Buy Anything On eBay | Loans | Novela romantica | Loans | Free SMS Messaging
Hit with a virus [Archive] - PCMech Forums

PDA

View Full Version : Hit with a virus


Pentium
08-20-2004, 03:05 PM
Hi guys,

I was browsing yesterday and my norton propped up a window saying that it detected the "bloodhound.exploit.6" virus and that it could not fix it. Anyway, I checked my log and it showed the same file 6 times and in the "action taken" column it says repair failed and also access denied (I attached an image). I scanned the folder again and there are no viruses being picked up so does that mean they have been deleted or could they still be in my system? :confused:

TheMajor
08-20-2004, 03:17 PM
try a different antivirus to make sure http://www.avast.com

Dangermouse1
08-20-2004, 03:33 PM
You can also do an online scan here (http://housecall.trendmicro.com/)

Pentium
08-20-2004, 03:48 PM
Are there any online scans that allows you to select a folder to scan rather then scan my whole system? The reason I ask is it usually takes upward of 9-10 hours the last time I done an online scan and also about the same time when I scan with norton.

Redfallon
08-20-2004, 03:54 PM
Housecall will let you scan specific folders, I believe, I know they'll let you select certain drives, but have never dug deep enough to see if they'll let you pick specific folders, good luck.

RJS2
08-20-2004, 11:38 PM
yes housecall will let u just scan specific folders just click on the plus next to the folder ur looking for and put a check there then scan

Pentium
08-21-2004, 04:59 AM
I just finished a scan at that housecall site on the folders which may have been infected and it came up clean.

If norton couldn't repair the file as it says in the logs does that mean it just deleted them?

pam123
08-21-2004, 09:44 AM
Hi guys,

I was browsing yesterday and my norton propped up a window saying that it detected the "bloodhound.exploit.6" virus and that it could not fix it. Anyway, I checked my log and it showed the same file 6 times and in the "action taken" column it says repair failed and also access denied (I attached an image). I scanned the folder again and there are no viruses being picked up so does that mean they have been deleted or could they still be in my system? :confused:


Been there, fixed that : http://forum.pcmech.com/showthread.php?t=106393

The info on it is on the Norton site.
It was still listed as a low level threat the last time I looked but I get the feeling it's practice for something else that's due later.
So kill restore and reboot as well when you run disk clean.
When the comp comes back up you can re-enable system restore.
If you have any idea where you picked it up it may help pinpoint potential breeding sites.

Pentium
08-21-2004, 03:36 PM
When I go to windows update there aren't any updates for me so I must have that April one installed. I want to follow your instructions but I've run into a problem. I've never used disk cleanup before so I tried it for the first time and for some reason it will not run properly. It pops up a screen like the one I have attached and keeps looking for around about 10 minutes (you can hear the computer grumbling while going through the files) then it sounds like it stops looking but the same screen stays as it is. I tried leaving it for an hour and it didn't change but what I did notice is that everytime I tried the disk clean program it would eat up 100% of my computer usage. Do you have any idea what the problem could be? :confused:

You also said that you found the virus in your temporary internet files folder. That is the same place that is listed in my norton logs but where exactly is the Content.IE5 for the file like below?

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GT6B8LYF\index[4].htm


As for where It was picked it up, unfortunately I can't be too sure but I think it came from some popups that opened while browsing a few computer info sites that I got from google.

pam123
08-21-2004, 07:04 PM
Can you get into safe mode ?
Try running Disk Clean from there.


edit : Norton has quarantined the folders not deleted the virus but having your cpu usage hit 100% should ring all kinds of warnings.
IE 5 ?
Are you running 98se ?

Pentium
08-22-2004, 07:58 AM
I will try to boot into safe mode and see if it will work then. The computer usage hits 100% only when I run disk clean. As for IE5, I'm talking about the location of the virus which is listed as follows in my norton logs.

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GT6B8LYF\index[4].htm

I'm using XP home edition with IE6 SP1.

ghost2003
08-22-2004, 09:29 AM
Empty your temp files. In IE go tools>internet options> delete files

Pentium
08-22-2004, 09:54 AM
Well I just booted in safe mode and I still can't get the disk cleanup to work for drive C. It works for drive D and also works fine when I tried it with another user account both in safe mode and normal mode. This is usually my experience with computers unfortunately in that when I have one problem it turns into multiple problems LOL.

Just to get back to the virus for a sceond, what do you think I should do? Again just to point out that it was detected by norton and I have posted an image of the log in my earlier post. It doesn't say that it was quarantined nor deleted as norton usually does but when I scanned my temp internet folder with both norton and the online housecall scan there was nothing picked up. As just an average computer user I'm really getting confused here and would appreciate any more help and thanks for the help already given.

ghost2003,

I will delete them if I can't get disk clean to work (I was hoping to get into the Content.IE5 folder before I delete the files).

pam123
08-22-2004, 10:49 AM
Well I just booted in safe mode and I still can't get the disk cleanup to work for drive C. It works for drive D and also works fine when I tried it with another user account both in safe mode and normal mode. This is usually my experience with computers unfortunately in that when I have one problem it turns into multiple problems LOL.

Just to get back to the virus for a sceond, what do you think I should do? Again just to point out that it was detected by norton and I have posted an image of the log in my earlier post. It doesn't say that it was quarantined nor deleted as norton usually does but when I scanned my temp internet folder with both norton and the online housecall scan there was nothing picked up. As just an average computer user I'm really getting confused here and would appreciate any more help and thanks for the help already given.

ghost2003,

I will delete them if I can't get disk clean to work (I was hoping to get into the Content.IE5 folder before I delete the files).


Nothing to worry about.
IE has automatic delete functions, mine is set to delete all files after 3 days, and doing it manually won't hurt anything.
You've never used it before so it seems strange.
If it were not for the fact that something is locking up your disk clean I would say that those files are already gone. As it is go into Internet Options and make sure bloodhound is gone.

Pentium
08-22-2004, 02:32 PM
Where exactly is that IE delete option you speak of ?

As I've been trying to ask in my last few post how exactly do I find the location of the folder that the virus is supposed to be in without disk clean?

C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\GT6B8LYF\index[4].htm

WhatsThisBoxFor?
08-22-2004, 02:36 PM
Type the address into the bar (without index[4].html), that should take you to the containing folder. I think it is safe to delete the whole Temporary Interent FIles folder, and IE will remake it, but since I don't use IE you will have to wait for someone to comfirm this.

pam123
08-22-2004, 02:46 PM
Open IE.
The menu bar across the top of the page will read File, Edit, etc.,it will also read Tools.
Click on Tools and from the pull down menu click on Internet Options.
The tab you should get is "General" (if for some reason you don't then click General) .
The boxes in that tab will read Homepage, Temporary Internet Files, History.
In Temporary Internet Files click on Delete Files.
That will delete all your temporary files.
Close all the windows .
When you have some spare time go back and famaliarize yourself with it but that's all you need to do for now.

Pentium
08-22-2004, 02:46 PM
Type the address into the bar (without index[4].html), that should take you to the containing folder. I think it is safe to delete the whole Temporary Interent FIles folder, and IE will remake it, but since I don't use IE you will have to wait for someone to comfirm this.

Ok, thanks for that I will have a look.

Pentium
08-22-2004, 02:52 PM
Open IE.
The menu bar across the top of the page will read File, Edit, etc.,it will also read Tools.
Click on Tools and from the pull down menu click on Internet Options.
The tab you should get is "General" (if for some reason you don't then click General) .
The boxes in that tab will read Homepage, Temporary Internet Files, History.
In Temporary Internet Files click on Delete Files.
That will delete all your temporary files.
Close all the windows .
When you have some spare time go back and famaliarize yourself with it but that's all you need to do for now.

LOL. My apologies I must be coming across wrong. I have deleted my temp files and all offline content many times in the past. What I was asking about is where you said;

IE has automatic delete functions, mine is set to delete all files after 3 days

;)

Pentium
08-22-2004, 03:04 PM
Type the address into the bar (without index[4].html), that should take you to the containing folder. I think it is safe to delete the whole Temporary Interent FIles folder, and IE will remake it, but since I don't use IE you will have to wait for someone to comfirm this.

Well, I found a file in the folder with the same name and scanned it with norton but it comes out clean. I will just delete all my temp internet files and then later on do a full system scan to see what it comes up with. I still have no idea however what is the problem with the disk clean program for my particular user account. :confused:

WhatsThisBoxFor?
08-22-2004, 03:12 PM
LOL. My apologies I must be coming across wrong. I have deleted my temp files and all offline content many times in the past. What I was asking about is where you said;

I think on the main tab of internet options where it says remember my history, you change it to 3 days, instead of 20 days. I'm not sure if this will delete the temporary files after 3 days though.

Pentium
08-22-2004, 03:29 PM
Hmm, I think that is only for the pages in the history folder (urls) and separate from the temp internet files but yeah maybe that's what pam123 was speaking of.

pam123
08-22-2004, 03:54 PM
That's what I get for not being clear.
Getting rid of files is one of the Scheduled Tasks.


edit: the above is an example of typing without thinking.
Forget I said it.

It does look like you've gotten rid of Bloodhound though.

Pentium
08-22-2004, 05:26 PM
Yeh It semms to be out of the system although I'll still run a full scan. :cool: