Virus Help

Technical - hardware, software, upgrades, building your PC
Bookmark and Share

Virus Help

Postby [SiK]Demiveil on Mon Feb 11, 2008 2:08 pm

I currently have a very annoying virus problem which I cannot seem to solve so thought I would ask for some help.

I have Avast Antivirus, Lavasoft Adaware SE, Zonelarm Firewall and ProcessGuard running security wise on my computer, and yet on every boot a virus is detected within my Local Settings/Temp folder, the file is a .dll of alternating name (xcvyz2.dll etc)
Whilst Avast easily seems to detect and delete the virus (Win32-Troj) it does not stop the problem on boot, it would seem some program is making said .dll yet ProcessGuard does not detect any Process attempting to start, so I am at a loss as to how to find the culprit.

Any Advice?
User avatar

[SiK]Demiveil
[DRuG] member

Status:
Wooo just got me a new job :) Uni pays off after all.

[DRuG] member
[SiK] member
 
Posts: 235
Joined: Sun Oct 28, 2007 8:33 pm
Location: Christchurch, New Zealand


Re: Virus Help

Postby [DRuG]NikT on Mon Feb 11, 2008 3:17 pm

[SiK]Demiveil wrote:I currently have a very annoying virus problem which I cannot seem to solve so thought I would ask for some help.

I have Avast Antivirus, Lavasoft Adaware SE, Zonelarm Firewall and ProcessGuard running security wise on my computer, and yet on every boot a virus is detected within my Local Settings/Temp folder, the file is a .dll of alternating name (xcvyz2.dll etc)

This is a symptom of the fact that the dll itself is being spawned from elsewhere - likely a source file that is able to go under the radar of your scanners, but contains the data required to generate the virus' dll. As such, addressing the infected dll doesn't fix the source of the problem, which is likely hidden away in a virus "hive" -- these are areas of your machine for which the operating system is not at liberty to modify, however, the virus often can. Hives are areas, for example, like "system restore points" - these should always be disabled and should not be used. With all hives disabled, I suggest you run Kaspersky AntiVirus.. it is very good for disinfecting infected machines. I have used it many times with success where others have failed. It will require a commercial key.

[SiK]Demiveil wrote:Whilst Avast easily seems to detect and delete the virus (Win32-Troj) it does not stop the problem on boot, it would seem some program is making said .dll yet ProcessGuard does not detect any Process attempting to start, so I am at a loss as to how to find the culprit.
Any Advice?

Perhaps contact me direct, but really, this problem can be solved with Kaspersky, and prevented by disabling restore points and other hives.


"But my head's all messed up, so you better driive brother"
User avatar

[DRuG]NikT
[DRuG] cofounder & your host

Status:
Check out the downloads and members areas on drugcrew.com

[DRuG] cofounder & your host
[DRuG] coleader
[DRuG] member
DRuG server admin
[AGS] member
]DR[ member
 
Posts: 2532
Joined: Sat Jul 28, 2007 10:39 am
Location: Melbourne, Victoria, Australia


Re: Virus Help

Postby [SiK]Grim_Reeper on Mon Feb 11, 2008 4:14 pm

Demi, if you can identify any of the virus files try this lil program.
http://download.bleepingcomputer.com/sp ... illBox.exe

With Killbox you will have to locate the file and then try to delete it while having the "End Explorer Shell While Killing" box ticked.
User avatar

[SiK]Grim_Reeper
[SiK] member
[SiK] member
 
Posts: 158
Joined: Thu Oct 04, 2007 11:27 am
Location: Townsville, Queensland


Re: Virus Help

Postby [DRuG]KillFrenzy on Mon Feb 11, 2008 5:10 pm

The virus may have gone deeper and crippled Windows itself to force it to boot up with that virus loaded. I'm pretty good at manually removing viruses, but you'll need some technical knowledge with Windows.
1. Make sure you've removed that virus and remember the file path it was in.
2. Try to boot into safe mode (keep tapping F8 on bootup).
3. Check if the virus is there. You must check manually, as the anti-virus is not loaded while in safe mode, nor any other startup programs.


IF THE VIRUS IS STILL THERE:

The virus has infected the system files. Insert your Windows CD and restart the computer, booting up with the CD. I've found an okay website with instructions to repair the system files. Make sure you backup. This way may be quite a hassle.
http://www.michaelstevenstech.com/XPrepairinstall.htm


IF THE VIRUS IS NOT THERE:

If you haven't already, perhaps you could try checking your startup applications and processes. Click on your Start Menu, press Run, and enter in 'msconfig'.

Look through anything suspicious in the Services and Startup tab. Be careful with disabling some of the Services though, it can stop your computer working if you uncheck the wrong ones. Although the computer will still work if you disable all the Startup items.

