Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 30th August 2003   #1
Inactive
 
Profile:
Join Date: Aug 2003
Posts: 13
Computer Experience:
Intermediate
Bleep Reputation Level


Help Please

Hi,

just registered and new to this.

One of my kids has discovered INTERNET Chat Rooms.

Yesterday, he was foolishly left unattended.

At the moment the family PC is behaving in an eratic manner. Occasionally (but not all of the time) when the mouse moves it opens up a whole range of windows, mainly those programs that have icons in the windows toolbat at the bottom of the page.

I have run the Norton Anti Virus software, full system scan, and nothing was found. I have run the W32.Welchia, W32.Sircam and W32.Blaster Worm removal programs and nothing was found. I have ZoneAlarm installed and I have run a wee program that looks for Trojans (SpyBot). Nothing found.

I have looked at the registry under the Run Folder and can see nothing suspicious:
Run -
Optional Components -
IMAIL
MAPI
MSFS

Anyone got any ideas what is going on and more important, how can I resolve this?

Thanks for any advice.


Bleep

PS I may be wrong, but it seems to be worse when I am running Inyernet Explorer.

Bleep is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 30th August 2003   #2
Administrator
 
Admin.'s Avatar
 
Profile:
Join Date: Dec 2001
Location: 35⁰ 53'55.1" N, 14⁰ 28'37.5" E
Posts: 3,301
Computer Experience:
***
Admin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation LevelAdmin. Reputation Level

My System

Welcome Bleep, but kindly follow the posting rule #3

For this time, please post your new subject in a reply to this thread, and I will change the current subject.

Admin. is offline  
Old 30th August 2003   #3
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


First go into control panel Add/Remove and uninstall any program that is named ICQ, IRC or MIRC.

Cleanup temps!

Then

Use this program to remove Spy/Adware and Browser hijacks

Spyware and adware removal

SpyBot http://security.kolla.de/index.php?l...&page=download

Run this twice delete all it finds.
Leave all it wants to leave after the second run.

Then go here http://www.spywareinfo.com/~merijn/

and get and run the following program "CoolWeb Shredder".

If you need more help post back.

Mike

mflynn is offline  
Old 31st August 2003   #4
Inactive
 
Profile:
Join Date: Aug 2003
Posts: 13
Computer Experience:
Intermediate
Bleep Reputation Level


Hi, thanks for taking the time to help.

I have done all of what you said, the only grey area was deleting stuff from temp folders because there are lots of them and some of the stuff seems to be required (although I can's be certain).

I had already run the SpyBot software as I had it on my machince. I downloaded and run the shredder software. For the moment all appears to be well, but a couple of days ago I thought the same and agter a few hours it all kicked off again.

Do you mind if I get back to you if it goes haywire again?

Thanks again for replying.

Bleep is offline  
Old 1st September 2003   #5
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


Hi Bleep

Glad all is well for now.

Here is how you clean temps.

Configure CleanMgr to max settings
Go to Start-Run and type

cleanmgr /sageset:1
The above need only be ran once (these settings will be remembered as the default until another sageset is ran).

It will present a menu select all except compress, then

Go to Start-Run and type

cleanmgr /sagerun:1
As long as /sageset above has been ran on this computer from now on the /sagerun is the only thing that needs to run.

And below a few downloads to help:

EasyClean1.7 <http://gswi.com/downloads.htm>
Run only unnecessary files and registry clean delete all it finds. If you have XP or ME in the “Unnecessary Files” type the word HELP in the skip box. Do not do Duplicate files!
NOTE: Easy clean breaks XP help but it is so easy to put back I still recommend and use EasyClean, so after Easy clean go here and click the top left hand corner to fix online or below download it to your computer for later. http://dougknox.com/xp/scripts_desc/fixwinxphelp.htm

DISK TEMP AND MRU(PRIVACY TRACKS) Cleanup

Dclean http://www.xs4all.nl/~mp2004/

I think Dclean is the smallest, fastest most thorough temp cleaner there is. When you run it the first time put a check in all boxes.

MRU BLASTER http://www.wilderssecurity.net/mrublaster.html

Cleans the registry of all tracks in MRUBlaster go to settings plugins and select both Cookie Blaster and IE Temp file cleaner, check the "Enable automatic" that is directly over the "Save settings and run now" then hit the Save settings and run now".

Spider: http://www.fsm.nl/ward/

Spider gets the infamous index.dat files, plus a few other things. Click scan then click clean, but when it asks for what to clean, check all drives and everything else.

XpAntiSpy http://www.webattack.com/get/xpantispy.shtml

There are many settings in XpAntiSpy but the ones you would use for privacy are:

Heck I usually do them all EXCEPT "Enable fast Shutdown and Task-Scheduler service.

I also set it to Clear Pagefile on shutdown for cleaning but after reboot I always turn this back off and only clean it when I want. Some leave it on all the time.

Mike

mflynn is offline  
Old 1st September 2003   #6
Inactive
 
Profile:
Join Date: Aug 2003
Posts: 13
Computer Experience:
Intermediate
Bleep Reputation Level


Hi again (M Flynn).

