Loans | Advertising | Mortgage Calculator | Your File Host | Anime Episodes
Couple of security issues [Archive] - PCMech Forums

PDA

View Full Version : Couple of security issues


ghost2003
04-06-2004, 06:55 PM
Since yesterday there seems to be lots of malware on my computer, ive got it all cleaned but but I still have 2 problems. First SpyBot S&D finds a worm but cant remove it(see attachement) it cant remove it in safe mode or with the startup scanner, no other virus, trojan or spyware scanner finds anything. And panda active scan freezes my computer after loading updates, I tried removing the ActiveX adn redownloading but it still does the same thing.

morriswindgate
04-06-2004, 07:17 PM
Go to www.webroot.com and first DL/Run their free privacy test and if it finds something DL/Run the trial of SpySweeper from the site.
You may also want to run an over the internet anti-virus sccan or even F-Prot for DOS to see what is going on.
As to the Panda AV, it is possible that Spybot Identified a file from that program as malware and locked it up. You can reverse Spybots actions by running running the restore feature on it.
And read this

http://www.sophos.com/support/disinfection/worms.html

Finally, and it just dawned on me, the file you cannot get rid of is in a screen saver program and the reason Spybot can't do anything is that it is running. So turn off the screen saver feature and see if it can now dump it. And like I tell most people anymore, screen saver programs on the Internet that are free, tend to be full of spyware anymore and if you want to deal with it then use them, otherwise stick with whatever Windows has built into it or buy one that is free of this junk.

ghost2003
04-06-2004, 07:51 PM
It is panda's online AV.
I scanned my computer with avast!4, A2, swatit, symantec online, bitdefender online, housecall, CWShredder and adaware6 but nothing else finds it, its probly just a false alarm(in the description they say it should have 4 detections). The only screensavers I downloaded were 2 from ATI and microsofts video screensaver powertoy and spybot S&D didint find anything till today. I dont know what to do about it.
BTW, Even with screensaver off I cant remove it.

EDIT: they also say it infects win9x machines

glc
04-07-2004, 09:36 AM
http://securityresponse.symantec.com/avcenter/venc/data/w32.opaserv.worm.removal.tool.html

ghost2003
04-07-2004, 01:57 PM
I downloaded it, it found something called "puta!!.exe" but couldnt delete it, told me to try in safe mode, still wouldnt let me, then I tried in command prompt but it did nothing untill I realised it was a directory, not a file, I went in windows explorer and deleted it. Spybot still finds SCRSVR.exe so I tried to quarantine it but then I typed the name (it didint show up on the list) it took mt to a empty directory exactly like the other one but I cant find this one to remove it, even when set to show hidden files and folders. How could all the scans I mentioned above miss all this and how do I remove it!?!?!?
Panda active scan still doesnt work.

ghost2003
04-07-2004, 07:55 PM
I deleted all panda active scan enteries in the registry and now it works :)

RAV online, hauri's livecall and command on demand didint find anything, panda is running right now and I doubt it will find anything. Spybot must be giving a false alarm.

glc
04-07-2004, 09:56 PM
When all else fails, go to Trend Micro and search for Sysclean. Download sysclean.com into a empty folder, then download and unzip the current pattern file into the same folder, run sysclean.

ghost2003
04-07-2004, 10:22 PM
What exactly is it? By what I see its a virus scanner like any other.

What I cant figure out is that the location spybot S&D shows me doesnt exist, not even in command prompt. But if I type in the name of the file when I try to quarantine it it brings me in a folder with its name!?!?!?!?!?!!?!?!?!?!?

But like I said before, if 8 <- :eek: virus scans, 1 spyware/adware scan and 2 trojan scans cant find it then spybot had got to have a false alarm!

EDIT 3. Close all applications running on your system, including any
antivirus software.

4. Run the executable file, SYSCLEAN.COM, by either:

[...]

4. Enable any antivirus software that is installed on your system and
perform a manual scan.


What does that mean? Do I scan with or without my AV on?(lol, they put #4 2 times.)

glc
04-08-2004, 11:14 AM
Turn off any resident shield or autoprotect is what that means.

ghost2003
04-08-2004, 01:27 PM
didint find anything although it gave like 50 access denied messeges in the log after. And when I turned my AV back on and tried to move the folder with sysclean in it it thought it was a virus.
Spybot must be hallucinating caus thers nothing on my computer.

glc
04-09-2004, 12:26 AM
It probably thought it was a virus because its a com file, not an exe. Trend does this on purpose so you can still run it when a worm takes over exe file associations. Whatever AV hit on that isn't terribly smart, it's crying wolf.

ghost2003
04-09-2004, 12:31 AM
lol, it was avast, as you might have seen im testing out kaspersky right now, this one should be smarter. And guess what...it doesnt find anything either, whats with spybot, its still giving me that opaserv thing.