OMG Viruses
OMG Viruses
I just got like 4 viruses today after my computer started acting funny. So I ran norton and this is what it found!
Download.Trojan
MHTMLRedir.Exploit
Trojan Horse
Trojan.Byte Verify
Now wtf is up with this. This is the first time I have ever found viruses on my computer and I have had it for like 5 years. Anybody now how I might have got these?
Download.Trojan
MHTMLRedir.Exploit
Trojan Horse
Trojan.Byte Verify
Now wtf is up with this. This is the first time I have ever found viruses on my computer and I have had it for like 5 years. Anybody now how I might have got these?
im having the same problems to. no matter what i do my IE home age is some shady search site. i do adware/spyware scans daily, but they always sneak back in after reboot.
how do we get our PC's back to normal?
i've already switched to mozilla.
but my system is still permenetly infected.
would a reinstallation of windows help?
how do we get our PC's back to normal?
i've already switched to mozilla.
but my system is still permenetly infected.
would a reinstallation of windows help?
- BUBBALOU
- DBB Benefactor
- Posts: 4198
- Joined: Tue Aug 24, 1999 2:01 am
- Location: Dallas Texas USA
- Contact:
Spybot - Search and Destroy 1.3 is your friend (adaware blows monkey chunks)
Download, install, run update, run scan, reboot if required, repair , then immunize (enable tea timer if you want)
Then get a Popup blocker and stop anything in the future
Download, install, run update, run scan, reboot if required, repair , then immunize (enable tea timer if you want)
Then get a Popup blocker and stop anything in the future
- Warlock
- DBB 3D Artist
- Posts: 3370
- Joined: Wed May 12, 1999 2:01 am
- Location: Midland, Tx, U.S.
- Contact:
uhhh u do know adaware finds stuff that spybot doesntBUBBALOU wrote:Spybot - Search and Destroy 1.3 is your friend (adaware blows monkey chunks)
- CDN_Merlin
- DBB_Master
- Posts: 9781
- Joined: Thu Nov 05, 1998 12:01 pm
- Location: Capital Of Canada
- Aggressor Prime
- DBB Captain
- Posts: 763
- Joined: Wed Feb 05, 2003 3:01 am
- Location: USA
Yes, Adaware does. But Spybot finds stuff that Adaware doesn't.Warlock wrote:uhhh u do know adaware finds stuff that spybot doesntBUBBALOU wrote:Spybot - Search and Destroy 1.3 is your friend (adaware blows monkey chunks)
You need both.
- WarAdvocat
- DBB Defender
- Posts: 3035
- Joined: Sun Jun 23, 2002 2:01 am
- Location: Fort Lauderdale, FL USA
Also, you get those files (most often) from warez/pr0n sites. The ones that pop up windows to install software like gator and so forth, 1 time in 10 it's some sort of overtly malign trojan, dialer or downloader. For some reason, the file gets saved even if you don't accept the download, That doesn't mean that you're infected though, it just doesn't get installed.
You're probably safe if the file is just in your internet casche or temp internet files.
You're probably safe if the file is just in your internet casche or temp internet files.
BHODemon
That will show you all Browser Helper Objects that IE is using. Most likely one of them is spyware that redirects your homepage. Uncheck it what looks suspicious and see if it helps.
That will show you all Browser Helper Objects that IE is using. Most likely one of them is spyware that redirects your homepage. Uncheck it what looks suspicious and see if it helps.
-
- Defender of the Night
- Posts: 13477
- Joined: Thu Nov 05, 1998 12:01 pm
- Location: Olathe, KS
- Contact:
Its coming back because theres a program running in the background restoring the data. Open up Task Manager and look for any suspicious in the process list. (note: You will see multiple instances of svchost.exe, this is NORMAL...unless you're Warlock. )[DWL]Punk wrote:im having the same problems to. no matter what i do my IE home age is some shady search site. i do adware/spyware scans daily, but they always sneak back in after reboot.
how do we get our PC's back to normal?
i've already switched to mozilla.
but my system is still permenetly infected.
would a reinstallation of windows help?
- WarAdvocat
- DBB Defender
- Posts: 3035
- Joined: Sun Jun 23, 2002 2:01 am
- Location: Fort Lauderdale, FL USA
Svchost.exe is a generic host process name for services that are run from dynamic-link libraries.
Currently on my office computer I show 4 instances of SVCHOST.EXE, one of which is using 22,008k/RAM
Shouldn't be anything to worry about for you although I'd check my startup files and make sure I didn't have any bloatware loading when I boot up.
To view the services running under SVCHOST.EXE in WinXP, check the following article:
MS Knowledge Base Article 314056 - "A description of Svchost.exe in Windows XP"
http://support.microsoft.com/default.as ... N];Q314056
Currently on my office computer I show 4 instances of SVCHOST.EXE, one of which is using 22,008k/RAM
Shouldn't be anything to worry about for you although I'd check my startup files and make sure I didn't have any bloatware loading when I boot up.
To view the services running under SVCHOST.EXE in WinXP, check the following article:
MS Knowledge Base Article 314056 - "A description of Svchost.exe in Windows XP"
http://support.microsoft.com/default.as ... N];Q314056
The best defense against malware is not Spybot or Ad-Aware: it's common sense. Granted, IE has security holes even seemingly innocuous websites can exploit, but downloading and installing things from random websites or KaZaA is an incredible no-no. And anything that advertises itself in a popup window can't possibly be as good as it seems (*cough*Precision Date & Time*cough*).
you should try using, as well as the other software mentioned here, two programs called Spyware Blaster, and Spyware Guard
both can be found here Spyware Stuff. Both are pretty good and have helped a lot. If you need to find out what stuff is running on your PC and other nifty (or unnifty)stuff, download HiJackThis.
Good luck!
both can be found here Spyware Stuff. Both are pretty good and have helped a lot. If you need to find out what stuff is running on your PC and other nifty (or unnifty)stuff, download HiJackThis.
Good luck!
advice
Here's what I do:
only use Mozilla (best browser of 2003)
use AVG antivirus from Grisoft (free and good)
use SpySweeper (PC magazine editor's choice)
use yahoo mail, not outlook or O. Express
I rarely get anything with these methods. Hope that helps you!
only use Mozilla (best browser of 2003)
use AVG antivirus from Grisoft (free and good)
use SpySweeper (PC magazine editor's choice)
use yahoo mail, not outlook or O. Express
I rarely get anything with these methods. Hope that helps you!
Exactly.Aggressor Prime wrote:Yes, Adaware does. But Spybot finds stuff that Adaware doesn't.Warlock wrote:uhhh u do know adaware finds stuff that spybot doesntBUBBALOU wrote:Spybot - Search and Destroy 1.3 is your friend (adaware blows monkey chunks)
You need both.
I haven't been able to get an update for spybot for a long time. Were they off line for a while?
To avoid trojan's it's best to also have a firewall in place as well.
- Vindicator
- DBB Benefactor
- Posts: 3166
- Joined: Mon Dec 16, 2002 3:01 am
- Location: southern IL, USA
- Contact:
-
- Defender of the Night
- Posts: 13477
- Joined: Thu Nov 05, 1998 12:01 pm
- Location: Olathe, KS
- Contact:
No, they just actually updated the software and quit supporting 1.2.Duper wrote: I haven't been able to get an update for spybot for a long time. Were they off line for a while?
Though it would be nice if the morons that upload the updates would bother to CHECK THE DAMN CHECKSUM! (the only two updates available have bac checksum values, thus will not install.)
Wonderful ..... would have been nice to have the updater to relay the message to the genral populas that they indeed quit supporting 1.2 Why not update that to a higher version or something? that's just wierd. Thanks for bringing me up to speed.
The reason I asked if they were off line is because I couldn't even get on their website.
The reason I asked if they were off line is because I couldn't even get on their website.
win xp , 2k etc. are all multiuser-os, why do you work and play in an admin account? if you browse with your ie in an restricted user account most likely nothing can install into your system cause ie has the same rights as the restricted user then. use the admin account only for driver updates, win updates and so on.
And, use the admin account to install a fair number of applications and games(most notable of which is BF1942, IIRC).DigiJo wrote:win xp , 2k etc. are all multiuser-os, why do you work and play in an admin account? if you browse with your ie in an restricted user account most likely nothing can install into your system cause ie has the same rights as the restricted user then. use the admin account only for driver updates, win updates and so on.
most people use admin accounts on windows because they are normally the only ones that use it, and its too inconvient to switch between accounts(provided they are aware of the capability in the first place, most aren't).
XP forces you to have a Computer Administrator account by default anyways.
Running Spybot V1.3 and couldn't update either. Went to KOLLA'Sdownload page and got the updated detection files. No checksum errors.
does anyone reconize any of these email addys:
matt@metallisoft.com
|clutch|@hotmail.com
im getting repeated numbers of virus loaded emails from these two addys.
matt@metallisoft.com
|clutch|@hotmail.com
im getting repeated numbers of virus loaded emails from these two addys.
MD-2389 wrote: Though it would be nice if the morons that upload the updates would bother to CHECK THE DAMN CHECKSUM! (the only two updates available have bac checksum values, thus will not install.)
i updated mine just fine..............updated my brothers just fine........updated my fathers just fine.......and mother just fine....???
Yah, those guys are pretty bad. Stay away from 127.0.0.1 too, he's a nasty one.AceCombat wrote:does anyone reconize any of these email addys:
matt@metallisoft.com
|clutch|@hotmail.com
im getting repeated numbers of virus loaded emails from these two addys.
More likely than not they're spoofed. Can you even have pipes in a hotmail user name?