CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

AntiVir found viruses and cannot delete them
Goto page 1, 2  Next
 
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
DemonSummonerZ

Trooper
Trooper


Joined: Oct 24, 2004
Posts: 17
Location: USA

PostPosted: Fri Jul 22, 2005 6:56 pm    Post subject: AntiVir found viruses and cannot delete them
Reply with quote

So my boyfriends computer was having problems and I downloaded this program onto it to help. It located several viruses or malware, or something... I saved the report, I will post it once I can get to it.

--------

Edit:I have now attached the report.

....Why isn't the attachment showing? I made it a txt file




AntiVir.txt
 Description:
AntiVir Report

Download
 Filename:  AntiVir.txt
 Filesize:  16.24 KB
 Downloaded:  18 Time(s)

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Fri Jul 22, 2005 7:45 pm    Post subject:
Reply with quote

Hi DemonSummonerZ,

Your attachment has loaded just fine.

I'll get back to you as soon as I've had a chance to read it!

Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Fri Jul 22, 2005 8:54 pm    Post subject:
Reply with quote

Wow - that's quite a collection of nasties you've picked up there!

I suggest you do the following:-

1) To start with you should disable system restore, as per here:- http://www.bleepingcomputer.com/forums/tutorial56.html

2) Then clear out all your temp files, and the easy way to do that is by downloading CCleaner from here:- http://www.ccleaner.com/
Before running CCleaner you should configure it by clicking 'Options'/'Advanced' and unticking the box 'Only delete files in Windows Temp folders older than 48 hours'.

3) Finally you should go into Safe Mode; see here:- http://www.bleepingcomputer.com/forums/tutorial61.html

and do a full system scan with your AV (which you should update beforehand to ensure you are using the latest definitions).

For this scan it would be better to configure AntiVir to search 'All files' (rather than just 'Program and macro files'). You do this by clicking 'Scan Settings'/'Search' and selecting 'All files'. Also ensure that it is set to search 'Archives'.

Allow AntiVir to delete what it finds.

Since you've got a lot of spyware related malware, I also suggest you D/L a trial version of Ewido from here:- http://www.ewido.net/en/download/
You should confgure it by clicking 'Scanner'/'Settings' and tick all the boxes, then go into 'safe mode' to do a complete system scan. After the scan a button will appear for you to save a scan report - you should click that, so you can post the results.

You should also D/L AdAware SE Personal Edition from here:- CastleCops Link/downloads-cat-14.html
Again do a full system scan in 'safe mode'.

You should make sure you update the definition file of both Ewido and AdAware before scanning with them.

After you've done all that, I would advise doing an online scan at one of the following sites:-

http://www.kaspersky.com/service?chapter=161739400

http://www.bitdefender.com/scan8/ie.html

http://housecall.trendmicro.com/

If you still find you have things you cannot shift, please post the full and exact filepath together with the precise name of the malware given by the scanner that finds it.

Back to top
View users profile Send private message
bpm3k

Sergeant
Sergeant


Joined: Mar 07, 2005
Posts: 79
Location: USA

PostPosted: Fri Jul 22, 2005 8:56 pm    Post subject:
Reply with quote

TopperID wrote:
Hi DemonSummonerZ,

Your attachment has loaded just fine.

I'll get back to you as soon as I've had a chance to read it!


I do not see an attachment either.

Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Fri Jul 22, 2005 9:00 pm    Post subject:
Reply with quote

Hi bpm3k,

Are your browser settings on medium?

Allowing Java?

Back to top
View users profile Send private message
bpm3k

Sergeant
Sergeant


Joined: Mar 07, 2005
Posts: 79
Location: USA

PostPosted: Sat Jul 23, 2005 10:29 pm    Post subject:
Reply with quote

TopperID wrote:
Hi bpm3k,

Are your browser settings on medium?

Allowing Java?


Internet zone is set to medium.
I do not have java installed.

Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Sat Jul 23, 2005 11:06 pm    Post subject:
Reply with quote

Quote:
Internet zone is set to medium.
I do not have java installed.

This is clearly one of life's mysteries. Laughing

I can only say that with cookies enabled, I can see the attachment; but with cookies disabled I cannot. Rolling Eyes

Maybe this is the way it is meant to be - i.e. top secret for my eyes only. Wink

Back to top
View users profile Send private message
DemonSummonerZ

Trooper
Trooper


Joined: Oct 24, 2004
Posts: 17
Location: USA

PostPosted: Mon Jul 25, 2005 5:18 pm    Post subject:
Reply with quote

Where do I find this "disable system restore" thing......

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
mav1976

Sergeant
Sergeant


Joined: May 22, 2005
Posts: 116


PostPosted: Mon Jul 25, 2005 5:24 pm    Post subject:
Reply with quote

Hmm... I also don't see the attachment. I'm browsing with Opera and MSIE + java and don't see the attachment. Silly. W00T


_________________
gruß mav
Back to top
View users profile Send private message
DemonSummonerZ

Trooper
Trooper


Joined: Oct 24, 2004
Posts: 17
Location: USA

PostPosted: Mon Jul 25, 2005 5:30 pm    Post subject:
Reply with quote

mav1976 wrote:
Hmm... I also don't see the attachment. I'm browsing with Opera and MSIE + java and don't see the attachment. Silly. W00T


That doesn't matter :: falls over ::

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
DemonSummonerZ

Trooper
Trooper


Joined: Oct 24, 2004
Posts: 17
Location: USA

PostPosted: Mon Jul 25, 2005 5:31 pm    Post subject:
Reply with quote

That bleeping computer site won't keep me logged in, why?

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Mon Jul 25, 2005 5:58 pm    Post subject:
Reply with quote

I'm sorry you can't get to the link I gave - for me it works O.K.; try this link instead:- http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam

If you can't get to that site either, will you please check the contents of your Hosts file by navigating to c:\windows\system32\drivers\etc\hosts
(that is for XP Home). You would have to open this in Notepad to read it. If you have never altered it before, it should just comprise of a preamble (with # signs in front of each line) followed by:-

127.0.01 Localhost

If you have a list of items following this entry please let me know.

Can you get to the Bleeping Computer tutorial on booting into 'safe mode'? If not try this:- http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam

It is essential you do your cleaning in safe mode, or else the procedure will not work.

Back to top
View users profile Send private message
DemonSummonerZ

Trooper
Trooper


Joined: Oct 24, 2004
Posts: 17
Location: USA

PostPosted: Tue Jul 26, 2005 6:06 pm    Post subject:
Reply with quote

okay so i scanned antivir in safe mode and saved the report, i couldn't scan with edwido because it took forever to download and stopped, this computer is on a 56k sadly enough.

I went to bitdefender and saved that report, it said it couldn't disinfect but it deleted the file




Bitdefender.txt
 Description:

Download
 Filename:  Bitdefender.txt
 Filesize:  441 Bytes
 Downloaded:  13 Time(s)


antivir2.txt
 Description:

Download
 Filename:  antivir2.txt
 Filesize:  5.47 KB
 Downloaded:  15 Time(s)

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Tue Jul 26, 2005 6:51 pm    Post subject:
Reply with quote

You only disinfect important files that have some 'bad' code inserted into them; that means cleaning out the bad bits while leaving the rest. But you never disinfect pure malware files, they should be deleted - so what BitDefender did is the right thing to do.

Unfortunately you have not included the relevant portion of the BitDefender report, so it is not apparent whether it deleted the 5 bugs it found - so I will take your word for it that they are now all gone!

Nor have you included the correct AntiVir log - what I need to see is the log with all the details of the files scanned together with the statistics at the end; exactly the same as the fisrt log you posted. So, please will you check through the AVWIN#.logs in the location C:\Program Files\AVPersonal\Logfiles to find the correct one. I'd better warn you that these logs quickly become overwritten, so if it is lost you would have to scan again to produce another one.

At the moment I simply do not know exactly how well the cleaning process has gone; though judging from the BitDefender report things are much better than they were!

Back to top
View users profile Send private message
DemonSummonerZ

Trooper
Trooper


Joined: Oct 24, 2004
Posts: 17
Location: USA

PostPosted: Wed Jul 27, 2005 3:45 pm    Post subject:
Reply with quote

okay I think I found it, at the end of the scan it said there were a certain amount of warning messages and /1/ detection, so this report looks correct.




AVWIN01.txt
 Description:

Download
 Filename:  AVWIN01.txt
 Filesize:  12.24 KB
 Downloaded:  14 Time(s)

Back to top
View users profile Send private message AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Goto page 1, 2  Next
Page 1 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer