Computer Talk Discussions here pertain to mods, troubleshooting, and PC/console gaming

Did the AIM virus invade my computer?

Thread Tools
 
Search this Thread
 
Old 10-18-2005, 08:53 AM
  #1  
Registered User
Thread Starter
 
Georgia4Runner's Avatar
 
Join Date: Dec 2004
Location: Potomac, MD
Posts: 254
Likes: 0
Received 0 Likes on 0 Posts
Did the AIM virus invade my computer?

I am in the dorms at Indiana University. I have a new Dell Latitude 610 with XP Home SP2. The XP Firewall is turned off, but the Virus Protection is on.

Anyways, yesterday I was logged in AOL Instant Messenger and I got a message from one of my "buddies". It was a clickable link that read "PicsDude.my-net-space.net/show.php"
YT MEMBERS: DO NOT CLICK ON THIS LINK!!!
So when I, like a moron, clicked on the link, weird stuf happened, like a download in the lower left corner of the screen. I realized what was happening and held down the power button on my laptop before it finished loading.

Symantec Anti-Virus was freaking out and Ad-Watch SE recorded blocking several tracking cookies. But when I just restarted my computer, a message from "Freeware.com"" or something like that popped up, and two XP error messages popped up. I will give more details later. Thank you and please help me!
Old 10-18-2005, 08:58 AM
  #2  
Contributing Member
 
4-RUNNIN' FREAK's Avatar
 
Join Date: Jun 2004
Location: NNJ
Posts: 3,950
Likes: 0
Received 0 Likes on 0 Posts
Scan with this... see what happens. It's free.http://www.pandasoftware.com/actives...an/ascan_1.asp
Old 10-18-2005, 09:55 AM
  #3  
Registered User
Thread Starter
 
Georgia4Runner's Avatar
 
Join Date: Dec 2004
Location: Potomac, MD
Posts: 254
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by 4-RUNNIN' FREAK
Scan with this... see what happens. It's free.http://www.pandasoftware.com/actives...an/ascan_1.asp
Thanks for the link, but it wants me to remove my Symantec Anti-Virus before the Panda software could be installed. Incompatability, I guess? Anyways, I called the Indiana University Tech Office and a rep told me to do the Trend Micro free virus scan.

He told me that Lavasoft finds some malicious stuff, but also has the potential to delete some important, non-malicous stuff as well.

My Lavasoft Ad-Watch SE has just posted 2211 instances of "Registry Modification Detected", each modification within seconds of the next.

What do I do? I can reinstall XP, but its a PITA and I have a bunch of programs that I'm not sure how to back up. Not to mention that I have already had to reinstall XP once since I got the Laptop two months ago.

Thanks all, especially 4Runnin Freak!
Old 10-18-2005, 10:00 AM
  #4  
Banned
 
Localmotion's Avatar
 
Join Date: Mar 2004
Posts: 0
Likes: 0
Received 0 Likes on 0 Posts
try to find the virus name, type it in to google, and you will see a way to "kill" the virus via microsoft.
Old 10-18-2005, 10:24 AM
  #5  
Registered User
Thread Starter
 
Georgia4Runner's Avatar
 
Join Date: Dec 2004
Location: Potomac, MD
Posts: 254
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by Localmotion
try to find the virus name, type it in to google, and you will see a way to "kill" the virus via microsoft.
Thats a great idea! My problem doing that is I have no clue of what the virus name is. Currently Windows is in Safe Mode, so I went to www.trendmicro.com and did the free virus check. It scanned my C drive and found no viruses or trojans. What do I do now? Thanks for the replys!
Old 10-18-2005, 10:36 AM
  #6  
Contributing Member
 
4-RUNNIN' FREAK's Avatar
 
Join Date: Jun 2004
Location: NNJ
Posts: 3,950
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by Georgia4Runner
Thanks for the link, but it wants me to remove my Symantec Anti-Virus before the Panda software could be installed. Incompatability, I guess? Anyways, I called the Indiana University Tech Office and a rep told me to do the Trend Micro free virus scan.

Sorry, forgot about that it asks you there. I know you have to get rid of Nortons if you buy it.

Between Panda and AOL spyware, I have over 230 unique instances blocked on my PC since I had it for about a month now.

Never knew there was so much crap on the net.
Old 10-18-2005, 11:12 AM
  #7  
Registered User
Thread Starter
 
Georgia4Runner's Avatar
 
Join Date: Dec 2004
Location: Potomac, MD
Posts: 254
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by 4-RUNNIN' FREAK
Sorry, forgot about that it asks you there. I know you have to get rid of Nortons if you buy it.

Between Panda and AOL spyware, I have over 230 unique instances blocked on my PC since I had it for about a month now.

Never knew there was so much crap on the net.
Thats crazy! I'm sure I have you beat with some of the sites I go to, lol...

Here is what I see restarting my computer. Symantec AntiVirus shows 2 instances:
THE FIRST:
Scan type: Auto-Protect Scan
Event: Threat Found!
Threat: Hacktool.Rootkit
File: C:\Documents and Settings\Denton Gupton\msdirectx.sys
Location: Quarantine
Computer: DENTONSLAPTOP
User: Denton Gupton
Action taken: Quarantine succeeded : Access denied
Date found: Tuesday, October 18, 2005 2:08:45 PM

THE SECOND:
Scan type: Auto-Protect Scan
Event: Threat Found!
Threat: Trojan Horse
File: C:\xz.bat
Location: Quarantine
Computer: DENTONSLAPTOP
User: Denton Gupton
Action taken: Quarantine succeeded : Access denied
Date found: Tuesday, October 18, 2005 2:08:47 PM

So does this notification show what the virus name is? What actions do I need to take now? Thank you so much!

