Re: Probable virus of some sort...

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 04/23/05


Date: Sat, 23 Apr 2005 09:17:44 -0400

From: "Derek D..." <Derek D...@discussions.microsoft.com>

| Hi there,
| I am certain I have a virus of some nature and hoping for some guidance...
|
| The Symptoms:
| After booting up and desktop appears, everything appears to be fine for a
| minute or so, but then everything slows right down i.e. opening folders takes
| some time, some programs will not open at all. Appears as though the desktop
| is stalling. Too may actions causes 'not responding' in the window header.
|
| Cures attempted:
| 1) I tried running a virus scan with my current trial version of PCcillin
| 2005. It took a few minutes to get going, got halfway and stalled!
|
| 2) I tried doing a system restore. It got almost to the end and stalled!
|
| What next?
| I have been researching some of the previous threads here that appear to be
| somehwat related and it seems as though downloading the sysclean package from
| Trend Micro appears to be a good start and that is where I'm at... Ive got it
| running now (it's taking forever!!!) in safe mode, but I wasn't sure whether
| or not I needed to turn off the system restore...if that is even possible (I
| seem to recall reading a thread making some suggestion to do so)...
|
| Can somebody impart their expert knowledge and/or opinion as to what to do
| or try next?
|
| Thanks,
| Derek! :)
| (thank goodness I have a laptop, otherwise i'd really be stuffed!!!)

Dump the contents of the IE Temporary Internet Folder cache (TIF)
Start --> Settings --> Control Panel --> Internet Options --> Delete Files

Dump the contents of the Mozilla FireFox Cache
Tools --> Options --> Privacy --> Cache --> Clear

1) Download TrendMicro Sysclean by one of the following 2 methods

Trend Sysclean Method 1
---------------------------------------
Trend Sysclean Package
http://www.trendmicro.com/download/dcs.asp

Latest Trend signature files.
http://www.trendmicro.com/download/pattern.asp

Create a directory.
On drive "C:\"
(e.g., "c:\sysclean")

Download SYSCLEAN.COM and place it in that directory.
Download the signature files (pattern files) by obtaining the ZIP file.
For example; lpt596.zip

Extract the contents of the ZIP file and place the contents in the same directory as
SYSCLEAN.COM.

Trend Sysclean Method 2
---------------------------------------
Download the utility SYSCLEAN_FE at the following URL --
http://www.ik-cs.com/got-a-virus.htm
SYSCLEAN_FE automates the download and execution process of the Trend Sysclean Package.
Direct URL --
http://www.ik-cs.com/programs/virtools/Sysclean_FE.exe

2) Download and install Ad-aware SE (free personal version v1.05)
         http://www.lavasoftusa.com/
3) Update Adaware with the latest definitions then exit the software.
4) Disable System Restore
        http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm
5) Reboot your PC into Safe Mode and shutdown as many applications as possible
6) Using the Trend Sysclean and Ad-aware SE utilities, perform a Full Scan of your
        platform and clean/delete any infectors found
7) Restart your PC and perform a "final" Full Scan of your platform using both Trend
        Sysclean and Ad-aware SE
8) Re-enable System Restore and re-apply any System Restore preferences,
        (e.g. HD space to use suggested 400 ~ 600MB),
9) Reboot your PC.
10) Create a new Restore point

* * * Please report back your results * * *

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: Is anyone experience like this? How did you removed this threat?
    ... | i'm not sure if these is the right place to post virus problems, ... | infected by backdoor these time on volume C. system restore. ... FireWall to allow it to download the needed AV vendor related files. ... This will bring up the initial menu of choices and should be executed in Normal Mode. ...
    (microsoft.public.windowsxp.general)
  • Re: Virus or?
    ... Trend Sysclean Method 1 ... Download SYSCLEAN.COM and place it in that directory. ... Restart your PC and perform a "final" Full Scan of your platform using both the ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: Antivirus & spy remover software
    ... | software, that can be able to protect my pc from known virus., i am using ... Trend Sysclean Method 1 ... Download SYSCLEAN.COM and place it in that directory. ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: Trojan DyFuCA problems
    ... | I have Trojan DyFuCA and no antitrojan remove it. ... Trend Sysclean Method 1 ... Download SYSCLEAN.COM and place it in that directory. ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.general)
  • Re: Trojan Infection
    ... Trend Sysclean Method 1 ... Download SYSCLEAN.COM and place it in that directory. ... Re-enable System Restore and re-apply any System Restore preferences, ...
    (microsoft.public.windowsxp.security_admin)