Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Worms?

 
Thread Tools Search this Thread
Old 09-18-2005, 10:27 PM   #1
Default Worms?


I don't know what's going on with my machine. I'll be visiting a site,
like CNN.com, and all of a sudden, I get a page not found screen with
"http:///" in the address bar. Before it'd go to the google search
page. It only seems to occur with IE and not with Mozilla Firefox. I
have done all the newest Windows updates, installed ZoneAlarm for
firewall purposes, run McAfee three times, used TrendMicro's HouseCall,
and everything, and yet it continues. I have gotten a detection message
from McAfee a couple of times for a p2p virus. Each time it says it's
been cleaned, but I'm still having problems. Anyone have any advice?
Thanks in advance!

SuzyElizabeth



TheThigILove@gmail.com
  Reply With Quote
Old 09-18-2005, 10:29 PM   #2
Imhotep
 
Posts: n/a
Default Re: Worms?
wrote:

> I don't know what's going on with my machine. I'll be visiting a site,
> like CNN.com, and all of a sudden, I get a page not found screen with
> "http:///" in the address bar. Before it'd go to the google search
> page. It only seems to occur with IE and not with Mozilla Firefox. I
> have done all the newest Windows updates, installed ZoneAlarm for
> firewall purposes, run McAfee three times, used TrendMicro's HouseCall,
> and everything, and yet it continues. I have gotten a detection message
> from McAfee a couple of times for a p2p virus. Each time it says it's
> been cleaned, but I'm still having problems. Anyone have any advice?
> Thanks in advance!
>
> SuzyElizabeth


Have you check for spyware/crapware? I used to use spybot search and
destroy...also check you hosts file....I would guess that you have some
kind of crapware installed...

Imhotep


Imhotep
  Reply With Quote
Old 09-18-2005, 10:49 PM   #3
TheThigILove@gmail.com
 
Posts: n/a
Default Re: Worms?
For someone who's kind of spyware naive, where can I locate the hosts
file? I will try the spybot as you suggested. I must admit, this is the
first instance of the term "crapware" that I've heard. Thank you!



TheThigILove@gmail.com
  Reply With Quote
Old 09-18-2005, 11:35 PM   #4
David H. Lipman
 
Posts: n/a
Default Re: Worms?
From: <>

| I don't know what's going on with my machine. I'll be visiting a site,
| like CNN.com, and all of a sudden, I get a page not found screen with
| "http:///" in the address bar. Before it'd go to the google search
| page. It only seems to occur with IE and not with Mozilla Firefox. I
| have done all the newest Windows updates, installed ZoneAlarm for
| firewall purposes, run McAfee three times, used TrendMicro's HouseCall,
| and everything, and yet it continues. I have gotten a detection message
| from McAfee a couple of times for a p2p virus. Each time it says it's
| been cleaned, but I'm still having problems. Anyone have any advice?
| Thanks in advance!
|
| SuzyElizabeth

For non-viral malware...

Please download, install and update the following software...

Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/

SpyBot Search and Destroy v1.4
http://security.kolla.de/

After the software is updated, I suggest scanning the system in Safe Mode.


For viral malware...

Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } three batch files, five Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend and McAfee Anti Virus Command Line Scanners to
remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode. This
way all the components can be downloaded from each AV vendor’s web site.
The choices are; Sophos, Trend, McAfee, Exit the menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




David H. Lipman
  Reply With Quote
Old 09-19-2005, 12:27 AM   #5
Imhotep
 
Posts: n/a
Default Re: Worms?
wrote:

> For someone who's kind of spyware naive, where can I locate the hosts
> file? I will try the spybot as you suggested. I must admit, this is the
> first instance of the term "crapware" that I've heard. Thank you!


Read David Lipman very good advice....

im


Imhotep
  Reply With Quote
Old 09-19-2005, 04:48 AM   #6
Winged
 
Posts: n/a
Default Re: Worms?
wrote:
> For someone who's kind of spyware naive, where can I locate the hosts
> file? I will try the spybot as you suggested. I must admit, this is the
> first instance of the term "crapware" that I've heard. Thank you!
>

%\windows\system32\etc

Make sure to switch mode of spybot to advanced mode, after scanning and
immunizing, preferably after you have updated...then check BHOs )browser
helper objects, activeX controls, startup items and processes. All of
this are accessible through the advanced mode. Use spybots host list if
you have a machine with >128MB RAM.
Winged


Winged
  Reply With Quote
Old 09-19-2005, 05:21 AM   #7
David H. Lipman
 
Posts: n/a
Default Re: Worms?
From: "Winged" <>

| wrote:
>> For someone who's kind of spyware naive, where can I locate the hosts
>> file? I will try the spybot as you suggested. I must admit, this is the
>> first instance of the term "crapware" that I've heard. Thank you!
>>

| %\windows\system32\etc
|
| Make sure to switch mode of spybot to advanced mode, after scanning and
| immunizing, preferably after you have updated...then check BHOs )browser
| helper objects, activeX controls, startup items and processes. All of
| this are accessible through the advanced mode. Use spybots host list if
| you have a machine with >128MB RAM.
| Winged

The correct path to the 'hosts' file is...

For NT based OS'
%windows%\system32\drivers\etc

For Win9x/ME
%windir%

For NT based OS', anything alse means the Registry setting which is...

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters
DataBasePath=%SystemRoot%\System32\drivers\etc

Has been changed by malware.

The Multi AV Scanning tool I provided in this thread deals with alterations of this setting
and if is different from the above it will be set to the above and it will also rename
'etc/hosts' to 'etc/hosts.bak' to make sure the anti virus files can be downloaded from
their respective vendors web sites.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




David H. Lipman
  Reply With Quote
Old 09-19-2005, 07:25 AM   #8
Winged
 
Posts: n/a
Default Re: Worms?
David H. Lipman wrote:
> From: "Winged" <>
>
> | wrote:
>
>>>For someone who's kind of spyware naive, where can I locate the hosts
>>>file? I will try the spybot as you suggested. I must admit, this is the
>>>first instance of the term "crapware" that I've heard. Thank you!
>>>

>
> | %\windows\system32\etc
> |
> | Make sure to switch mode of spybot to advanced mode, after scanning and
> | immunizing, preferably after you have updated...then check BHOs )browser
> | helper objects, activeX controls, startup items and processes. All of
> | this are accessible through the advanced mode. Use spybots host list if
> | you have a machine with >128MB RAM.
> | Winged
>
> The correct path to the 'hosts' file is...
>
> For NT based OS'
> %windows%\system32\drivers\etc
>
> For Win9x/ME
> %windir%
>
> For NT based OS', anything alse means the Registry setting which is...
>
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\Tcpip\Parameters
> DataBasePath=%SystemRoot%\System32\drivers\etc
>
> Has been changed by malware.
>
> The Multi AV Scanning tool I provided in this thread deals with alterations of this setting
> and if is different from the above it will be set to the above and it will also rename
> 'etc/hosts' to 'etc/hosts.bak' to make sure the anti virus files can be downloaded from
> their respective vendors web sites.
>

Yup, your right, somehow I missed the driver portion of the
path...Thanks for the catch..
Winged


Winged
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Pix506e behind Cisco1841 VPN problem aimeruko Hardware 0 09-27-2006 08:10 AM
Cisco 1841 and Pix506e VPN aimeruko General Help Related Topics 0 09-26-2006 08:50 AM
Dealing with viruses and Worms Raymond A+ Certification 7 10-17-2003 12:13 AM
Re: Why are Symantec/Norton products such pieces of sh*t? dave A+ Certification 2 09-22-2003 12:43 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46