Last edited by Georgia4Runner; 10-18-2005 at 11:13 AM.
Old 10-18-2005, 11:16 AM
  #8  
Registered User
 
Churnd's Avatar
 
Join Date: Jan 2003
Location: Hattiesburg, MS
Posts: 4,087
Likes: 0
Received 1 Like on 1 Post
Threat: Hacktool.Rootkit
File: C:\Documents and Settings\Denton Gupton\msdirectx.sys
Those two lines tell you the virus name and where the file it's infecting is located.

But according to Symantec, it's been quarantined, so you're ok.
Old 10-18-2005, 11:19 AM
  #9  
Registered User
Thread Starter
 
Georgia4Runner's Avatar
 
Join Date: Dec 2004
Location: Potomac, MD
Posts: 254
Likes: 0
Received 0 Likes on 0 Posts
YES! Thanks Churnd, excellent news! I was hoping I wouldn't have to reinstall XP for the second time in a month!

Thanks for the help everyone!
Old 10-18-2005, 11:23 AM
  #10  
Registered User
 
Churnd's Avatar
 
Join Date: Jan 2003
Location: Hattiesburg, MS
Posts: 4,087
Likes: 0
Received 1 Like on 1 Post
It's still a good idea to take extra precautions. Check out my PC HOWTO sticky for some ideas.
Old 10-18-2005, 06:53 PM
  #11  
Registered User
 
green91runner's Avatar
 
Join Date: Feb 2005
Location: thunder bay, ontario
Posts: 895
Likes: 0
Received 0 Likes on 0 Posts
What I would do if I were you, go into safe mode, navigate to those folder and delete those 2 files. (safe mode just ensures nothing is running in the background) They aren't system files, so you're free to destroy em. Also, because of the tracking cookies and freeware pop-ups, I would follow some of the spyware removal and computer cleaning steps in pc tips, to ensure no nasty surprises are left behind, which could leave the door open for another virus.
Old 10-18-2005, 07:08 PM
  #12  
Contributing Member
 
doink's Avatar
 
Join Date: Jul 2002
Location: Atl. Georgia
Posts: 3,112
Likes: 0
Received 0 Likes on 0 Posts
that was going around here too i think.

my friend used this i think...http://jayloden.com/VirusClean.htm
Old 10-22-2005, 11:43 AM
  #13  
Contributing Member
 
DH6twinotter's Avatar
 
Join Date: Oct 2002
Location: Charlotte, North Carolina
Posts: 1,661
Likes: 0
Received 0 Likes on 0 Posts
Same thing happened to me. One of my Roommates downloaded AOL (not AIM), and the next morning I had a bunch of Ad-aware threats and a few Trojans. 91 total and I was only able to delete like 19 I think.

I tried the Panda site again, but nothing happens when I click on the HUGE green button. :cry:
Old 10-22-2005, 11:49 AM
  #14  
Contributing Member
 
DH6twinotter's Avatar
 
Join Date: Oct 2002
Location: Charlotte, North Carolina
Posts: 1,661
Likes: 0
Received 0 Likes on 0 Posts
Oh, my Window's Media Player won't work either
Old 10-22-2005, 12:09 PM
  #15  
Banned
 
jimbo74's Avatar
 
Join Date: Jan 2004
Location: Nor*Cal
Posts: 6,590
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by 4-RUNNIN' FREAK
Never knew there was so much crap on the net.

this comment isnt actually directed at you but for all....

there is a lot of crap on the net, even sites liek htis that you wnat to see there are peopel that post crap all the time.....


sure a lot of you here don't like me or care what i have to say... please read the line in my signature...... thank you and have a nice day......
Old 10-22-2005, 01:20 PM
  #16  
Contributing Member
 
dwh91102's Avatar
 
Join Date: Nov 2004
Location: Aurora, Indiana
Posts: 1,285
Likes: 0
Received 0 Likes on 0 Posts
I run spybot search & destory, adaware se, and microsoft antispyware. They will all find something the other doesn't. As for antivirus I run AVG, and if I was you I'd keep that firewall on........
And for someone else lighten up a bit Mr Postmaster general.
Old 10-22-2005, 06:29 PM
  #17  
Contributing Member
 
TDiddy's Avatar
 
Join Date: Sep 2002
Location: Urbandale, IA
Posts: 7,112
Likes: 0
Received 0 Likes on 0 Posts
Originally Posted by jimabena74
there is a lot of crap on the net, even sites liek htis that you wnat to see there are peopel that post crap all the time.....


Have another
Old 10-22-2005, 06:36 PM
  #18  
Contributing Member
 
DH6twinotter's Avatar
 
Join Date: Oct 2002
Location: Charlotte, North Carolina
Posts: 1,661
Likes: 0
Received 0 Likes on 0 Posts
I'm getting a pup (what's a pup?) called Adware-POP, Adware Qoolaid, and Adware-surfsidekick.dll. Also getting Adclicker-BA.dll, Adware Casclient.dr, and Downloader-DC Trojans.

Any ideas/suggestions? I think this is from my roommate downloading AOL on it, but not sure.

Thanks.
Daniel
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
kawazx636
The Classifieds GraveYard
34
10-06-2021 03:03 PM
some drunk guy
86-95 Trucks & 4Runners
23
08-03-2021 06:09 PM
dbollier123
Pre 84 Trucks
8
09-29-2015 05:23 PM



Quick Reply: Did the AIM virus invade my computer?



All times are GMT -8. The time now is 11:22 PM.