CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

not that simple

 
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
benaround3

Sergeant
Sergeant
Premium Member

Joined: Jun 14, 2004
Posts: 99

Premium Team F@H

PostPosted: Mon Mar 07, 2005 2:45 pm    Post subject: not that simple
Reply with quote

Hiya Rockford
Things are going from bad to worse
Haven't done the on line scan yet
Since last night antivir has started to detect a whole myriad of trojans, in all different locations. As soon as I close a warning box another new one comes up in front before I can write down the name of the one underneath!
The point is that the scan froze before it finished. I will have another go but before I do please advise whether I should close Antivir before I do the scan, as during the scan AntiVir keeps popping up the warning boxes and asking whether I should delete, move, quarantine, allow etc. I supposedly had the control programme closed during this scan, but the boxes came up anyway. The other thing is, when the warnings come up, during the scan, which options should I take, move, delete, quarantine, allow? etc.
Finally when this whole thing is over, what should I do about the fact that AntiVir hasn't provided a solution to the Trojan problen?
Best Wishes
Benliner

Back to top
View users profile Send private message Send email
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Mon Mar 07, 2005 5:49 pm    Post subject:
Reply with quote

Howdy,

During the online scan deactivate the active Guard and let the online scan autoclean. After that we will continue with the rest.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
benaround3

Sergeant
Sergeant
Premium Member

Joined: Jun 14, 2004
Posts: 99

Premium Team F@H

PostPosted: Mon Mar 07, 2005 6:14 pm    Post subject:
Reply with quote

hiya
Had 2 more goes at scanning today but it froze, 2nd time was after it scanned all the C:/ files, scanning something else called wialog It stopped there, and all I did was hit the start button and close it again, (By mistake) and the browser screen went white and stayed like that for an hour. Will have another go tomorrow and won't touch anything and find out a bit more about the page it stops at. Time to go to work now, will keep posted. Thanks for your help
Benaround

Back to top
View users profile Send private message Send email
Tosal

Cadet
Cadet


Joined: Feb 03, 2005
Posts: 9
Location: Germany

PostPosted: Mon Mar 14, 2005 11:57 am    Post subject:
Reply with quote

Hi Benaround!
Could you please check if you have a file "HTPATCH.EXE" in your WINDOWS directory. If yes, please rename this to e.g. HTPATCH.ORG and retry. We have reports that this tool (it's part of a SiS chipset driver) somehow freezes AntiVir. Unfortunately we can not reproduce this so far.


_________________
Thomas Salomon
H+BEDV Datentechnik GmbH
Back to top
View users profile Send private message
benaround3

Sergeant
Sergeant
Premium Member

Joined: Jun 14, 2004
Posts: 99

Premium Team F@H

PostPosted: Thu Mar 17, 2005 3:11 am    Post subject: Couldn't find HTPatch
Reply with quote

Hello Tosal
I couldn't find this file, but I hope I was looking in the right place, do you mean in My Computer>Hard drive>windows? It wasn't there, and to make sure I did a search for HTPATCH and found nothing. But anyway, I haven't had a problem with AntiVir freezing at any time, the problem is that it keeps detecting the trojans, and when I click on delete, they get detected again immediately after. Now since I ran several of the spyware and cleanup programs, as recommended, the problem has gradually eased off, I'm not getting so many detections, the problem seems to be clearing up as mysteriously as it started, but I am still unable to run housecall on line scan. I still have some unwanted startup routines as well but I'll sort them out in time, I also have to work out why Ad Aware freezes on me.
Waiting for result of my Hijack this scan as well.

Back to top
View users profile Send private message Send email
Tosal

Cadet
Cadet


Joined: Feb 03, 2005
Posts: 9
Location: Germany

PostPosted: Mon Mar 21, 2005 9:05 am    Post subject:
Reply with quote

Hi benaround!
Probably you've got a trojan or backdoor which hooks the system by a so called Winsock Layered Service Provider (LSP).
Download LSPFIX from this site: http://www.aboutlyrics.com/Software/Download/LSPFix.php
in the Internet and start it. If it displays a Dll at the right side of it's pane this could be the cause of your problems.
First, make sure you have a backup of all you data (!!!) and then allow the program to fix it.

Another possibilitiy is a so called Browser Helper Object. This guys hook your IE or Windows Explorer so it's difficult to get rid of them. Again: make sure you have a backup of all you data before you do anything!

Run Regedit and check the following keys:
1.
HKLM\SOftware\Microsoft\Internet Explorer\Extensions.
You should see a number of subkeys and on the right pane the name of this stuff. On my computer I have 2:
"Sun Java Console" and "Windows Messenger". Both are ok. If another one look suspicious remove the complete subkey, e.g. something like: {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
2.
HKLM\Software\Microsoft\Windows\Current Version\Explorer\Browser Helper Objects\
You'll see again a number of sub keys like {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}. Now search for each item in the following key:
HKCR\CLSID
If you've found one, check the default value of it's subkey InProcServer32. It point to a Dll. If this Dll is not origin MS or unknown, you should delete the key in Browser Helper Objects.
After this you should restart the system.
Hope this helps.

And as my personal opinion: do NOT use MS Internet Explorer when exploring the Internet. Use e.g. Opera, Mozilla or Firefox. But avoid IE!


_________________
Thomas Salomon
H+BEDV Datentechnik GmbH
Back to top
View users profile Send private message
mrrockford

News Admin
News Admin
AVPE Host
AVPE Host

Joined: Apr 24, 2004
Posts: 3010

Forums Admin MVP Premium Team F@H

PostPosted: Mon Mar 21, 2005 9:44 am    Post subject:
Reply with quote

@Tosal,

An HJT log is being looked at, along with other scan results.

@benaround,

wait to do/remove anything until littleeagle tells you what to do for now.


_________________
"Anyone who considers protocol unimportant has never dealt with a cat."

L. Long
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer