OT: Virus infection WAS Re: Computer Statement Usage

From: Peter E.C Dashwood (dashwood_at_enternet.co.nz)
Date: 10/17/04

  • Next message: LX-i: "Re: Creative Javascript writing"
    Date: Sun, 17 Oct 2004 13:01:02 +1300
    
    

    Robert,

    I'm really sorry you have been infected and I know you will be doing
    everything you can to remove this.

    Please don't take offense at the following (comparatively simple)
    suggestions; I am not trying to "teach my grandmother to suck eggs" and my
    advice in no way reflects on your competency or ability.

    (It's just that sometimes when we are under stress we miss what might
    otherwise be obvious...)

    1. Download and run hijackthis. I have found it extremely useful when there
    are registry hooks involved. Inspection of the log from it may give you some
    further clues.
    http://www.tomcoyote.org/hjt/
    2. Download AdAware, update it to the latest version, then run it. It is
    free for personal use.
    http://www.lavasoftusa.com/software/adaware/
    3. I'm sure you have a very good virus protector, but has it been updated?
    4. There is Trojan detector software available from: http://xoftspyware.com/
    (I found this product outstanding. It found some registry entries that were
    missed by AdAware, but AdAware found some stuff missed by Xoft...)

    If all of the above reports "clear" and yet you know there is something
    running somewhere, then it is possible it is a direct attack on you
    personally, with a "tailored" virus or worm. All you can really do is keep
    monitoring the ports and running processes. You might think about checking
    for executable files that were created/modified around the time the symptoms
    started appearing.

    Hope you crack it soon.

    Pete.

    "Robert Wagner" <robert@wagner.net.yourmammaharvests> wrote in message
    news:1q4nm0lq7unpc0quhqp489tkefpt5tebmm@4ax.com...
    > On 11 Oct 2004 19:52:46 -0400, docdwarf@panix.com wrote:
    >
    > >In article <dl3mm011cq6ctjpl1micqvtfccmklqf8ah@4ax.com>,
    > >Robert Wagner <robert@wagner.net.yourmammaharvests> wrote:
    > >>On Mon, 11 Oct 2004 13:07:22 -0700, "Chuck Stevens"
    > >><charles.stevens@unisys.com> wrote:
    > >>
    > >>>(Top posting):
    > >>>
    > >>>I am having difficulty understanding how the average reader of a
    response
    > >>>such as the one below would be stimulated to anything but contempt and
    > >>>disgust toward its author.
    > >>
    > >>You're right. The next morning I regretted posting it.
    > >>
    > >>I wrote it after spending 24 hours battling hackers, followed by an
    > >>hour or two celebrating victory. Putting it bluntly, I was drunk.
    > >
    > >Hmmmm... one of those dead-language-aphorisms is trying to surface...
    > >something about wine and truth.
    >
    > Translated: 'Nothing is said while inebriated that wasn't thought
    > while sober.' I wrote about crudeness and cruelty, so I might have
    > been thinking about .. what?
    >
    > FWIW, the victory was illusory, hacker code is still functioning. We
    > keep thinking .. if I could find THE file and delete it, the problem
    > would gone. In this case it's not a file, it's a sequence of registry
    > entries and scripts intertwined with legit Microsoft stuff. They use
    > Microsoft software to install their hooks.
    >


  • Next message: LX-i: "Re: Creative Javascript writing"

    Relevant Pages

    • Re: OT: Virus infection WAS Re: Computer Statement Usage
      ... It found some registry entries that were ... >monitoring the ports and running processes. ... >> entries and scripts intertwined with legit Microsoft stuff. ...
      (comp.lang.cobol)
    • Re: Windows XP buggy and unstable
      ... I'll bet AdAware doesn't do a thing for you and hasn't found a problem to ... one can manually delete temp files or use XP's Disk Cleanup ... I'm not referring to the registry "Issues" function of Ccleaner. ... Abexo Registry Cleaner, Easy Clean etc. ...
      (microsoft.public.windowsxp.basics)
    • Re: VX2 - My Victory!
      ... The AdAware VX2 cleaner didn't work for me either. ... >> the spyware in Safe Mode or whatsoever. ... >> I search the registry for these two files. ...
      (microsoft.public.security.virus)
    • Re: CoolWebSearch
      ... AdAware with updates did detect it as Cool Web variant of high ... AdAware would remove it but every time I would run AdAware it would ... folders and the registry. ... I later enabled support for third party browser ...
      (microsoft.public.security)
    • RE: Start-up registry problem
      ... "AutoRuns for Windows v8.61 By Mark Russinovich and Bryce Cogswell" ... The tool above will show in real time the running processes and can show ... Searh for these Running processes and delete them from your system. ... Deleted line out of registry, ...
      (microsoft.public.windowsxp.perform_maintain)