|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
Papoila
Trooper

 Joined: Feb 06, 2005 Posts: 17 Location: Netherlands
|
Posted: Mon Feb 14, 2005 11:13 pm Post subject: NEWBIE! HELP! Rapidly multiplying virus UNNOTICED by Antivir |
|
|
Hello! Please help me!!!
I have found almost 200 image files (supposedly!), all rootnamed "AlbumArt" spreading within all my music folders and in the recycler folder. When trying to delete them, the confirmation pop-up window says that they're system files. I've scanned my pc with Antivir PE (installed and updated) and several online anti-virus scanners but ALL FAILED to find something!!! This weekend I lost access to the internet without any apparent reason and only got it back after restoring the system back to a few days ago. Also, I have disabled 2 suspicious entries (squares both under Startup item and Command) in the startup menu, located in
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows.
Oh, and I'm running Windows XP SP2. Is there anything else you need to know?
What should I do? I have no idea how to find and remove a virus without an antivirus tool signaling it for me!!! I thank you in advance for your help!!!
|
|
| Back to top |
|
 |
satishincbs
Trooper

 Joined: Oct 12, 2004 Posts: 27 Location: India
|
Posted: Tue Feb 15, 2005 3:53 pm Post subject: |
|
|
Hi
Don't panic. Try sending the suspicious file to virus@free-av.com for analysis.
It could be a new virus. But who knows, it might be a system problem as well..
But before u do that, zip the file using winzip or winrar and encrypt it with a password and send the password along with the file to the above-mentioned address.
You can be sure to get a reply from AntiVir within a day.
Also, you could try google to find if there is a virus with the characteristics you describe.
Regards
|
|
| Back to top |
|
 |
Papoila
Trooper

 Joined: Feb 06, 2005 Posts: 17 Location: Netherlands
|
Posted: Tue Feb 15, 2005 11:25 pm Post subject: Desperate situation!!!!!!!! |
|
|
Hi!
First of all, thanks for your reply!
I tried to do that just now and I guess something went wrong!!!! I was trying to compress and encrypt a sample of the files and protect with a password on Winrar and as soon as I hit the "OK" button, the pc automatically terminated the session and tried to reboot (it didn't crash, rather closed normally, except that I didn't tell it to do so...). I pulled the plug on it, but it only "died" after completely closing Windows!!! I think the virus in those files must have been activated in this process, although I never opened any, and probably had the time to lodge itself on my boot sector...
What should I do now???? Is it safe to turn the pc on and try to restore the system to yesterday, for instance? Can I do that in safe mode? I have a boot CD, but it's still for the SP1, I didn't have the chance to make a new one... Will it work neverthess? PLEASE HELP!!!!
(I'm at a friend's pc now)
|
|
| Back to top |
|
 |
satishincbs
Trooper

 Joined: Oct 12, 2004 Posts: 27 Location: India
|
Posted: Wed Feb 16, 2005 3:54 pm Post subject: |
|
|
Hi
I tried to search the net to see if there is a virus like the one you described but havent found anything in particular. The only virus I read about that writes itself into music folders as a deliberate ploy is W32/Zafi.D. You can follow this link http://securityresponse.symantec.com/avcenter/venc/data/w32.erkez@mm.removal.tool.html
to get a removal tool for it. Maybe its worth a try.
Try restoring the system with system restore but you can be sure that there is a very high probability that the system restore might write back infected files. But before you do anything else, try to BACKUP all your important files.
If I was in your place, I would have backed up important files, formatted my hard disk and reinstalled winows. But that is an extreme measure.
I strongly suggest you wait till some of the other more experienced users in this forum can help you out.
Best wishes and Regards
|
|
| Back to top |
|
 |
Papoila
Trooper

 Joined: Feb 06, 2005 Posts: 17 Location: Netherlands
|
|
| Back to top |
|
 |
Prince_Serendip
Site Moderator
 Joined: Sep 07, 2002 Posts: 17542
|
Posted: Thu Feb 17, 2005 5:18 pm Post subject: |
|
|
Nice work satishincbs. We appreciate it.
Glad Papoila got the help needed. Now that the problem is solved this thread is closed.
Best regards
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|