The problem has not gone away.

I'm at a complete loss as to what to do. My Norton AV is fully up to date and I have the latest SpyBot program. I have downloaded and run AdAware as well as the program you advised me to run.

It does seem to be associated in some way with Internet Explorer or Outlook Express as it is worse when these programs are being used, particularly IE.

Thanks again for any advice.

Bleep

Bleep is offline  
Old 1st September 2003   #7
Inactive
 
Profile:
Join Date: Aug 2003
Posts: 13
Computer Experience:
Intermediate
Bleep Reputation Level


Oops, sorry Mike. I'm sure your reply (above) wasn't there when I posted my last message.

Any advice now that the **** virus hasn't gone away?

Thanks again.

Bleep is offline  
Old 1st September 2003   #8
Inactive
 
Profile:
Join Date: Jan 2002
Location: Marlboro, NY.
Posts: 6,211
Computer Experience:
Gaining more every d
BillyBob Reputation LevelBillyBob Reputation LevelBillyBob Reputation LevelBillyBob Reputation LevelBillyBob Reputation LevelBillyBob Reputation Level


Ideas.

If running Windows 98.

Go to the C:\Windows\sysbckup folder and delete ALL RB00X.CAB files. The virus may still be in one of them and Windows is picling it up.

If using XP.

Shut down System Restore. That will clean out all restore points. I would not turn it back on untill I was sure that the system was clean.

After either one of the steps above do another FULL System Virus scan.

And use the suggestions by mflynn again.

Either OS.

Do not use any prevous backups the may have been made while the Virus was present.

BillyBob

BillyBob is offline  
Old 1st September 2003   #9
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


HI BB

Bleep

Yes, what OS are you running. When you mentioned Blaster I assumed 2k or Xp.

Blaster only effects directly anyway 2k and Xp.

And you never said you found a Virus, after multiple checks and scans. Including a Trojan scanner.

I guess we need more info so do this first:

Get HiJackThis here http://www.lurkhere.com/~nicefiles/index.html

Then load it and click Config then Misc tools then generate Startup list. This will bring up all your startup programs. While this is on screen copy it and paste it back to us in a message.

With this info we can help you better.

Your move!

Mike

mflynn is offline  
Old 1st September 2003   #10
Inactive
 
Profile:
Join Date: Aug 2003
Posts: 13
Computer Experience:
Intermediate
Bleep Reputation Level


Hi.

Thanks for all of the advice.

I am replying from place of work and when I get home tonight I will address each of the suggestions, then get back to you. I intend also to subscribe to the site so I will do that when I get home also.

Much appreciated.

Bleep

Bleep is offline  
Old 1st September 2003   #11
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


Don't forget to let us know what OS you have.

Win 98 or XP or what?

Do the HiJackThis proceedure first and get it on out to us.

Mike

mflynn is offline  
Old 1st September 2003   #12
Staff
 
Christer's Avatar
 
Profile:
Join Date: Dec 2002
Location: Sweden
Posts: 5,162
Computer Experience:
I'm trying!
Christer Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation LevelChrister Reputation Level


Hi Mike!

When I open any WebAttack page I get multiple error messages reading:

An error has occured
Line: 131
Error: Code undefined

After clicking the messages away the page load OK.

Anyone else having this problem?

The XP-Anti-Spy download is no longer available. Do You know why?

Thanks,
Christer


Last edited by Christer; 1st September 2003 at 14:24.
Christer is offline  
Old 1st September 2003   #13
Inactive
 
Profile:
Join Date: Aug 2002
Posts: 4,147
mflynn Reputation Levelmflynn Reputation Levelmflynn Reputation Level


Hi Christer

I do not get any errors loading the page. So you may have other problems here.

But you are correct they no longer offer this program. This must be a very recent change.

XpAntiSpy is a German program newest ver is 3.72. So get it from the programmer at:

http://www.xp-antispy.org/download.php

Mike

mflynn is offline  
Old 1st September 2003   #14
Inactive
 
Profile:
Join Date: Sep 2003
Location: UK
Posts: 21
Computer Experience:
intermediate
wizzkid121 Reputation Level


hiya bleep,

this might b a bit late but

it sounds like the after affects of a trojan. ask your son what he got sent (pictures etc) and check startup run for that filename.

when your online try going on msn dos and type netstat -a i think, see if anything is funny.

let me know how you go on...

Mike

wizzkid121 is offline  
Old 1st September 2003   #15
Inactive
 
Profile:
Join Date: Sep 2003
Location: UK
Posts: 21
Computer Experience:
intermediate
wizzkid121 Reputation Level


after reading through more thoroughly i seen the bit about going worse when you load ie.

there was a trojan or virus not so long ago which used internet explorer to execute itself with. eg open trojan server etc.

when a trojan server usually opens, the computer slows down and sometimes freezes for a short while depending on speed.

does yours freeze etc?

any1 help? any1 remember this?

Mike


Last edited by wizzkid121; 1st September 2003 at 15:31.
wizzkid121 is offline  
Closed Thread

Thread Tools



All times are GMT +1. The time now is 06:09.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]