Submit Your Article Forum Rules FAQ About Us
Search the forums:

Tech Support Team


Hello and Welcome to Tech Support Team! Before you can start posting and answering questions, you'll have to register. Registration is fast, simple and absolutely free! Feel free to browse through existing questions by choosing the forum you want to visit below.



Notices

Reply
  #1 (permalink)   Top
Old 22nd February 2008, 05:25 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
[Solved] Possible virus although not found by Kaspersky

Possible tester for Howard!
System used by youth for P2P share. Has picked up a scam advising virus found and should visit a site and download a fix for it. This has been avoided.
System running XPH SP2 and is patched, has Norton.
Also has a regular pop-up advising "Task Manager has been disabled by your administrator" - it hasn't. Also pop up advising of internet attack althought system is not attached to the net.
I have run Ccleaner and Hijackthis - both found bits and pieces but no cure.

Ideas, anyone?
thanks in advance.
__________________
Confuse and Prosper.
Reply With Quote
  #2 (permalink)   Top
Old 22nd February 2008, 05:31 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Yes mate, it`s instructions time, as the system is obviously infected.

Go and read the Viruses/Spyware/Malware, preliminary removal instructions. Follow all the instructions exactly.

Post fresh HJT, AVG Antispyware and Combofix logs as Attachments into this thread, only after doing the above.

Also, let me know the results of the Panda Antirootkit scan.

Regards Howard

This thread is for the use of Albert Lionheart only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
Reply With Quote
  #3 (permalink)   Top
Old 22nd February 2008, 05:34 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
htj log attached - will do the others over the weekend.
Don't forget I have had a go at this one already and have removed anything marked as even slightly dodgy.
cheers

PS - don't forget it is a rugby weekend!

thanks Tom - I had jumped to the wrong conclusion and assumed (to assume makes an '***' out of 'u' and 'me' [UPS doctrine statement]) that this was not a system based message. Back in a tick!
Attached Files
File Type: log hijackthis.log (9.0 KB, 34 views)
__________________
Confuse and Prosper.

Last edited by Howard; 22nd February 2008 at 05:46 PM.
Reply With Quote
  #4 (permalink)   Top
Old 22nd February 2008, 05:41 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
The HJT log shows various infections.

You should not be removing anything using HJT unless advised to do so.

Run HJT and click the config button, followed by the backups button. Select all entries and click the restore button and confirm. This will restore all removed entries from HJT so we can see exactly what the original HJT log contained. Reboot the system.

Once done, please follow the main instructions and post the requested log files.

Regards Howard

This thread is for the use of Albert Lionheart only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
Reply With Quote
  #5 (permalink)   Top
Old 22nd February 2008, 05:51 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Howard - please could you either reinstate Tom's suggestion or send me a PM with the contents?
cheers
__________________
Confuse and Prosper.
Reply With Quote
  #6 (permalink)   Top
Old 22nd February 2008, 06:53 PM
Daveskater's Avatar
Community Moderator
 
Join Date: Dec 2007, 4,345 posts.
Location: Oxford, UK
Reputation: Daveskater will become famous soon enoughDaveskater will become famous soon enough
Don't worry about that mate, the "Task manager disabled" message can sometimes be fixed through HJT.

Restore all the backups and post the new log, and we'll take a look-see.
__________________
Numberwang!

A little air on the earth.
Reply With Quote
  #7 (permalink)   Top
Old 22nd February 2008, 08:01 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Albert:

Please just follow the instructions I have given you. I have pm`d tomrca and he is now aware of TST policy on malware advice.

You might also want to look at this thread HERE for info on just who is allowed to help in malware threads. There are very good reasons for this.

Regards Howard
Reply With Quote
  #8 (permalink)   Top
Old 23rd February 2008, 12:57 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Youth's dad turned up today - he was not impressed with some of the stuff we found on the thing and as it turns out to have 2 HDDs in it we agreed to move the decent stuff to one of them and reinstall XPH onto the other. One day I will get to follow the procedures for real, but not this time! Thanks for the help Howard
On a serious not, although it is not my place to comment on what his Dad and I found on this machine - explains a lot about today's society's values.
If you were asked to fix a machine stuffed full of porn, what would you do about showing the parents if asked? Shall we have a poll? No, not a pole to dance round - be serious!

Last edited by Albert Lionheart; 23rd February 2008 at 12:58 PM. Reason: forgot to thank Howard
Reply With Quote
  #9 (permalink)   Top
Old 23rd February 2008, 02:57 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Finding a load of porn an a system, is probably the reason for the infections in the first place.

Depending on the age of the user, I would have to inform the parents.

Regards Howard

This thread is for the use of Albert Lionheart only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
Reply With Quote
  #10 (permalink)   Top
Old 23rd February 2008, 06:11 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Another good reason for the reinstall of the OS was that it is clear that a whole load of windows files were not working properly - like that Gpedit.msc file which had vanished.
__________________
Confuse and Prosper.
Reply With Quote
  #11 (permalink)   Top
Old 23rd February 2008, 06:12 PM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
Tell the that although you are sure their parenting skills are good you feel you should warn them about the things found on the computer. Make them aware that studies have shown that viewing porn at a young age is very similar to to a child experimenting with marijuana. It is a gateway to many many other more dark and sinister activities. No parent needs much more warning than that. All you can do is set the record straight and hope they handle it in the right manner.

More resources if needed.

Kids safety resources:Free Parental Control Software
  • KidRocket - Safe Web Browser for Kids.
  • W3kids.com - Kid safe search engine.
  • Glubble creates a trusted surfing environment for kids. Allows you to set sites that you trust for your kids.
  • DirFile.com Free Parental Control Software.
  • Crawler Parental Control provides you with comprehensive control of user activity on your computer.
  • Naomi is an advanced internet filtering program, easy to use and totally free, intended for families, and kids in particular.
Commercially licensed Parental Control Software
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ
Reply With Quote
  #12 (permalink)   Top
Old 23rd February 2008, 06:25 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
evilfantasy - if that is not a standard reference point for the forum, I suggest it should be.
__________________
Confuse and Prosper.
Reply With Quote
  #13 (permalink)   Top
Old 28th February 2008, 09:11 PM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
I`m marking this thread as solved.

If you need this thread re-opened please contact a moderator or PM me.

Regards Howard
Reply With Quote
  #14 (permalink)   Top
Old 1st March 2008, 06:23 AM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
Quote:
Originally Posted by Albert Lionheart View Post
evilfantasy - if that is not a standard reference point for the forum, I suggest it should be.
Done, with extra info added. I had been working on that along with more information for a while now and have finally finished it to a point I am happy with.

Web, email, chat, password and kids safety
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ

Last edited by evilfantasy; 1st March 2008 at 06:36 AM.
Reply With Quote
Reply

Only registered members can participate in forum threads. You must register or log in to contribute.


Thread Tools

Forum Jump


All times are GMT. The time now is 09:06 PM.






Post A Question!
Useful Links
Main Menu
Home
Forum Rules
FAQ
About Us
Welcome Pack
Search the forums
TST Mobile
Contact Us
Send Message

These are the 8 most used thread tags
Tag Cloud
geforce modem monitor no ring response no signal nvidia soft modem win7