PDA

View Full Version : Virus problem maybe?



LA_MERC_Drax
May 16th, 2006, 01:29 AM
Everytime i start my computer up now, i see that little orangish yellow shield pop up in the bottom right part of the screen saying downloading updates. First time i noticed it, i was thinking no big deal, just normal updates, but it installed everything without notifying me first(which if i remember right, it tells you after downloading the updates, what the updates are and gives you options on them). So this screen pops up telling me to restart my computer, so i hit restart later. Well that damn window kept popping up like every 5 minutes, so i just restarted it to get it out of my way. Now, it takes awhile for windows to start up, and i notice these little glitches in my performance. Every once in awhile, the mouse will freeze in one place, flash a few times, and then after about 5 seconds, resume normal use. Annoying as hell when you're playing a game, and just plain annoying cause there's some crap on my computer and this close to the lan. Any ideas, i'd rather not have to reformat, because its looking like ill be offshore til the lan. I'm on a snail connection out here, so anything i have to d/l goes at a rate of 5 kb/s.

LA_MERC_Spark
May 16th, 2006, 07:15 AM
what i do here at the office is as follows... Go to add/remove programs and see if there's anything that shouldn't be there. Uninstall same. Then run Stinger, adaware se personal then spybot S&D 1.4. Make sure the definitions are updated for all of these b4 you run them. You can also try ewido... It seems to be able to stomp out lots of stuff. As a last resort you can get hijack this. Run the exe and save a copy of the scan. Then post it to one of the forums and let the guru's have a look.

http://www.lavasoft.de/software/adaware/
http://www.safer-networking.org/en/download/index.html
http://us.mcafee.com/virusInfo/default.asp?id=stinger
http://www.ewido.net/en/
http://www.hijackthis.de/

LA_MERC_LaTech
May 16th, 2006, 07:27 AM
Could have been Windows Security Update or something (Red, Green and Yellow Shield depending on your level, etc). Just an idea...

LA_MERC_M@lACHi
May 16th, 2006, 05:40 PM
Yeah, you got a bug in there. I just had the same issue with one of my customers and it turned out to be some malicious adware. Doing what Spark recommends will take care of it for you.

LA_MERC_Drax
May 16th, 2006, 05:48 PM
I've ran the adaware and BPS spyware adaware remover, although it won't update the BPS stuff. Gonna go ahead and put my hijackthis log on here, and ill try running stinger and spybot S&D in the mean time.

LA_MERC_Drax
May 17th, 2006, 03:57 AM
I've ran almost all of those programs that spark said, with the exception of spybot(some reason the file i downloaded to install it from them was corrupted, and it took me like 2 hours to get it). I can run BPS spyware adaware remover and the same files keep reappearing in there, seems to be some kind of file going in my cookies folder, i took a screen shot. I'm begining to think it may be something in the network out here, but who knows(well someone probably knows, but not i).

LA_MERC_Spark
May 17th, 2006, 07:46 AM
Now this is just an OPINION...so noone get all worked up, but Norton is a complete waste of system resources. It is just trash, and I would not have it on my machine. That being said, i assUme this is a work rig and not your own right? If it is your own get rid of that crap! Clamwin has so far proven to be a less invasive alternative. Also what are your security center settings. I turn the damn thing off completely. As far as your log. I would post it to one of the Hijackthis forums and let the gurus look at it. removing the wrong things can really ruin your day. Also worth mentioning that microsoft has offically admittied that some of the bugs you pick up now a days can NOT be removed without a total reformat. I have found several instances where that was the case. So... next step. Take whatever information you can get from your scans, and google the terms. You will find that there are several people that have had and fixed your problem. They can offer you specific steps including how to stop processes and delete files from a command prompt. Some even offer bat files that will do it for you. I've had to do that a couple times here at the office. Now looking at your scan snapshot all I see are tracking cookies. While these may allow a browsing profile to compiled, there's no real threat there. The fact that you say they keep showing back up with each scan could be the sign of the real problem.

42d3e78f26a4b20d412==