PDA

View Full Version : did i get a virus?



Little Whiskey
08-05-2010, 09:39 AM
This morning i go to log on to my computer and the screen is blank, but the mouse curser is visible. I cannot reset my computer from the keyboard (control, alt, delete) so i hit the manual reset button on the tower. after it restarts, i get a popup screen that says Wireshark has detected a bunch of infected files. I've tried to close that screen, but to no avail. it wants me to click on either continue scanning or to buy somthing. I then tried to restart the computer. same thing happens when it comes back up. I've never seen this program before on my computer, but it looks official.

thanks for the help in advance.

MadScientist
08-05-2010, 10:02 AM
Here's some more information on the virus/scam you picked up, with links to removal instructions
http://answers.yahoo.com/question/index?qid=20100804130154AA2p56X

Time to ditch IE.

Little Whiskey
08-05-2010, 10:17 AM
Thanks MS, I'm going to give it a try.

I just saw my life pass before my eyes when this thing poped up. I realized i hadn't backed up our family pics in a while and my wife would kill me if those were lost.

Its weird that that computer would catch something. Its not used that often. but is always on and connected to our wireless internet. strange.

Little Whiskey
08-05-2010, 12:07 PM
Worked like a champ! .......so far.

I downloaded a program from malwarebytes.org and it found about 50+ files infected. deleted them all and restarted the computer. good to go!

hoosier
08-05-2010, 03:44 PM
Did you remember to run it in safe mode? Otherwise you might be able to delete the files but the malware will probably be able to rewrite them.

Freak Out
08-05-2010, 04:31 PM
What are you running for virus protection? What warez and porn sites were you on? :lol:

Little Whiskey
08-05-2010, 05:37 PM
Hoosier---I had to reboot in safe mode w/ networking. this damn program wouldn't let you open any program.

freak----Its norton, but its old. ive read that it could have come from flicker or youtube.

Freak Out
08-05-2010, 09:26 PM
Hoosier---I had to reboot in safe mode w/ networking. this damn program wouldn't let you open any program.

freak----Its norton, but its old. ive read that it could have come from flicker or youtube.

Go AVG free or Microsoft security essentials for free. The NEW Norton is actually pretty nice if you don't mind paying for that kind of stuff. Oh ya.....ditch IE if you are still using it.

MJZiggy
08-05-2010, 09:29 PM
If my formerly fast fios is now running too slow to keep up with streaming, could that be a virus too? I'm running AVG and it doesn't find anything. If it's not a virus, why is it so slow these days?

pbmax
08-05-2010, 09:38 PM
LW, good to hear its better, but even malwarebytes will not get rid of everything.

I suggest you go here: http://forums.majorgeeks.com/

register for a user name using the Register link at the top of the forum list or here: http://forums.majorgeeks.com/register.php

and follow these instructions from the malware removal forum: http://forums.majorgeeks.com/showthread.php?t=35407
This thread is called "READ & RUN ME FIRST. Malware Removal Guide"

I have used these guys several times on my own and family computers and they haven't let me down yet. They will even review the reports from the scans you run and tell you if anything left is suspicious. For the fastest response, try to follow all the directions exactly as posted. If you combine steps or skip them, they will not respond. Once you get to the step by step section for your OS, I suggest printing the instructions so you don't have to go back to the website after every restart.

Only run the suggested scans in safe mode if you cannot log in normally. If you cannot get internet, you can download the install files from another computer. Each program that needs updated definitions usually has a link to allow you to manually download the latest updates. Then burn the installer and update files to a CD on another computer and print the instructions. if you close the CD-R session, even an infected computer will not be able to tamper with your CD files.

It will take some time, but will work. Good luck.

Freak Out
08-05-2010, 10:32 PM
If my formerly fast fios is now running too slow to keep up with streaming, could that be a virus too? I'm running AVG and it doesn't find anything. If it's not a virus, why is it so slow these days?

Something is running and hogging bandwidth or the service is overloaded with customers downloading porn and pirated media. :)

mraynrand
08-06-2010, 11:16 AM
If my formerly fast fios is now running too slow to keep up with streaming, could that be a virus too? I'm running AVG and it doesn't find anything. If it's not a virus, why is it so slow these days?

Something is running and hogging bandwidth or the service is overloaded with customers downloading porn and pirated media. :)

Skinbasket Ho!

MJZiggy
08-06-2010, 05:26 PM
No, nothing major is running. I haven't even loaded CS yet.

retailguy
08-06-2010, 08:03 PM
No, nothing major is running. I haven't even loaded CS yet.

