Go Back   PCMech Forums > Windows Support > Windows Legacy Support (XP and earlier)

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 06-11-2003, 02:57 PM   #1
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
You might find this interesting...

I did a fresh install of win2000 (reformatted through setup).

First, I installed my Nvidia display driver.

Second, I installed my monitor driver.

Third, I installed my ethernet card driver.

Fourth, I used Windows update to get all the critical updates and service packs.

I didn't go to any websites (other than windows update) and I didn't check my mail or anything.

That's when I noticed I had the lovegate virus.

Strange, isn't it?
KlumpDud is offline   Reply With Quote
Old 06-11-2003, 03:21 PM   #2
Member (14 bit)
 
reboot's Avatar
 
Join Date: Mar 1999
Location: Kelowna, B.C., Canada
Posts: 9,138
Probably one of your driver files is infected.
If it's a remnant of your previous install, and not a NEW download...
__________________
Black holes are where God divided by zero...
Cheers, Jim

Jims Modems
reboot is offline   Reply With Quote
Old 06-11-2003, 03:35 PM   #3
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
So neither of those cleaners can detect if my files are infected?

What good are they then?

Last edited by KlumpDud; 06-11-2003 at 03:46 PM.
KlumpDud is offline   Reply With Quote
Old 06-11-2003, 03:55 PM   #4
Ride 'em Cowboy
 
EzyStvy's Avatar
 
Join Date: Dec 1999
Location: Dallas, Tx
Posts: 9,109
When you put in your nic, did you network to any other computers in your house/office? How about emails?

http://securityresponse.symantec.com...gate.h@mm.html
EzyStvy is offline   Reply With Quote
Old 06-11-2003, 03:56 PM   #5
Member (10 bit)
 
Join Date: Apr 2002
Location: Belgium
Posts: 850
where do you drivers originate from
factory cd's or downloaded?
__________________
Been there, broke that
grasshopperbe is offline   Reply With Quote
Old 06-11-2003, 04:07 PM   #6
Member (14 bit)
 
reboot's Avatar
 
Join Date: Mar 1999
Location: Kelowna, B.C., Canada
Posts: 9,138
Do you have any saved emails anywhere?
Do you have the drivers on a floppy, CDR, or other partition?
Something you have contains the trojan, and it keeps getting reinstalled.

What "cleaners" are you talking about?
reboot is offline   Reply With Quote
Old 06-11-2003, 04:31 PM   #7
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
I mean, neither of those AV programs (Norton Anti-Virus or Moosoft's The Cleaner) seems to be able to get rid of it permanently. It keeps coming back after reboots:

No, I have not checked email, nor do I have any saved email. I have not even accessed any internet sites other than the windows update.
KlumpDud is offline   Reply With Quote
Old 06-11-2003, 05:16 PM   #8
Member (14 bit)
 
reboot's Avatar
 
Join Date: Mar 1999
Location: Kelowna, B.C., Canada
Posts: 9,138
NAV is notorious for missing things, especially if it hasn't been updated. Moosoft's Cleaner, same problem, and it never did get every trojan anyhow.
Where are you loading the drivers for your video and NIC from?
If you have multiple partitions, are you scanning ALL of them?
Have you been to http://housecall.antivirus.com yet?
reboot is offline   Reply With Quote
Old 06-11-2003, 06:50 PM   #9
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
reboot, that housecall plugin is not working: it won't install
KlumpDud is offline   Reply With Quote
Old 06-11-2003, 07:21 PM   #10
Member (8 bit)
 
Join Date: Mar 2003
Location: the hand state
Posts: 133
Quote:
It keeps coming back after reboots
try deleting you system restore points,it might be hanging in there
around2it is offline   Reply With Quote
Old 06-12-2003, 01:48 AM   #11
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
1. How do I delete my system restore points?

2. I just reformatted and found a file on my HD called AVG6DB_F.dat, could that be a malicious file?
KlumpDud is offline   Reply With Quote
Old 06-12-2003, 10:23 AM   #12
Member (14 bit)
 
reboot's Avatar
 
Join Date: Mar 1999
Location: Kelowna, B.C., Canada
Posts: 9,138
No, that's AVG anti-virus' signature file.
It could be that NAV thinks that it's a virus, because it contains the names of the viruses that AVG removes.
reboot is offline   Reply With Quote
Old 06-12-2003, 12:17 PM   #13
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
around2bit,

How do I delete my system restore points like you mentioned?
KlumpDud is offline   Reply With Quote
Old 06-12-2003, 04:34 PM   #14
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
This is driving me nuts! I used 4 different AV programs, including the Lovegate removal tool. Reformatted, reinstalled windows, and it's back!

That leads me to the conclusion that it's somewhere on my D: Harddrive, but I've used a bunch of programs to scan and clean both my harddrives, so what am I supposed to do?
KlumpDud is offline   Reply With Quote
Old 06-12-2003, 04:47 PM   #15
Staff
Premium Member
 
mairving's Avatar
 
Join Date: Jul 1999
Location: Arlington, TN
Posts: 5,538
You don't have system restore or points since you are running W2K. ME and XP have them but not 2K.

You might have mentioned that you had another partition. Have you scanned that partition as well?
mairving is offline   Reply With Quote
Old 06-12-2003, 05:23 PM   #16
Member (10 bit)
 
Join Date: Dec 2001
Posts: 592
Yes, all the scanning that I did with all the anti-virus programs included both hard drives

Why can't any of the programs get rid of it?
KlumpDud is offline   Reply With Quote
Old 06-12-2003, 08:34 PM   #17
Tanker Yanker
Premium Member
 
doubledragon5's Avatar
 
Join Date: Nov 2001
Location: Lewisville TX
Posts: 2,920
If that is a big issue and it is I use a program now and then called wipe drive. It is on a floopy and destroys everything on the drive period. Depending on how big your drive is and how many times you write over it it can take a long time.

I had some viruses once that I could not get rid of, so when I wiped my hd drive clean I choose write x3 and it took 14 hrs for a 100GB drive.

The makers say it is made to clean your HD of anything you don't want people to see and it is the same standards the department of difense uses. They say on wipe will make it impossible,and to expensive for anyone to find information on your HD.
__________________


MB: DFI Lanparty UT-NF4 SLI-D/Processor AMD Athlon 64x2 Toledo/video Card:XFX 9800GTX+/Audio:Sound Blaster Audigy 4/Ram:Corsair XMS Extreme 4x1Gig PC3200/HD:1x150GBWestern Digital Raptor 1x80GB Segate Beracuda 7200 SATA /Monitor:ASUS VS247 H-P 23.6"/Keyboard Mouse:Logitech Cordless Wave/Speakers: Logitech G51/Printer/Fax/Scanner:Brother MFC-685CW
doubledragon5 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 12:01 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2