Computing.Net > Forums > Windows Me > A virus i think

A virus i think

Reply to Message Icon

Original Message
Name: sue
Date: November 10, 2003 at 20:50:53 Pacific
Subject: A virus i think
OS: windows me
CPU/Ram: toshiba
Comment:

Everytime i sign on instant messenger, in my AIM profile it says: Whoaaa....look at what I found, click here. WHen i click on it, it brings me to a site that says: This Account Has Been Suspended. I can't get it out of my profile. I can see at the bottom of my browser it says www.talkstocks.net when trying to load up. Someone please help me.


Report Offensive Message For Removal

Response Number 1
Name: smithdk
Date: November 10, 2003 at 21:26:58 Pacific
Subject: A virus i think
Reply: (edit)

See if this helps:

http://www.computing.net/security/wwwboard/forum/6937.html


Report Offensive Follow Up For Removal

Response Number 2
Name: wawadave
Date: November 10, 2003 at 23:16:33 Pacific
Subject: A virus i think
Reply: (edit)

hello/ sue
d/l spybot search and destroy,update it,run it. d.l ad-ware do the same. try these links
free trojin scan
http://www.trojanscan.com/trojanscan
panda scan
http://www.pandasoftware.es/activescan/
housecall
http://housecall.trendmicro.com/housecall/start_corp.asp
nrav av
http://www.ravantivirus.com/scan/
virus scan
http://www.bitdefender.com/scan/licence.php
avast cleaning tool
http://www.avast.com/i_idt_171.html
mcafee avert stinger
http://vil.nai.com/vil/stinger/
scans for open trojin ports
http://scan.sygate.com/pretrojanscan.html
test my sheilds grc
https://nanoprobe.grc.com/x/ne.dll?bh0bkyd2
dsl port scan
http://www.dslreports.com/scan
pest patrol scan mediocre
http://www.pestscan.com/Scan.asp
security scan
http://www.it-sec.de/index/inhalt/vulchk.php/?sid=2eb8ea121e57434616fa2c6f283c63b7


Report Offensive Follow Up For Removal

Response Number 3
Name: sonnysandiego
Date: November 10, 2003 at 23:21:56 Pacific
Subject: A virus i think
Reply: (edit)

Dave, bless you if you can help her.


Report Offensive Follow Up For Removal

Response Number 4
Name: kygirl
Date: November 11, 2003 at 11:55:07 Pacific
Subject: A virus i think
Reply: (edit)

did you figure out how to get rid of it? i have it, too.


Report Offensive Follow Up For Removal

Response Number 5
Name: kimzaprncess
Date: November 13, 2003 at 16:29:08 Pacific
Subject: A virus i think
Reply: (edit)

yea.. i just got it too.. i tried a symantec.com virus scan and it said I had no viruses, so I don't know what else to do! if you figured out how to get rid of it could u please email me? kimzaprncess@hotmail.com... thanks!


Report Offensive Follow Up For Removal


Response Number 6
Name: lucy
Date: November 13, 2003 at 17:44:29 Pacific
Subject: A virus i think
Reply: (edit)

I have the talkstocks.net virus also and i tried going to the registry to delete the value but it keeps coming back. I dont know what else to do. I dont know how I even got it cuz I had just gotten rid of the realphx virus. But the procedure I used for the realphx virus didnt work. so please email us infected people if you figure out how to get rid of it please! thanks!


Report Offensive Follow Up For Removal

Response Number 7
Name: krystv
Date: November 13, 2003 at 17:46:33 Pacific
Subject: A virus i think
Reply: (edit)

try this, it appears to be a fix

http://digitalmatter.net/index.php


Report Offensive Follow Up For Removal

Response Number 8
Name: mike
Date: November 13, 2003 at 19:46:44 Pacific
Subject: A virus i think
Reply: (edit)

I just got it as well. Right when I got it and THEN read the disclaimer [stupid me] and saw it was Ad-ware, i immediatly ran Spybot S+D, restarted and more spyware came back. I d/led ad-aware6, ran it... 10minutes later decided to check again, another 26 spyware comes up. I've been killing all the programs that seem fishy to me only then i am able to run AIM. before that AIM would freeze and I would have to restart.

Spy/Adwares seems to reproduce itself even after Spybot S+D and Ad-aware removes it. I was able to shutdown most of the 'fishy' looking programs and search for it on the computer and remove it. [I found programs like "vvlouit.exe" "rwhyliwf.exe" "WinFavorites" "SafeSurfing" "BargainBuddy" that never ran before]

Another thing, WScript.exe startsup now, and I understand it comes with Windows or something but it used to never auto-startup. I'm guessing it's using WScript to carry out some of the infections. If you try and delete WScript it re-creates itself since it's a windows file. It's a program to run scripts, so... i duno, seems fishy. Never auto-started and now it does after www.talkstocks.net

Ran 'The Cleaner', it found "BargainBuddy" to be a trojain. Hope this somehow helps people to find a fix for the adware reproducing itself.


Report Offensive Follow Up For Removal

Response Number 9
Name: dave
Date: November 13, 2003 at 20:06:23 Pacific
Subject: A virus i think
Reply: (edit)

i don't know what method it uses to infect, but i tried as hard as i could to find out, the site's source is too cryptic and full of crap to really be informative, but

1) change your homepage to something else
2) ctrl+alt+delete and end task "b" / "b.exe"
3) go into start>run>"msconfig">startup tab>uncheck "b" / "b.exe"
4) delete the file c:\windows\b.exe

it will be gone

send me an im at 'magisterofmayhem' if you need any more help


Report Offensive Follow Up For Removal

Response Number 10
Name: mike
Date: November 13, 2003 at 20:45:46 Pacific
Subject: A virus i think
Reply: (edit)

I think i got rid of it. There's more then just 'b.exe'. I belive these are some too that I got rid of:

Ctrl+Alt+Dlte these, then use Win's Search and find these files and remove it.
vvlouit.exe
rwhyliwf.exe

Use Spybot S+D and Ad-Aware to try and remove these:
WinFavorites
SafeSurfing
BargainBuddy

I think it installs more, i'm not too sure though.



Report Offensive Follow Up For Removal

Response Number 11
Name: dan
Date: November 13, 2003 at 21:20:41 Pacific
Subject: A virus i think
Reply: (edit)

hey everyone i found the fix! (i think...) delete your info, then hit ctrl alt dlt and under processes, end b.exe if its there, and most importantly gmt.exe. after you end these, search for them and delete them, along w/ the .pf file if there is one. then start menu, run, msconfig, and make sure there isn't anything strange that is checked under startup, including these programs. i think thats it... im almost positive the virus was gmt.exe. hope it works for u too...


Report Offensive Follow Up For Removal

Response Number 12
Name: Nathan Halstead
Date: November 14, 2003 at 07:22:07 Pacific
Subject: A virus i think
Reply: (edit)

The name of the virus is W32/Alphx.worm

Its not a new virus, but it is definately an annoying one. There's a nice article about it from October (found via Google news) here:
http://www.inform.umd.edu/News/Diamondback/archives/2003/10/22/news8.html

The web site mentioned in that article is the one that actually infected your system (it was loaded via javascript from the talkstocks.net page)

The University of Maryland has some fairly straightforward removal instructions at:
http://www.helpdesk.umd.edu/virus/alerts/proxybots.shtml

Just look under the "Realphx/Alphx" heading.

It would probably be nice if you linked to the rmeoval instructions in your profile for all your friends who may have been infected after you get yours cleaned up.

Good luck,
Nathan



Report Offensive Follow Up For Removal

Response Number 13
Name: cocobutter185
Date: November 16, 2003 at 08:25:18 Pacific
Subject: A virus i think
Reply: (edit)

do control alt delete and find b.exe and close that. and then search all files and folders for b.exe and if it comes up delete it. now go to ur profile and makes sure its working properly
i hope it works for you, i had it and it worked for me!
-cocobutter


Report Offensive Follow Up For Removal

Response Number 14
Name: Pimpstarr
Date: November 16, 2003 at 15:20:42 Pacific
Subject: A virus i think
Reply: (edit)

The virus discussed in the Maryland webpage is for an older version I think. This one has been modified. The b.exe method will work. I dont know of any gmt.exe. Hope you didnt delete somethin important :P. I love you all


Report Offensive Follow Up For Removal

Response Number 15
Name: T.Knight
Date: November 17, 2003 at 08:29:46 Pacific
Subject: A virus i think
Reply: (edit)

Ummm..I don't have the RealPhx virus, but some version of it. ON my proflie it says "Whoaa...look what I found!" I was just wondering what I should do to remove it. Thanks


Report Offensive Follow Up For Removal

Response Number 16
Name: Brit12
Date: November 17, 2003 at 14:25:51 Pacific
Subject: A virus i think
Reply: (edit)

I clicked on the link that said Whoaaa....look at this and it downloaded porn on to my computer, but I never got the link in my AIM profile. Any suggestions on how to get rid of it? I have noticed when I turn on my comp. a box pops up and asks for my zip code for a weather update


Report Offensive Follow Up For Removal






Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: A virus i think

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software