View Full Version : Help, Nos!
DesertFox
08-24-2003, 02:21 PM
I've picked up a virus that disabled my BlackICE firewall and my Norton anti-virus. I uninstalled Norton and bought E-trust per your recommendation, but the virus keeps interrupting the E-trust downloads. They get to 95% and then terminate. I've tried about 50 times and it just keeps terminating. Would it help to get the CD version?
I've emailed E-trust but they're not open on weekends.
I downloaded the Microsoft fix for the sobig virus that you recommended, and that got my Outlook working again (it was out of commission for over a month).
My system is Windows Millennium Edition. Microsoft packs 1 and 2 don't work with ME.
DoctorDoom
08-25-2003, 02:08 AM
Do you know what virus it was? There aren't all that many that will disable the firewall and the AV (W32/Blinkom-A (http://www.sophos.com/virusinfo/analyses/w32blinkoma.html) and Troj/KillAV-Q (http://www.sophos.com/virusinfo/analyses/trojkillavq.html) are a couple of them).
I've never heard of one that will kill a download of AV software at 95%.
The first vital step is to get your critical data backed up off of the hard drive. You can do it by burning a bunch of CDs, but I'd recommend spending the bucks for an external USB-connected hard drive from Staples or any well-stocked computer or office-equipment supplier. It's then a matter of moving the files and folders that you want to save to the drive. If your box doesn't have a USB 2.0 port, it runs with USB 1.1, but it's going to take quite a while if you have a shitload of data.
After the box has been sterilized you can use the virus scanner to look over your saved data.
With all your valuable files safely off the drive (by whatever means you chose), it's time to address the problem. The thing is apparently being started at bootup. Here are a couple of things to try.
Click Start > Run. In the text box, type in msconfig and click OK or hit Enter. Click on the Startup tab and look for anything that you don't recognize. Record it and post it and we can identify it as valid or naughty. Or, if it's evidently the offender, remove the checkmark from it and close the window, then reboot.
Right after bootup, use the Vulcan nerve pinch (Ctrl-Alt-Delete keys together). In that window, see what's running, and record the listings. We can identify them from standard lists. Use the End Task button to shut off everything but Explorer and Systray. They are all that's necessary for Windows to run. After that, go online and see if you can DL the files.
Wet blanket time: my son's previous puter ran Win Me. He contracted a virus (he and his brother in law took turns fetching shit from KaZaa) that even a system restore from the CDs wouldn't clear out. I finally backed up all his files to my external drive, replaced the hard drive (his was not that big anyway) and loaded it from scratch from the CDs, end of problem.
As long as your data is all safe and secure, you can use the restore CDs to reformat and reload the HD if it becomes the last-ditch option. That of course means reloading all the software, but it does thoroughly cleanse the drive. On the plus side, you start running again with a lean, mean machine that will run considerably better than it has in a while.
If you choose that option, create a start-up floppy disk. It will give you access to the CD-ROM drive if the CDs don't autoboot.
Create a Windows Me startup disk (http://www.microsoft.com/windowsME/using/computerhealth/articles/startupdisk.asp)
The restore CDs will ordinarily give the option of restoring just the system files, leaving the data and program files intact, or of formatting the drive and then reloading the system files. Your choice.
DesertFox
08-25-2003, 05:55 PM
Thanks, Doc. I'm not a geek, and so will work thru your directions a little at a time.
nosferatuscoffin
08-25-2003, 06:54 PM
Sorry, DF, I wasn't on FC or even my PC most of the weekend, so I only got your post a few minutes ago.
One thing, you say you have purchased E-Trust but that it was crapping out at 95%, so I assume you it was, at that point, never fully installed on your hard drive?
If you have not already gone ahead with backing up your data etc. I can mail you a working copy of E-Trust from here that you can DL directly from your ISP's mail server. It would of course, need to be updated to get all of the virus updates/patches. However, if you can DL it from there, it would be a lot faster then backing up everything and re-partitioning and reformatting the hard drive.
If not, go ahead and backup your data and sterilize the drive per Doc's instructions, as he covered the above very well.
DesertFox
08-25-2003, 07:15 PM
I'm willing to try it, Nos.
nosferatuscoffin
08-25-2003, 07:50 PM
Ok..I will send it over now.
DesertFox
09-07-2003, 04:37 PM
It worked! My puter's saved! Outlook works again! BlackICE is once again bugging me every 15 seconds!
nosferatuscoffin
09-07-2003, 07:20 PM
[ QUOTE ]
DesertFox said:
It worked! My puter's saved! Outlook works again! BlackICE is once again bugging me every 15 seconds!
[/ QUOTE ]
Excellent. Listen to Sir Nos, and all PC's will operate at 100%..
http://freeconservatives.com/ubbthreads/images/graemlins/laugh.gif
nosferatuscoffin
09-07-2003, 07:21 PM
One thing. Never use Outlook.
Go to Eudora (http://www.eudora.com/) and DL a real email client that is not so virus prone.
Well i think I have something buggin MY Machine because number one early this morning I have been having troubles surfing the net 'again' and today lost an entire huge post because the page wouldnt load i.e. it could not be found, then again I could not get any website up, hence in order to get some measure of normalacy I have to constantly reboot to get it to function normally.
