot of my screen every minute or so. Normally I wouldn't mind this but when it takes a screenshot, it replaces whatever I have on clipboard. Anyone know what this is? how to get rid of it?



Sponsored Link
Ads by Google

Response Number 1
Name: michael2
Date: March 13, 2005 at 16:34:42 Pacific
Reply:

It helps to give the name of the virus.
What have you tried to get rid of it?
Have you tried running your AV in 'SafeMode'?
Tried an online scan?


0

Response Number 2
Name: daytripper
Date: March 14, 2005 at 05:59:23 Pacific
Reply:

i don't know the name of the virus. i've ran a symantec scan, adaware, spybot search and destroy, and microsoft spyware scan. I haven't tried running adaware in safe mode, didn't know you could. i'll try though. which online scans would you recommend?


0

Response Number 3
Name: jboy
Date: March 14, 2005 at 08:11:38 Pacific
Reply:

How have you determined that the problem is caused by virus?

Give me ambiguity or give me something else


0

Response Number 4
Name: daytripper
Date: March 14, 2005 at 11:27:02 Pacific
Reply:

it acts like a virus but i'm not sure that it's a virus. it could be something else but whatelse could it be?


0

Response Number 5
Name: jboy
Date: March 14, 2005 at 12:06:35 Pacific
Reply:

That's a very good question. It just seems that whenever someone encounters something in Windows that they don't understand, they immmediately cry "virus!"

If multiple scans by different AV software fail to find one, the chances are it's not.

Trojans and adware are not necessarily going to be detected by AV - frequently you need to scan for those separately.

I'm not sure that I understand your description of the symptoms - the contents of the clipboard are replaced? I would tend to suspect an installed program, either misbehaving or performing contrary to expectations. You might check running processes with CTRL-SHIFT-ESC or else examine the startups with msconfig to see if there is any clue there.

Panda AV

SpywareGuide

Give me ambiguity or give me something else


0

Related Posts

See More



Response Number 6
Name: daytripper
Date: March 14, 2005 at 17:53:51 Pacific
Reply:

i couple spyware, trojans, and true viruses into one category: viruses. i had the problem, spent 2 months trying to get rid of it, formatted my computer, and it's still there. sounds like some malicious script to me. maybe a boot virus?? and it basically takes a screenshot (same as pressing the "prt sc" button) every minute or so. i've looked at my running processes, i've looked at my startup processes. i'm not a novice, i just can't get rid of this thing. it might be piggy backing on another process like explorer


0

Response Number 7
Name: jabuck
Date: March 14, 2005 at 19:12:26 Pacific
Reply:

Tim, There are tools out there that will reveal the spyware or at least most of it.

Hijack This is a good one and can help identify the bogus files but usually you need someone to help you through the process. There are some tools to help read your HT log but usually don't help get rid of the problem files.

You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.

Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor.

Do not fix anthing yet. Let someone review your log. ---jabuck


0

Response Number 8
Name: jboy
Date: March 14, 2005 at 19:46:54 Pacific
Reply:

"i couple spyware, trojans, and true viruses into one category: viruses"

You may if you wish, but that wouldn't be accurate, and there are different strategies for detecting and removing each.

It doesn't really sound like malicious software, and boot virus are generally readily detectable by AV. HJT! might give you some indication, sure

Give me ambiguity or give me something else


0

Response Number 9
Name: daytripper
Date: March 15, 2005 at 04:38:24 Pacific
Reply:

i ran hijack this before i formatted my computer but it came up with nothing (besides what's supposed to be there). same thing happened this time. I tried the panda scan, it didn't find anything. and jboy, you're right, in general you shouldn't group them but i have no idea what the hell this thing is. if i had to place my money on something, i'd say it was back oriface 2000.


0

Response Number 10
Name: jboy
Date: March 15, 2005 at 09:51:05 Pacific
Reply:

Collectively that stuff is know as malware for easy reference, but they are different things and need to be treated as such in order to be dealt with.

BO2K

Taking screenshots doesn't sound like it serves any useful or malicious purpose


13. How can I tell if BO2K is running on my machine?

You will probably want to check your RunServices and Run registry keys as well as your startup groups to make sure that there isn't anything in there that you didn't specifically put in there (Good idea regardless!).

Give me ambiguity or give me something else


0

Response Number 11
Name: daytripper
Date: March 17, 2005 at 10:18:02 Pacific
Reply:

no luck. thank you everyone for your help but i think i'm going to format it again because new problems have arose.


0

Response Number 12
Name: jboy
Date: March 17, 2005 at 16:04:17 Pacific
Reply:

If you ever do make a determination, post back. All I can say is that it doesn't sound like any malicious program I'm aware of, nor has anything significant been detected by the various scans you've performed.

Give me ambiguity or give me something else


0

Sponsored Link
Ads by Google
Reply to Message Icon

Absolutely NO PC anonymit... E mail to myself ??



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Screenshot Virus

StartPage-CD is a virus? www.computing.net/answers/security/startpagecd-is-a-virus/10481.html

removing VBS/Psyme virus www.computing.net/answers/security/removing-vbspsyme-virus/10595.html

Spaces.1445 Virus: Using Rescue Dis www.computing.net/answers/security/spaces1445-virus-using-rescue-dis/5340.html