Computing.Net > Forums > Security and Virus > Virus that won't let Virus Scan Run

Virus that won't let Virus Scan Run

Reply to Message Icon

Original Message
Name: Peter Monaghan
Date: November 10, 2002 at 14:00:09 Pacific
Subject: Virus that won't let Virus Scan Run
OS: Win 98
CPU/Ram: Pentium 128
Comment:

I think I have a virus that will not let me run virus scan software. When i run and old copy of Mcaffee or "the cleaner" the applications close after a few seconds. It also gave me problems accessing the internet. I had to remove my Norton firewall to get back to the internet. Finally, I got a strange message yesterday in a black chat box calling me names (from god it claimed). I tried to talk back to it (it called me "you") but I guess the person had gone. The other think that happened is that I lost my yahoo email id (bad password it said) but I did not change my password (i am trying to get yahoo to help me).

It sounds like someone is trying to hack into my system. Note my business applications word, accounting etc still seem to work. Any ideas would certainly be appreciated. The email address above is my wife's.



Report Offensive Message For Removal

Response Number 1
Name: Dennis
Date: November 10, 2002 at 14:11:22 Pacific
Subject: Virus that won't let Virus Scan Run
Reply: (edit)

The virus scanner wont work.... sounds like the Bugbear virus. Problem connecting the internet.... sounds like the Bugbear virus.
Problem with E-mail... don't know. You can try the Bugbear removal tool...
Good luck, Dennis

http://securityresponse.symantec.com/avcenter/tools.list.html


Report Offensive Follow Up For Removal

Response Number 2
Name: CompGuy
Date: November 10, 2002 at 14:20:29 Pacific
Subject: Virus that won't let Virus Scan Run
Reply: (edit)

Sounds like a trojan or a virus.

Using a different computer either a friends or family member download F-PROT Antivirus for DOS. Make sure their computer is virus free before continuing!

You will need to create 3 brand new floppy rescue disks!

Rescue Disk 1
1. Format the first rescue disk using the following command line which will copy system files onto the disk allowing you to boot in DOS with the disk:
FORMAT A: /S
2. Copy the following files onto the disk:
F-PROT.EXE
F-PROT.INI
MACRO.DEF
ENGLISH.TX0
3. Write protect the disk.
4. Label the disk: F-PROT Rescue Disk 1: MACRO.DEF (This Disk Is Bootable)

Rescue Disk 2
1. Copy SIGN.DEF onto this disk.
2. Write protect the disk.
3. Label the disk: F-PROT Rescue Disk 2: SIGN.DEF

Rescue Disk 2
1. Copy SIGN2.DEF onto this disk.
2. Write protect the disk.
3. Label the disk: F-PROT Rescue Disk 3: SIGN2.DEF.

Now at your system:
1. Turn it off for at least 60 seconds.
2. Insert F-PROT Rescue Disk 1, and start your computer.
3. Once the disk loads to a command prompt type in: F-PROT.EXE /LOADDEF
4. Insert the proper disk which contains SIGN.DEF, and SIGN2.DEF when prompted. It will ask should ask for the first disk to be inserted last which contains the F-PROT.EXE file.


Report Offensive Follow Up For Removal

Response Number 3
Name: wawadave
Date: November 10, 2002 at 20:28:39 Pacific
Subject: Virus that won't let Virus Scan Run
Reply: (edit)

hello
as for some one trying to hack your system they allready did. and they stole you yahoo pass word and changed your pass word.
i would change all pass words and if you had any crdite card or banacont numbers consider them compormized tottaly.


Report Offensive Follow Up For Removal

Response Number 4
Name: Imp
Date: November 10, 2002 at 23:51:23 Pacific
Subject: Virus that won't let Virus Scan Run
Reply: (edit)

Hello Peter,
I have been reading all post answered to you, and of course I believe it gave you a solution to resolve the problem.
What I don't understand is why nobody mention simply there is some specialized programs to eradicate Trojan's easily without any manipulation of the primordial files of your computer ?
If you do any mistake by changing the contents of any "ini" files, all your computer will crash irremediably !!!!
Blue screen or frozen screen !!!
Trojan Remover is an excellent program made by english conceptor Nigel, which created it especially to help users without any particular knowledge in computers configuration. His program destroy any Trojan virus known actually as well as to restore all files corrupted to come back to the original configuration you had before the corruption.
http://members.aol.com/simplysup/tremover
Try it.......


Report Offensive Follow Up For Removal

Response Number 5
Name: Johnny
Date: November 11, 2002 at 05:15:33 Pacific
Subject: Virus that won't let Virus Scan Run
Reply: (edit)

Sounds to me someone sent you and then you executed a remote access trojan called Optix Pro 1.2. And the server, what you opened, used a special sub 7 virus method that will stop you executing other executables. Also, the sender, enabled both the antivirus and firewall kills which scans for and stops those processes every 45 seconds.

That sub 7 is difficult to remove even if you had an antivirus running, however with patience you can do it manually if you follow the step - by - step instructions at the Symantec site - just search for the trojan by name. It's undoubtedly a trojan because to message you like that they've remote access of your machine when on the net.

I guess only a kid or an idiot or both would give themselves away so easily showing off like that and I doubt whether they have the sense to hide from you by connecting via a socks4 or socks5 proxy, thereby hiding their real ip address. You can't check your firewall connection logs now but, unless they've killed netstat.exe on your system, the next time they intrude you'll find their ip via that command prompt... that's assuming you'd like some retribution.


Report Offensive Follow Up For Removal


Response Number 6
Name: WhoDunnit
Date: November 11, 2002 at 13:18:57 Pacific
Subject: Virus that won't let Virus Scan Run
Reply: (edit)

Yaha and Klez also can fit that description.


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Virus that won't let Virus Scan Run

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software