If that still doesn't work, you may have to check if the virus has installed any drivers. Right click on 'My Computer' and click on properties. Go to the 'Hardware' Tab, then 'Device Manager'. Look through all the hardware and see if anything is suspicious. Disable it. If that doesn't help, I'd recommend re-enabling it again.


Well, hope that can help you manually remove the virus. I just noticed how much I wrote :P
User avatar

[DRuG]KillFrenzy
[DRuG] member
[DRuG] member
[alr] member
 
Posts: 257
Joined: Sat Jul 28, 2007 7:07 pm
Location: My House


Re: Virus Help

Postby [SiK]Demiveil on Mon Feb 11, 2008 5:16 pm

Thanks for the help, will try each of these suggestions until one works, if it comes down to reinstalling windows that shouldn't be a problem given my hard disk is partitioned into 3 sections, XP32, Vista64 and a Storage Drive where most of my actual programs etc lie.
User avatar

[SiK]Demiveil
[DRuG] member

Status:
Wooo just got me a new job :) Uni pays off after all.

[DRuG] member
[SiK] member
 
Posts: 235
Joined: Sun Oct 28, 2007 8:33 pm
Location: Christchurch, New Zealand


Re: Virus Help

Postby DragonMaster on Mon Feb 11, 2008 5:22 pm

I'm not really a "PC professional" but I can say one thing. Try not to overload your computer with anti-viruses, having one good anti-virus is the best.
Dragon:
1. A flying dinosaur.
2. Something that you'll never own.

Interesting facts:
1. DragonMaster is the commander of all dragons.
2. Only DragonMaster can call them Flynosaurs.

©569BC-1 second ago
User avatar

DragonMaster
forum member
forum member
 
Posts: 114
Joined: Tue Dec 11, 2007 10:12 pm


Re: Virus Help

Postby [SiK]Demiveil on Mon Feb 11, 2008 5:36 pm

I am aware of that, and have certainly done no such thing, thanks for the input though.
User avatar

[SiK]Demiveil
[DRuG] member

Status:
Wooo just got me a new job :) Uni pays off after all.

[DRuG] member
[SiK] member
 
Posts: 235
Joined: Sun Oct 28, 2007 8:33 pm
Location: Christchurch, New Zealand


Re: Virus Help

Postby [DRuG]NikT on Mon Feb 11, 2008 5:37 pm

I've said it once, and I'll say it again. Use Kaspersky.

If this doesn't work, don't go anywhere near a windows disk - contact me directly.

The procedures outlined above show ignorance of the systematic approach to removing virii/locked files in the standard manner - booting off media that doesn't lock the files - eg. a BartCD/XP/PE "live" CD.

With this disk booted, none of the files infected & locked by the OS are locked any more, making disinfection a snap.

I suggest Kaspersky because it has had success where about 12 other scanners fail. I have to disinfect machines every day for work, often from the opposite side of the planet, while dealing with someone that doesn't speak English as their first language.

Stay in touch & let me know how you go.


"But my head's all messed up, so you better driive brother"
User avatar

[DRuG]NikT
[DRuG] cofounder & your host

Status:
Check out the downloads and members areas on drugcrew.com

[DRuG] cofounder & your host
[DRuG] coleader
[DRuG] member
DRuG server admin
[AGS] member
]DR[ member
 
Posts: 2532
Joined: Sat Jul 28, 2007 10:39 am
Location: Melbourne, Victoria, Australia


Re: Virus Help

Postby [DRuG]KillFrenzy on Mon Feb 11, 2008 5:44 pm

Lol yeah, having more than one anti-virus or more than one firewall can mess up your computer. Also a conflicting anti-virus and firewall can also mess up the computer. I like how you've got your system partitioned and ready for formatting though :)

EDIT: Nikt is right, The Windows CD should always be your last option. I forgot to mention about the anti-virus.
User avatar

[DRuG]KillFrenzy
[DRuG] member
[DRuG] member
[alr] member
 
Posts: 257
Joined: Sat Jul 28, 2007 7:07 pm
Location: My House


Re: Virus Help

Postby [SiK]Demiveil on Mon Feb 11, 2008 5:50 pm

I unfortunately do not have any means of actually purchasing a copy of Kaspersky, given I have no credit card etc.
User avatar

[SiK]Demiveil
[DRuG] member

Status:
Wooo just got me a new job :) Uni pays off after all.

[DRuG] member
[SiK] member
 
Posts: 235
Joined: Sun Oct 28, 2007 8:33 pm
Location: Christchurch, New Zealand


Next

Return to Tech & PC Chat

Who is online

Users browsing this forum: No registered users and 1 guest

cron