Re: Opinions sought re virus ?




"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:ulvTNJqJHHA.4928@xxxxxxxxxxxxxxxxxxxxxxx
| From: "TaurArian [MS-MVP]" <taurarianREMOVECAPS@xxxxxxxxx>
|
|| Dave
||
|| I had a quick look at the start up log - and nothing in there. Will examine the
|| add/remove section next time, and then I'll look for spyware/malware.
|| Unfortunately due to the time of year, time is severely limited.
||
|| Just thought I would give an update.
||
|| The computer is usable - so it's not urgent although the owners have not reported
any
|| more flashes across the screen since I cleared the TIF etc.
||
|| It's a possibility it could be a hardware problem locking up the computer. Once I
|| eliminate the obvious, it can go back to the dealer in the New Year as it's under
|| warranty - it's less than 3 months old.
||
|| When the computer was locking up, they were manually turning off - ran chkdsk
which
|| seemed to improve things a little - there were quite a few errors.
||
|| Have a Merry Christmas and a Happy New Year.
||
|| Will report back when I've had a chance to further investigate.
||
|| Kaylene
||
|
| OK Kaylene. Happy Holidays to you and I'll see 'ya on the rebound.
|
| --
| Dave
| http://www.claymania.com/removal-trojan-adware.html
| http://www.ik-cs.com/got-a-virus.htm
|


Hi Dave, update on the infected computer. I checked with Spybot and undercovered
registry entries marked under the name of "CyberDefender".
A quick google indicated there is a legitimate program named Cyber Defender. Could
not locate anything specific in add/remove.
Trend has picked up nothing about this program in its scans.

Whatever it is it's affecting internet usage (dial up). Sometimes OE fails to open,
sometimes IE cannot find provider. Shortly after this, the computer locks up.

If I remove the registry keys, OE will open but "Trend Antispam" then has a runtime
error. If I put the registry keys back, Trend is okay.
OE will fail to open again. Then perhaps after a few tries, OE eventually opens.

The disconnect when idle, only appears occasionally even though it's set to appear
when no longer needed.

Neither myself or the owner downloaded "CyberDefender" from the manufacturers site.
Will investigate next week when the dealer is opened if they ever installed it.

Interesting that it's being detected as "spyware".

I don't understand it.

Kaylene


--

==================================
TaurArian [MS-MVP] 2005-2007 - Australia
==================================
http://www.dts-l.org/goodpost.htm
Need more help? http://support.microsoft.com/?scid=ph;en-us;6527
Get Safe online: http://www.getsafeonline.org/
(Links to web pages and MSKB Articles are posted for the purposes of keeping the
information current)


.



Relevant Pages

  • Re: Locating a Table object
    ... Yes Dave, I am setting it up the "correct way" as you describe below. ... this will help determine how a form opens later in the code (not ... Dim obj As AccessObject, dbs As Object ... strHoldTableName exists, but it's not working. ...
    (microsoft.public.access.formscoding)
  • Re: Not sure how to setup the following...
    ... dave made a post then I commented ... > This opens my webmail login page. ... Microsoft Windows MVP - Windows Server - Directory Services ...
    (microsoft.public.win2000.dns)
  • Re: Windows 98 files not showing in XP
    ... Network connection and I bought a serial cable for that reason. ... "Lil' Dave" wrote: ... access by file transfer using Messenger or a file transfer program. ... why one opens and not the other when both files were dwled from the ...
    (microsoft.public.windowsxp.general)
  • Re: Minimize pain from relocating an XLA function library
    ... I haven't seen Tushar's suggestion but I imagine it does pretty much as Dave ... The downside is a potential delay as each wb opens, ... vLink = Wb.LinkSources ...
    (microsoft.public.excel.programming)
  • Re: IETLBASS.dll trojan
    ... Trend is SLOW at producing Pattern Files. ... If you would like to try the McAfee Command Line Scanner, ... "Dave" wrote in message ... |> "safe" location and NAV/SAV should give you the capability of dumping any quarantine ...
    (microsoft.public.windowsxp.security_admin)