Download the free trial of tune up utilities. I find the registry cleaner pretty good and is the likely source of your problems.

I believe the program is free for 15 days with no limitiations (at least it used to be), I find it worth the money, but you can find a torrent download on the pirate bay or demonoid if you don't want to pay for it.

http://www.tune-up.com/download/

MJZiggy
08-06-2010, 08:48 PM
Verizon said it was my RWIW and sent me to Microsoft for a patch. I get an error installing the patch and now am on permanent hold with Microsoft tech support. Someone bring me a drink...

retailguy
08-06-2010, 09:57 PM
Verizon said it was my RWIW and sent me to Microsoft for a patch. I get an error installing the patch and now am on permanent hold with Microsoft tech support. Someone bring me a drink...

Well, if the computer isn't outdated when you get off the phone, give my idea a try... :wink:

MJZiggy
08-06-2010, 10:19 PM
Verizon said it was my RWIW and sent me to Microsoft for a patch. I get an error installing the patch and now am on permanent hold with Microsoft tech support. Someone bring me a drink...

Well, if the computer isn't outdated when you get off the phone, give my idea a try... :wink:

I've been on with folks, first from Verizon and then Microsoft since 8-ish. I think I'm outdated by now, lol.

Freak Out
08-07-2010, 12:41 AM
Hardware/software breakdown please.

MJZiggy
08-07-2010, 05:00 PM
Toshiba 4g 64 bit T6500@2.1 gh Vista and Office is the only space hog. AVG FIOS. Verizon says FIOS doesn't play well with Vista (which would have been nice to know BEFORE I bought the damned service) so I need a patch which we eventually got to download but now I just need to back everything up before I install the patch.

MJZiggy
08-08-2010, 06:59 AM
Verizon said it was my RWIW and sent me to Microsoft for a patch. I get an error installing the patch and now am on permanent hold with Microsoft tech support. Someone bring me a drink...

Well, if the computer isn't outdated when you get off the phone, give my idea a try... :wink:

Didn't work, but it was worth a try...

Brando19
08-08-2010, 10:59 AM
Why is everyone against IE and if I ditch it, what do you recommend?

MJZiggy
08-08-2010, 11:24 AM
Firefox or chrome.

Joemailman
08-08-2010, 12:34 PM
I found both Firefox and Chrome to be much faster than IE. Actually, I haven't used IE in ages, so perhaps that's no longer the case. I do have the same problem Zig has with playing videos, even though my online connection seems quite fast otherwise.

MJZiggy
08-08-2010, 01:12 PM
The other day Verizon told me my RWIN number was too small :oops: and that I needed a patch. Today's Verizon guy tell me I have a virus somewhere (AVG's full scan came up with nothing). He says my CPU usage is too high, but that he doesn't know about the technical RWIN number but that I should call Toshiba ($35.00) to have them deal with it seems almost worth it at this point.

MJZiggy
08-08-2010, 08:12 PM
Does anyone know if AVG and Malware Bytes do the same thing or are they discrete?

Malware Bytes found a bit of adware that AVG missed but I know I can't run two anti-virus programs at the same time.

pbmax
08-09-2010, 02:53 PM
Does anyone know if AVG and Malware Bytes do the same thing or are they discrete?

Malware Bytes found a bit of adware that AVG missed but I know I can't run two anti-virus programs at the same time.
AVG was originally a traditional anti virus program. But if you are running a newer version, it also scans for malware (adware, bots, etc.). Most infections these days are transmitted through the internet.

Malwarebytes was designed specifically to find malware that originated over the internet. So there is overlap. The free version of Malwarebytes does no active scanning. So unless you bought it, there probably is no conflict.

However, all programs tend to label lost of things ad ware that are really innocuous. for instance, some programs label tracking cookies as malware since the owner of the cookie can then review your browsing history. But many legit sites use them. So much depends on what malware the program found. If it was just cookies, I would not be too worried. In fact, when I scan with these programs, I ignore the cookies unless something else has been downloaded along with it.

I would suggest you also go to majorgeeks.com and while it will take some time, they probably can give you peace of mind that you are not infected. Then you can use that piece of mind to yell at your vendors for giving you the run around. Frankly, it doesn't sound like you have malware issues, unless there is other behavior beyond the slowness and CPU spiking.

hoosier
08-09-2010, 03:28 PM
The other day Verizon told me my RWIN number was too small :oops: and that I needed a patch. Today's Verizon guy tell me I have a virus somewhere (AVG's full scan came up with nothing). He says my CPU usage is too high, but that he doesn't know about the technical RWIN number but that I should call Toshiba ($35.00) to have them deal with it seems almost worth it at this point.

Did you remember to tell them it's not length but width that counts?

mraynrand
08-09-2010, 04:57 PM
The other day Verizon told me my RWIN number was too small :oops: and that I needed a patch. Today's Verizon guy tell me I have a virus somewhere (AVG's full scan came up with nothing). He says my CPU usage is too high, but that he doesn't know about the technical RWIN number but that I should call Toshiba ($35.00) to have them deal with it seems almost worth it at this point.

Did you remember to tell them it's not length but width that counts?

He did:

http://i453.photobucket.com/albums/qq254/mraynrand/FavreBrown.jpg

MJZiggy
08-10-2010, 09:51 PM
The other day Verizon told me my RWIN number was too small :oops: and that I needed a patch. Today's Verizon guy tell me I have a virus somewhere (AVG's full scan came up with nothing). He says my CPU usage is too high, but that he doesn't know about the technical RWIN number but that I should call Toshiba ($35.00) to have them deal with it seems almost worth it at this point.

Did you remember to tell them it's not length but width that counts?

He did:

http://i453.photobucket.com/albums/qq254/mraynrand/FavreBrown.jpg

I think I need a larger patch than that.

Joemailman
08-10-2010, 10:29 PM
Can't believe that picture has made it into 2 different threads. Disturbing.

Little Whiskey
08-13-2010, 10:09 AM
somthing's back again......i think.

I cannot get the pc to get log on to the internet. It shows that i am connected, but the IE goes to a fail page. I've re-ran malwarbytes and its found nothing. I've not used that computer since i thought i fixed it. I went to fire it up today to install Firefox like other have suggested. this pc has no other browsers on it other than IE. However, i was able to update my version of Malwarebytes. wierd? how can i tell if its a virus issue or a software/hardware issue?

MadScientist
08-13-2010, 01:05 PM
somthing's back again......i think.

I cannot get the pc to get log on to the internet. It shows that i am connected, but the IE goes to a fail page. I've re-ran malwarbytes and its found nothing. I've not used that computer since i thought i fixed it. I went to fire it up today to install Firefox like other have suggested. this pc has no other browsers on it other than IE. However, i was able to update my version of Malwarebytes. wierd? how can i tell if its a virus issue or a software/hardware issue?

Lots of things can screw up networking. First thing to try is rebooting the router (you may have to pull the plug since they often don't have switches despite needing them). Even if other computers can connect, the router can still be a problem for another computer. If that fails, reboot the system, and check any firewall settings to see that IE is actually allowed to connect to the internet.

If that fails, copy all your files off, paint a target on the box and shoot the damn thing. It's earned it.

Freak Out
08-13-2010, 01:26 PM
somthing's back again......i think.

I cannot get the pc to get log on to the internet. It shows that i am connected, but the IE goes to a fail page. I've re-ran malwarbytes and its found nothing. I've not used that computer since i thought i fixed it. I went to fire it up today to install Firefox like other have suggested. this pc has no other browsers on it other than IE. However, i was able to update my version of Malwarebytes. wierd? how can i tell if its a virus issue or a software/hardware issue?

Lots of things can screw up networking. First thing to try is rebooting the router (you may have to pull the plug since they often don't have switches despite needing them). Even if other computers can connect, the router can still be a problem for another computer. If that fails, reboot the system, and check any firewall settings to see that IE is actually allowed to connect to the internet.

If that fails, copy all your files off, paint a target on the box and shoot the damn thing. It's earned it.

Exactly.....if you are running through wireless router/router that is your problem... disconnect the power from the router for a 10 count and you should reconnect. I was on an open cable network once and I was attacked daily and the things firewall was always shutting off traffic....what a pain.

retailguy
08-13-2010, 01:29 PM
somthing's back again......i think.

I cannot get the pc to get log on to the internet. It shows that i am connected, but the IE goes to a fail page. I've re-ran malwarbytes and its found nothing. I've not used that computer since i thought i fixed it. I went to fire it up today to install Firefox like other have suggested. this pc has no other browsers on it other than IE. However, i was able to update my version of Malwarebytes. wierd? how can i tell if its a virus issue or a software/hardware issue?

Old versions of Norton Antivirus were notorius for this type of crap. Personally, I unplugged Norton several years ago and have never looked back. I'm using Microsoft Security essentials now, and it does a pretty good job. Plus it's free. I've also used the free version of AVG. Both are much better than Norton ever was.

retailguy
08-13-2010, 01:31 PM
somthing's back again......i think.

I cannot get the pc to get log on to the internet. It shows that i am connected, but the IE goes to a fail page. I've re-ran malwarbytes and its found nothing. I've not used that computer since i thought i fixed it. I went to fire it up today to install Firefox like other have suggested. this pc has no other browsers on it other than IE. However, i was able to update my version of Malwarebytes. wierd? how can i tell if its a virus issue or a software/hardware issue?

Lots of things can screw up networking. First thing to try is rebooting the router (you may have to pull the plug since they often don't have switches despite needing them). Even if other computers can connect, the router can still be a problem for another computer. If that fails, reboot the system, and check any firewall settings to see that IE is actually allowed to connect to the internet.

If that fails, copy all your files off, paint a target on the box and shoot the damn thing. It's earned it.

Exactly.....if you are running through wireless router/router that is your problem... disconnect the power from the router for a 10 count and you should reconnect. I was on an open cable network once and I was attacked daily and the things firewall was always shutting off traffic....what a pain.

I don't think the problem is the router as he was able to update malwarebytes from the problem laptop. The router should stop all traffic, not just IE.

pbmax
08-13-2010, 11:16 PM
Some malware removers can break a network connection depending on the type of fix it must apply. Although its an open question to me whether it would then be able to connect for an update.

If typical troubleshooting doesn't help, you could try to download Super Anti Spyware. Its a free scanner as well. Occasionally, it will find things that Malwarebytes doesn't.

The advantage to SAS is that it includes some commands to fix broken services after you have removed malware. A broken internet connection is one of the repairs it can perform. But I would try this only if basic troubleshooting fails.

SAS can be found here: http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE

Directions can be found here for XP/Vista/Seven: http://forums.majorgeeks.com/showthread.php?t=127217

Little Whiskey
08-16-2010, 11:52 AM
I unplugged the router and turned it back on......still can't get IE to load up.

I've installed and ran SAS. It found a some things that Malwarebytes missed........but still can't get IE to connect to the internet

As was suggested i removed my old version of Norton.......still can't get IE to connect.

this is strange. the icon in the lower left of my screen says that it is connected, but IE pops up a failed page when i try to open it.

Could it be an issue with IE? can i download a copy of firefox, could i be able to connect thru that?

ugh! :?

Little Whiskey
08-16-2010, 01:08 PM
I tried installing the AVG 9.0, i was told my version of windows is too old. WTF! its XP!

retailguy
08-16-2010, 03:39 PM
I suspect that the virus has changed your internet settings. Installing firefox might work, and it might not. Depends on the settings.

Are you familiar with the settings in IE on the tools menu, select internet settings...

I'll see if I can find something that'll walk you though it.

I think the PC is online, I just think it's mis-configured.

Little Whiskey
08-16-2010, 03:43 PM
thanks retail

I installed Firefox and figured out how to get it to work. Proxy settings were screwed with. (fyi, i needed help figuring out what the hell that was! i still don't know, but at least whatever i did worked....kinda) However, i can't get IE to work. I'm now trying to update XP, but for some reason evertime i try clicking on the update on Microsofts website, the page won't open in Firefox. maybe microsoft is pissed that i'm not using IE.

retailguy
08-16-2010, 03:47 PM
thanks retail

I installed Firefox and figured out how to get it to work. Proxy settings were screwed with. (fyi, i needed help figuring out what the hell that was! i still don't know, but at least whatever i did worked....kinda) However, i can't get IE to work. I'm now trying to update XP, but for some reason evertime i try clicking on the update on Microsofts website, the page won't open in Firefox. maybe microsoft is pissed that i'm not using IE.

Windows update only works in IE. You can find specific things via firefox and update using firefox, but the update tool only works with IE.

Open the settings in firefox, then open the settings in IE. Figure out which one is causing the issue. As I recall (and it's been literally 5 years since I've used IE), that they're named differently but you should be able to sort the similarities.

My guess is you've got a proxy server controlling IE. Remove that and it'll probably work.

retailguy
08-16-2010, 03:49 PM
this shows how to display proxy settings in both browsers.

http://www.ehow.com/how_6352794_fix-proxy-server-settings.html

Sparkey
08-22-2010, 10:43 AM
ATFCleaner
Combofix
Spybot seek and destroy
Malware Bytes
Comodo
Hijack This

All good tolls, although some can destroy your registry if you don't know what you are doing with them.