Author Topic: I can not get to restore or even have norton run online virus scan  (Read 17603 times)

0 Members and 2 Guests are viewing this topic.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11228
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: I can not get to restore or even have norton run online virus scan
« Reply #75 on: January 09, 2009, 10:04:52 PM »
Hi, Nash.  I don't know where they are coming from unless it is your son downloading files with the P2P programs.  I'm going to ask for another pair (or two) of eyes to take a look.  It could also be that something has been staring me in the face and I just haven't seen it. 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11228
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: I can not get to restore or even have norton run online virus scan
« Reply #76 on: January 09, 2009, 11:06:42 PM »
Hi, Nash.  A fellow team member suggested the symptoms are similar to the exploits discussed in MS08-067 and a scan at F-Secure.  Please allow F-Secure to remove anything found and provide a report of any actions here.  Thanks.

The instructions are available here:  http://support.f-secure.com/enu/home/ols.shtml
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline nash017

  • Jr. Member
  • **
  • Posts: 63
Re: I can not get to restore or even have norton run online virus scan
« Reply #77 on: January 11, 2009, 07:11:49 PM »
Hi Corrine, I dont know if your site was down yesterday but I could not get on at all, I tried the F-secure, it downloaded the online files, and when I wanted it to scan the system, it crashed, and my browser went down with it, so i tried again, and this time it worked on a shorter scan mode, i reported it to F-secure. Here is the log  :

Scanning Report
Saturday, January 10, 2009 00:46:30 - 11:23:02
Computer name: nash
Scanning type: Scan system for malware, rootkits
Target: C:\ G:\


--------------------------------------------------------------------------------

Result: 8 malware found
Client-IRC.Win32.mIRC (spyware)
System
TrackingCookie.Revsci (spyware)
System
TrackingCookie.Webtrends (spyware)
System
TrackingCookie.Xiti (spyware)
System
TrackingCookie.Zanox (spyware)
System
Trojan.Win32.Agent.bewa (virus)
C:\QOOBOX\QUARANTINE\C\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\MICROSOFT\IPDLL.DLL.VIR (Renamed & Submitted)
W32/Packed_FSG.D (virus)
C:\DOWNLOADS\SPYWARE DOCTOR 5.1.0.273 WITH ANTIVIRUS\KEYGEN\KEYGEN.EXE (Submitted)
mIRC/Gen_COM (virus)
C:\EXCURSION9.5\SYSTEM\REMOTES\EXS011.MRC (Submitted)

--------------------------------------------------------------------------------

Statistics
Scanned:
Files: 135048
System: 4599
Not scanned: 31
Actions:
Disinfected: 0
Renamed: 1
Deleted: 0
None: 7
Submitted: 3
Files not scanned:
C:\WINDOWS\TEMP\PERFLIB_PERFDATA_60C.DAT
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SAM
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
C:\WINDOWS\SYSTEM32\CATROOT2\EDB.LOG
C:\WINDOWS\SYSTEM32\CATROOT2\TMP.EDB
C:\QOOBOX\QUARANTINE\C\WINDOWS\NIRCMD.EXE.VIR.VIR
C:\DOCUMENTS AND SETTINGS\NORMAN\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\NORMAN\NTUSER.DAT.LOG
C:\DOCUMENTS AND SETTINGS\NORMAN\LOCAL SETTINGS\TEMP\JET3B08.TMP
C:\DOCUMENTS AND SETTINGS\NORMAN\LOCAL SETTINGS\TEMP\~DF772D.TMP
C:\DOCUMENTS AND SETTINGS\NORMAN\LOCAL SETTINGS\TEMP\~DF773F.TMP
C:\DOCUMENTS AND SETTINGS\NORMAN\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\NORMAN\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT.LOG
C:\DOCUMENTS AND SETTINGS\NORMAN\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\CARDSPACE\CARDSPACE.DB
C:\DOCUMENTS AND SETTINGS\NORMAN\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\CARDSPACE\CARDSPACE.DB.SHADOW
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\NTUSER.DAT.LOG
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT.LOG
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\NTUSER.DAT.LOG
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT.LOG

--------------------------------------------------------------------------------

Options
Scanning engines:
F-Secure USS: 2.40.0
F-Secure Hydra: 2.8.8110, 2009-01-09
F-Secure AVP: 7.0.171, 2009-01-09
F-Secure Pegasus: 1.20.0, 2008-11-17
F-Secure Blacklight: 0.0.0
Scanning options:
Scan all files
Use Advanced heuristics

--------------------------------------------------------------------------------

Copyright © 1998-2007 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.

Offline Eric the Red

  • ISO/IEC 27001:2005
  • Administrator
  • Hero Member
  • *****
  • Posts: 1611
  • Would somebody please pass me a beer!
Re: I can not get to restore or even have norton run online virus scan
« Reply #78 on: January 12, 2009, 09:52:12 PM »
Nash,

I don't like that, especially the line:

Quote
Trojan.Win32.Agent.bewa

I would like you to go to the following Sophos web page and read the instructions contained within, don't do anything else yet, what I want you to decide is whether or not you are confident to follow the directions at that page.

