UndergroundScene Forums  

Welcome to the UndergroundScene Forums forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!


Go Back   UndergroundScene Forums > SPECIAL AREAS > Information Technology
Register FAQ Site Areas Gig Guides Members Calendar Arcade Mark Forums Read

Reply
 
LinkBack (1) Thread Tools Display Modes
Old 3rd May 2008, 04:17 PM   1 links from elsewhere to this Post. Click to view. #1 (permalink)
My First Kev
Senior Member
 
My First Kev's Avatar
 
Join Date: Aug 2003
Location: Crewe, Cheshire
Posts: 1,910
My First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really nice
Unhappy I have a virus

If anyone on here could help that would be lovely.

I was downloading what i thought was "Diary of the Dead" via bit torrent. when the download was complete I went to watch it in divx movie player when a messege popped up saying my drivers were out of date. Seemed reasonable. I hit the run button and well....

I now get a bogus 'system error' message everytime i open a window asking me to 'download the latest anti-virus software or my computer will crash' and any time i use search engine the results are either 'click here to win an i-pod', porn or said bogus anti-virus software.

I've run 'PC Tools Spyware Doctor' which found a trojan and claimed to have fixed it but the problem still persists. The Free AVG anti-virus software keeps picking up on a shell32.dll in my system32 folder but can't do anything about it.

Any ideas?

Last edited by My First Kev : 3rd May 2008 at 05:33 PM.
My First Kev is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 3rd May 2008, 08:28 PM   #2 (permalink)
LimpKnot
Registered User
 
LimpKnot's Avatar
 
Join Date: Apr 2002
Location: Dundee
Posts: 392
Band: I'm involved with your mom
LimpKnot will become famous soon enoughLimpKnot will become famous soon enoughLimpKnot will become famous soon enoughLimpKnot will become famous soon enoughLimpKnot will become famous soon enough
Don't steal?
LimpKnot is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 3rd May 2008, 11:44 PM   #3 (permalink)
Hometown Zero
Senior Member
 
Hometown Zero's Avatar
 
Join Date: Dec 2005
Location: the 'dee
Posts: 1,345
Band: Wasted Nation
Hometown Zero has a spectacular aura aboutHometown Zero has a spectacular aura aboutHometown Zero has a spectacular aura aboutHometown Zero has a spectacular aura aboutHometown Zero has a spectacular aura aboutHometown Zero has a spectacular aura aboutHometown Zero has a spectacular aura about
try the software you have there already but also try ad-aware or spybot? I always try to updated the program, then completely disconnect from any net connection (I actually take the wire out), reboot then run the software again whilst still offline.

might work, might not but worth a try i suppose.
Hometown Zero is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 4th May 2008, 12:06 AM   #4 (permalink)
RiseAgainst
rambling boy of pleasure
 
RiseAgainst's Avatar
 
Join Date: Aug 2004
Location: Work id presume
Posts: 3,331
Band: bandless :(
RiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the rough
you have a spyware running on your machine.

Remove Spyware - Anti-Spyware Tools Ad-Aware And Spybot - Easy Computer Tips

gives you a nice guide to sorting it.

you could also try replacing shell32.dll if its been modified by the trojan.
RiseAgainst is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 4th May 2008, 03:01 PM   #5 (permalink)
My First Kev
Senior Member
 
My First Kev's Avatar
 
Join Date: Aug 2003
Location: Crewe, Cheshire
Posts: 1,910
My First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really niceMy First Kev is just really nice
Quote:
Originally Posted by RiseAgainst View Post
you have a spyware running on your machine.

Remove Spyware - Anti-Spyware Tools Ad-Aware And Spybot - Easy Computer Tips

gives you a nice guide to sorting it.

you could also try replacing shell32.dll if its been modified by the trojan.
the programes didn't find my problem but i replaced the file (didn't even know i could til you said) and now everythings soretd!



cheers!
My First Kev is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 4th May 2008, 06:11 PM   #6 (permalink)
: : Scott : :
Senior Member
 
Join Date: Mar 2003
Location: Dundee
Posts: 7,130
: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute: : Scott : : has a reputation beyond repute
Back up all your data, format your drives and reinstall your OS as soon as possible. Even if the symptoms seem to be fixed you are now in a state where you just don't know what's still lurking there. I wouldn't do anything (banking, etc) until you do as suggested. Sucks, but it's the only way to be sure.
: : Scott : : is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 4th May 2008, 09:23 PM   #7 (permalink)
RiseAgainst
rambling boy of pleasure
 
RiseAgainst's Avatar
 
Join Date: Aug 2004
Location: Work id presume
Posts: 3,331
Band: bandless :(
RiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the rough
if a trojan was running using shell32, replacing it will clear anything to do with it as it wont have anything to call any crap its left behind.

it'd only be if you had another trojan (which would hopefully get flagged by the AV) that itd be unsafe.

and if you backup all your data you could copy a virus over, so that'd potentially do nothing but waste time.

You could reset your firewall's software accesses and make it alert you to them all if you really wanna get paranoid.

Last edited by RiseAgainst : 4th May 2008 at 09:26 PM.
RiseAgainst is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 4th May 2008, 11:08 PM   #8 (permalink)
CaptainAmerica
Registered User
 
Join Date: Apr 2008
Location: Aberdeen/Montrose
Posts: 14
CaptainAmerica is an unknown quantity at this point
I had a similar virus by the sounds of it.

I just ran spybot with windows in safe mode and that deleted it.

As usual my shitty Norton couldn't even find it.
CaptainAmerica is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 5th May 2008, 02:39 PM   #9 (permalink)
RiseAgainst
rambling boy of pleasure
 
RiseAgainst's Avatar
 
Join Date: Aug 2004
Location: Work id presume
Posts: 3,331
Band: bandless :(
RiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the roughRiseAgainst is a jewel in the rough
which version of Norton you running? i tend to find Norton is awesome if you dont use the default settings which baffles me that they continue to set it up that way.
RiseAgainst is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://www.undergroundscene.co.uk/forum/information-technology/51883-i-have-virus.html
Posted By For Type Date
UndergroundScene.co.uk This thread Refback 3rd May 2008 08:52 PM

Similar Threads
Thread Thread Starter Forum Replies Last Post
Gig in anstruther Kevxx Gig / Event Announcements & Gig Seeking 37 9th August 2005 10:43 AM
msn vbulletin virus Hecate Information Technology 9 6th August 2005 11:43 PM
Virus? TNF Information Technology 8 26th April 2005 10:38 AM
I have a nasty virus... please help. gord Information Technology 8 12th March 2005 06:34 PM
Virus help please! PrettyPumpkin Information Technology 7 26th January 2005 09:05 PM


All times are GMT. The time now is 12:41 PM.


Powered by vBulletin
UndergroundScene.co.uk is bad-ass and under copyright

Content Relevant URLs by vBSEO 3.0.0 RC8