Right afterwards just like when the blaster worm nailed me I got 20 junk spam in my mailbox, I use the Microsoft Office XP Outlook version and I turned off the preview feature in the deleted mail and the inbox part.
just checked my email box and I had to delete 9 more off of it.
still at times on and off I have troubles surfing the net, posting and pulling up pages, i did a thorough scan with my e-trust, and did a thorough scan with my Ad-aware and pulled up nothing, so I have no idea what it is thats plaguing me.
Any ideas?
Peachdiane
09-08-2003, 12:47 AM
[ QUOTE ]
Rink said:
I got 20 junk spam in my mailbox, I use the Microsoft Office XP Outlook version and I turned off the preview feature in the deleted mail and the inbox part.
just checked my email box and I had to delete 9 more off of it.
[/ QUOTE ]
Maybe try out MailWasher? (http://www.mailwasher.net)
Basically you bounce back unwanted e-mails so it looks as if your email address is not valid. Delete them before you download them. You’ll be able to see who the email is from, etc. There's so much more and I love it!
Have fun whammin' the spammers! http://freeconservatives.com/ubbthreads/images/graemlins/computer2.gif
It's not that, it seems evertime my PC gets hit with somethin and I cant websurf or whatnot, right afterwards I get a loadfulla spam.
Right now tonight I tried to get a website up and nothing, absolutely nothing would come up.
I finally got tired of it, I turned my PC off and unplugged my modem and unplugged the phone line to the wall and consequently changed my damn IP#.
Now I can websurf again.
something or someone had my IP addy and was blocking me.
Not sure if it was a hidden worm or virus because I did a thorough scan usint E-trust and didnt find anything, also did a scan using my Ad-aware, cleaned everything out from that as well.
tacitus
09-08-2003, 06:04 AM
Diane Mailwasher is great. I like the feature of adding entire domains to the Blacklist and Deleting blacklisted emails before they eve show up on the list. Great program.
I may bother with that mailwasher for my hotmail and my private mailbox
thanks
well sorry but I think I'm going to have to get damn drastic in order to get this problem of my inability to websurf stopped, I called my ISP and they told me to remove my antivirus, hence I removed etrust from my pc
I keep getting this thing popping up on my comp everytime I boot my pc up and I have been trying to find out what it is and how to get it to stop popping up all the time, i click no once and it popps back up and I have to click no again to get rid of it.
I once clicked yes and it wanted to start an RPC client.
heres a pic of the irritating thing that I just have no idea what it is, where its from or whatnot, if anyone can identify this PLEASE let me know ok?
http://w3.gorge.net/rink/script%20editor.JPG
well i think i finally figured out this pesky websurfing problem... (I hope!)
just need to know what that weirdo debugging thing is.
nosferatuscoffin
09-09-2003, 09:21 PM
Well, looks like you got reinfected with the Blaster virus. What you described was a flood of ip calls via you TCP/IP driver.
Did you make sure you had all of the latest MS updates, the latest E-Trust updates and were you running any sort of firewall? Did you get the router up? If not, at least run ZoneAlarm for now.
Blaster is casued by a simple security hole in XP, not by a virus or even a piece of spyware.
Sorry I have been gone the past 2 nights, other things must take priority. http://freeconservatives.com/ubbthreads/images/graemlins/sad.gif
Let me know. Email or here.
My ISP told me to remove my antivirus, hence i did so reluctantly.
Not happy bout that, not sure if I do or dont have all the updates or not http://freeconservatives.com/ubbthreads/images/graemlins/sad.gif
Dont have the router up yet, not overly sure how to go bout getting it set up, not sure if i have to have the router plugged all in then put in the cdrom or the cdrom first then plugin the router :/
nosferatuscoffin
09-09-2003, 09:50 PM
Did we not go over this last month? http://freeconservatives.com/ubbthreads/images/graemlins/laugh.gif
As for E-Trust, please put it back on. Your ISP techs are morons. And since you do not, at the moment, have a firewall, go toZoneAlarm (http://www.zonelabs.com/store/content/catalog/products/sku_list_za.jsp?lid=nav_za) and DL the personal version. That is a lot better than having no firewall whatsoever. Without any firewall, and with updates in question, you are asking to get re-infected.
We will go over the router install again this weekend, if you like.
I'd like that, thanks Nos
Just hope this zone alarm dont interfere with my gaming, last time i tried zone alarm it was a pure pain in the butt.
is it the Free ZoneAlarm one?
nosferatuscoffin
09-09-2003, 10:13 PM
I should not...since you are running XP.
kay hope not, getting a lotta pings tho, some from canada and some from california, not sure if its related to my netsurfing problems or not.
I went ahd hid my entire IP addy, so thats a plus.
got two IPs from those pings that dont come up with anyplace, not sure whats up with that cept proxy servers.
y'kno this is unusual, since I put in zone alarm i checked my game, and my pings are a lot better now than ever before, much lower and nicer looking.
very odd.
nosferatuscoffin
09-09-2003, 11:08 PM
Because your TCP/IP driver is not spending so much time translating those pings and is using those resources to acutally go to the game's ip.
KOOL! http://freeconservatives.com/ubbthreads/images/graemlins/icon16.gif
vBulletin® v3.7.2, Copyright ©2000-2008, Jelsoft Enterprises Ltd.