What we are looking at there is to download a stand alone virus checker and the relevant signature files it uses, boot the computer into safe mode and run the AV tool from a Command line. Don't do it yet, just report back if you think you can because I have a couple of points that may make the instructions a bit more clear.

The page in question is:

http://www.sophos.com/support/knowledgebase/article/13251.html
"The time to start running is around about the "e" in "Hey, you!" "
Proud member Since 2004 

The information I provide is provided "AS IS" without warranty, and confers no rights.

Offline Eric the Red

  • ISO/IEC 27001:2005
  • Administrator
  • Hero Member
  • *****
  • Posts: 1611
  • Would somebody please pass me a beer!
Re: I can not get to restore or even have norton run online virus scan
« Reply #79 on: January 14, 2009, 07:07:32 AM »
Nash,

Put the above post to one side for a minute, I have just discovered that McAfee have updated their Avert Stinger tool and this version covers the infections I suspect that you are seeing. Stinger is easier to use than the Sophos tool as it can be run in the GUI. Download the tool from:
 
http://vil.nai.com/vil/stinger/

and save it to your desktop. Reboot the machine to "Safe Mode", disable system restore (details of how to do this are on the McAfee page) and run Stinger. Once it has run restart in Normal mode and let us know the results. See FAQ #2 on the McAfee page for details of how to save the logfile.
"The time to start running is around about the "e" in "Hey, you!" "
Proud member Since 2004 

The information I provide is provided "AS IS" without warranty, and confers no rights.

Offline nash017

  • Jr. Member
  • **
  • Posts: 63
Re: I can not get to restore or even have norton run online virus scan
« Reply #80 on: January 14, 2009, 09:28:22 PM »
Hi Eric, here are the results:
McAfee® Stinger Version 10.0.0.482 built on Jan  9 2009

Copyright © 2008 McAfee, Inc. All Rights Reserved.

Virus data file v1000 created on Jan 10 2009.

Ready to scan for 538 viruses, trojans and variants.



Scan initiated on Wed Jan 14 17:28:26 2009

  Number of clean files: 325389




Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11228
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: I can not get to restore or even have norton run online virus scan
« Reply #81 on: January 14, 2009, 11:08:23 PM »
Well, dang it!  Just so you know, you're not alone, Nash.  I'm a bit tied up with some real life issues right now but the staff is consulting in the background.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Eric the Red

  • ISO/IEC 27001:2005
  • Administrator
  • Hero Member
  • *****
  • Posts: 1611
  • Would somebody please pass me a beer!
Re: I can not get to restore or even have norton run online virus scan
« Reply #82 on: January 15, 2009, 10:23:19 PM »
Hi Nash,

Two major AV products are indicating that there is no longer an infection, let's take a step back and assess the current situation. You posted earlier:

Quote
Apart from that the PC seems to be running better, can't open web pages from links in emails, can look at a few more pages tho' from google.

What is the current situation? Are there any symptoms being displayed that may indicate that you are still having problems?

"The time to start running is around about the "e" in "Hey, you!" "
Proud member Since 2004 

The information I provide is provided "AS IS" without warranty, and confers no rights.

Offline nash017

  • Jr. Member
  • **
  • Posts: 63
Re: I can not get to restore or even have norton run online virus scan
« Reply #83 on: January 16, 2009, 05:33:10 PM »
Hi Eric and Corrine, the situation at the moment is , I can get on the web, but every now and then it locks and i have to reconnect, I can go to web pages from emails as well now. Avira has not found anything just lately, but then I have not been on much (a pets demise ).
I am keeping an eye on my web browsing and have Webroot running all the time scanning incoming and out going IPs also which ports are in use, so hopefully it is getting much better, thanks to you and the Landzdown Forum :flowers: So i will keep monitering and if anything happens you will be the first to know, Thank you very much.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11228
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: I can not get to restore or even have norton run online virus scan
« Reply #84 on: January 16, 2009, 06:37:57 PM »
Nash, I am so sorry to hear about the loss of your family pet and fully appreciate what your family is dealing with.

I've just a minute here so will take a look later at any tools that were used that can be removed for cleanup and any other recommendations. 
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11228
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: I can not get to restore or even have norton run online virus scan
« Reply #85 on: January 18, 2009, 11:13:22 PM »
Hi, Nash. 

Please do the following to implement cleanup procedures an also to reset System Restore points:

Click Start > Run  and copy/paste the following bolded text into the Run box and click OK:  ComboFix /u



Note: In the event you wish to contribute to the ongoing development of ComboFix, the developer is accepting donations via PayPal.

