Computing.Net > Forums > Security and Virus > what's going on?

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

what's going on?

Reply to Message Icon

Original Message
Name: Glo
Date: November 7, 2007 at 19:05:36 Pacific
Subject: what's going on?
OS: WinXP 2002 Pro SP2
CPU/Ram: PIII 797 MHz/128 megs RAM
Model/Manufacturer: compaq deskpro
Comment:

Hmm where do I being, well first off I started to notice that when I searched something on google and clicked a link I would get redirected to another site. This happened for a day or two until I figured I might have spyware (and accused my brother of downloading something on my system). So I downloaded Norton Antivirus which scanned my computer and found a tracking cookie which I removed. I then downloaded Ad-ware and it found a Trojan downloader (I think it was win32 trojan). It also found more tracking cookies (over 700 infections) and some kind of MRU object?? I tried to remove as much as possible but got a lot of errors. Finally I did more scans and nothing was found. But now I can't even get on the internet (dns error) and it seems as though my internet history is being deleted. My computer is also on a network with the computer I'm using now, and when I scanned this one I found a tracking cookie on it too and I think it might also have that win32 trojan virus (when I scanned with Zone Alarm Pro, the scanning details kept reading, " scanning: win 32.trojan downloader, etc" but it said that it didn't find any infections, neither did Norton 360. We've always had problems with this computer, and have had to strip it twice. In microsoft outlook my mom keeps getting hundreds of junk emails) The info at the top is not for this computer but my other one. Any help? (please try to keep it simple, I don't know a lot about computers) Thanx :)


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: November 7, 2007 at 19:17:36 Pacific
Reply: (edit)

We will need to run a few scans to find the problem.

Please download SmitFraudFix from this link http://siri.urz.free.fr/Fix/Smitfra... Then right click on it> extract all> extract the contents to your desktop.

!!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!


Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd"
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Please download and install the latest version of HijackThis v2.0.2:

Download the HijackThis Installer from this link: HijackThis

1. Save " HJTInstall.exe" to your desktop.
2. Double click on HJTInstall.exe to run the program.
3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
4. Accept the license agreement by clicking the "I Accept" button.
5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
6. Click "Save log" to save the log file and then the log will open in Notepad.
7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
8. Paste the log in your next reply.
9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.


Report Offensive Follow Up For Removal

Response Number 2
Name: Razor2.3
Date: November 7, 2007 at 19:19:50 Pacific
Reply: (edit)

That was far too long without any whitespace, so I didn't read it. Instead, I'm just going to point to you towards this.

Also, I'd stay off of the warez/porn sites.


Report Offensive Follow Up For Removal

Response Number 3
Name: Glo
Date: November 7, 2007 at 19:59:54 Pacific
Reply: (edit)

oh haha sorry I didn't know what would be useful or not so I decided to put as much as possible. and ya my brother shares the computer with me but I think I'm going to change that...
Anyways, would you like me to scan both computers? I can't download anything on my other computer because I can't get on the internet so should I save and transfer it?


Report Offensive Follow Up For Removal

Response Number 4
Name: jabuck
Date: November 7, 2007 at 20:47:43 Pacific
Reply: (edit)

Just scan the one that can get on the internet and diconnect the other from the network if possible.


Report Offensive Follow Up For Removal

Response Number 5
Name: Razor2.3
Date: November 7, 2007 at 22:42:21 Pacific
Reply: (edit)

Assuming the one that can't get online is the one with the damaged TCP/IP stack, my previous post should help that one get online.

Also, don't worry about MRU's. They're just the list of recently opened documents/files that most programs like to keep. (FYI, it stands for "Most Recently Used." Doesn't sound as intimidating when written in full, does it?)


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software