Because your son appears to be using P2P software, a strong word of caution: 

P2P programs form a direct conduit on to your computer. They have always been a target of malware writers and are increasingly so of late. P2P security measures are easily circumvented and if your P2P program is not configured correctly, you may be sharing more files than you realize. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to the file sharing network by a badly configured program. Use of P2P programs can result in Identity Theft.

Having a firewall, anti-virus and anti-malware software are not enough.  You also need to stay current with security updates.  If you don't have your computer set to automatically install the Microsoft Security Updates, please check for updates now.  For additional information, see my blog post Understanding Microsoft Updates

To check if your system is missing security updates or has insecure applications installed, visit http://secunia.com/software_inspector/ .  The Secunia Software Inspector runs through your browser with no installation or download required and does the following:
  • Detects insecure versions of applications installed
  • Verifies that all Microsoft patches are applied
  • Assists you in updating your system and applications

Install and update SpywareBlaster to prevent the installation of spyware and other potentially unwanted software: http://www.javacoolsoftware.com/spywareblaster.html

My favorite security software is WinPatrol which includes the features described at http://www.winpatrol.com/features.html

Please let me know if you have any questions.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11228
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: I can not get to restore or even have norton run online virus scan
« Reply #86 on: January 19, 2009, 10:26:27 PM »
Hi, Nash.

I would like you to do one more thing -- because it will give me a more comfortable feeling about the current status of your computer.  Please download the Microsoft Malicious Software Removal Tool from here:  http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en

The following information regarding the running of the MSRT was copied from Microsoft KB Article 891717:

The Malicious Software Removal Tool runs in quiet mode. If it detects malicious software on your computer, the next time that you log on to your computer as a computer administrator, a balloon will appear in the notification area to make you aware of the detection.

Performing a full scan

If the tool finds malicious software, you may be prompted to perform a full scan. We recommend that you perform this scan. A full scan performs a quick scan and then a full scan of the computer, regardless of whether malicious software is found during the quick scan. This scan can take several hours to complete because it will scan all fixed and removable drives. However, mapped network drives will not be scanned.
Removing malicious files

If malicious software has modified (infected) files on your computer, the tool prompts you to remove the malicious software from those files. If the malicious software modified your browser settings, your homepage may be changed automatically to a page that gives you directions on how to restore these settings.

You can clean specific files or all the infected files that the tool finds. Be aware that some data loss is possible during this process. Also, be aware that the tool may be unable to restore some files to the original, pre-infection state.

The removal tool may request that you restart your computer to complete the removal of some malicious software, or it may prompt you to perform manual steps to complete the removal of the malicious software. To complete the removal, you should use an up-to-date antivirus product.

Reporting infection information to Microsoft

The Malicious Software Removal Tool will send basic information to Microsoft if the tool detects malicious software or finds an error. This information will be used for tracking virus prevalence. No identifiable personal information that is related to you or to the computer is sent together with this report.



Let us know the results.

Thank you!
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline nash017

  • Jr. Member
  • **
  • Posts: 63
Re: I can not get to restore or even have norton run online virus scan
« Reply #87 on: January 23, 2009, 07:27:21 PM »
Hi Corrine, I use the p2p to watch football (soccer) on the pc, the program is myp2p and i only go on it once a week if possible, the other program i use is packet news on Mirc, which i think could be the one that has a virus, as when i open it i get popups in the back ground and the pc tells me something is downloading behind the main screen. I have been on packet news for the last 4 years and it has always been clean.
I tried The Secunia Software Inspector but it stopped working, something about java applets, which I know that my Java is up to date, so maybe could be a problem there??
Apart from that everything seems to be working great, i ran Avira all night scanning and did not find anything, also Microsoft Malicious Software Removal Tool scanned and found nothing, but will put it on scan over night just in case.

Offline winchester73

  • Administrator
  • Hero Member
  • *****
  • Posts: 5077
  • Half a bubble off plumb
Re: I can not get to restore or even have norton run online virus scan
« Reply #88 on: January 23, 2009, 08:37:31 PM »
If memory serves, some of the MyP2P streams have had an issue with Zango.  There is always a danger with any p2p download ...  :(

BTW, my Liverpool boys have won more trophies than any other English side:  18 First Division, 7 League Cups, 5 European Champions Cups, 7 FA Cups.   :D
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member



Offline nash017

  • Jr. Member
  • **
  • Posts: 63
Re: I can not get to restore or even have norton run online virus scan
« Reply #89 on: February 23, 2009, 07:13:09 PM »
Hi Corrine and Eric, have had probs with my server, my telephone line had a fault on it and my provider service help is based in India, so a few language problems for a start, also they said no problem with line for weeks, but i knew there was and now they have rectified it at long last.
So far No major problems ( touch wood), a few trojans have tried to get through but my defences are up and they are being kept at bay, also being very careful about what i download of the net as well.
Eric  my team is Chelsea, but we all have a cross to bare,  :laughing: