Computer Talk Discussions here pertain to mods, troubleshooting, and PC/console gaming

Did the AIM virus invade my computer?

Thread Tools
 
Search this Thread
 
Old Oct 18, 2005 | 08:53 AM
  #1  
Georgia4Runner's Avatar
Thread Starter
Registered User
 
Joined: Dec 2004
Posts: 254
Likes: 0
From: Potomac, MD
Did the AIM virus invade my computer?

I am in the dorms at Indiana University. I have a new Dell Latitude 610 with XP Home SP2. The XP Firewall is turned off, but the Virus Protection is on.

Anyways, yesterday I was logged in AOL Instant Messenger and I got a message from one of my "buddies". It was a clickable link that read "PicsDude.my-net-space.net/show.php"
YT MEMBERS: DO NOT CLICK ON THIS LINK!!!
So when I, like a moron, clicked on the link, weird stuf happened, like a download in the lower left corner of the screen. I realized what was happening and held down the power button on my laptop before it finished loading.

Symantec Anti-Virus was freaking out and Ad-Watch SE recorded blocking several tracking cookies. But when I just restarted my computer, a message from "Freeware.com"" or something like that popped up, and two XP error messages popped up. I will give more details later. Thank you and please help me!
Reply
Old Oct 18, 2005 | 08:58 AM
  #2  
4-RUNNIN' FREAK's Avatar
Contributing Member
 
Joined: Jun 2004
Posts: 3,950
Likes: 0
From: NNJ
Scan with this... see what happens. It's free.http://www.pandasoftware.com/actives...an/ascan_1.asp
Reply
Old Oct 18, 2005 | 09:55 AM
  #3  
Georgia4Runner's Avatar
Thread Starter
Registered User
 
Joined: Dec 2004
Posts: 254
Likes: 0
From: Potomac, MD
Originally Posted by 4-RUNNIN' FREAK
Scan with this... see what happens. It's free.http://www.pandasoftware.com/actives...an/ascan_1.asp
Thanks for the link, but it wants me to remove my Symantec Anti-Virus before the Panda software could be installed. Incompatability, I guess? Anyways, I called the Indiana University Tech Office and a rep told me to do the Trend Micro free virus scan.

He told me that Lavasoft finds some malicious stuff, but also has the potential to delete some important, non-malicous stuff as well.

My Lavasoft Ad-Watch SE has just posted 2211 instances of "Registry Modification Detected", each modification within seconds of the next.

What do I do? I can reinstall XP, but its a PITA and I have a bunch of programs that I'm not sure how to back up. Not to mention that I have already had to reinstall XP once since I got the Laptop two months ago.

Thanks all, especially 4Runnin Freak!
Reply
Old Oct 18, 2005 | 10:00 AM
  #4  
Localmotion's Avatar
Banned
 
Joined: Mar 2004
Posts: 0
Likes: 0
try to find the virus name, type it in to google, and you will see a way to "kill" the virus via microsoft.
Reply
Old Oct 18, 2005 | 10:24 AM
  #5  
Georgia4Runner's Avatar
Thread Starter
Registered User
 
Joined: Dec 2004
Posts: 254
Likes: 0
From: Potomac, MD
Originally Posted by Localmotion
try to find the virus name, type it in to google, and you will see a way to "kill" the virus via microsoft.
Thats a great idea! My problem doing that is I have no clue of what the virus name is. Currently Windows is in Safe Mode, so I went to www.trendmicro.com and did the free virus check. It scanned my C drive and found no viruses or trojans. What do I do now? Thanks for the replys!
Reply
Old Oct 18, 2005 | 10:36 AM
  #6  
4-RUNNIN' FREAK's Avatar
Contributing Member
 
Joined: Jun 2004
Posts: 3,950
Likes: 0
From: NNJ
Originally Posted by Georgia4Runner
Thanks for the link, but it wants me to remove my Symantec Anti-Virus before the Panda software could be installed. Incompatability, I guess? Anyways, I called the Indiana University Tech Office and a rep told me to do the Trend Micro free virus scan.

Sorry, forgot about that it asks you there. I know you have to get rid of Nortons if you buy it.

Between Panda and AOL spyware, I have over 230 unique instances blocked on my PC since I had it for about a month now.

Never knew there was so much crap on the net.
Reply
Old Oct 18, 2005 | 11:12 AM
  #7  
Georgia4Runner's Avatar
Thread Starter
Registered User
 
Joined: Dec 2004
Posts: 254
Likes: 0
From: Potomac, MD
Originally Posted by 4-RUNNIN' FREAK
Sorry, forgot about that it asks you there. I know you have to get rid of Nortons if you buy it.

Between Panda and AOL spyware, I have over 230 unique instances blocked on my PC since I had it for about a month now.

Never knew there was so much crap on the net.
Thats crazy! I'm sure I have you beat with some of the sites I go to, lol...

Here is what I see restarting my computer. Symantec AntiVirus shows 2 instances:
THE FIRST:
Scan type: Auto-Protect Scan
Event: Threat Found!
Threat: Hacktool.Rootkit
File: C:\Documents and Settings\Denton Gupton\msdirectx.sys
Location: Quarantine
Computer: DENTONSLAPTOP
User: Denton Gupton
Action taken: Quarantine succeeded : Access denied
Date found: Tuesday, October 18, 2005 2:08:45 PM

THE SECOND:
Scan type: Auto-Protect Scan
Event: Threat Found!
Threat: Trojan Horse
File: C:\xz.bat
Location: Quarantine
Computer: DENTONSLAPTOP
User: Denton Gupton
Action taken: Quarantine succeeded : Access denied
Date found: Tuesday, October 18, 2005 2:08:47 PM

So does this notification show what the virus name is? What actions do I need to take now? Thank you so much!

Last edited by Georgia4Runner; Oct 18, 2005 at 11:13 AM.
Reply
Old Oct 18, 2005 | 11:16 AM
  #8  
Churnd's Avatar
Registered User
 
Joined: Jan 2003
Posts: 4,087
Likes: 1
From: Hattiesburg, MS
Threat: Hacktool.Rootkit
File: C:\Documents and Settings\Denton Gupton\msdirectx.sys
Those two lines tell you the virus name and where the file it's infecting is located.

But according to Symantec, it's been quarantined, so you're ok.
Reply
Old Oct 18, 2005 | 11:19 AM
  #9  
Georgia4Runner's Avatar
Thread Starter
Registered User
 
Joined: Dec 2004
Posts: 254
Likes: 0
From: Potomac, MD
YES! Thanks Churnd, excellent news! I was hoping I wouldn't have to reinstall XP for the second time in a month!

Thanks for the help everyone!
Reply
Old Oct 18, 2005 | 11:23 AM
  #10  
Churnd's Avatar
Registered User
 
Joined: Jan 2003
Posts: 4,087
Likes: 1
From: Hattiesburg, MS
It's still a good idea to take extra precautions. Check out my PC HOWTO sticky for some ideas.
Reply
Old Oct 18, 2005 | 06:53 PM
  #11  
green91runner's Avatar
Registered User
 
Joined: Feb 2005
Posts: 895
Likes: 0
From: thunder bay, ontario
What I would do if I were you, go into safe mode, navigate to those folder and delete those 2 files. (safe mode just ensures nothing is running in the background) They aren't system files, so you're free to destroy em. Also, because of the tracking cookies and freeware pop-ups, I would follow some of the spyware removal and computer cleaning steps in pc tips, to ensure no nasty surprises are left behind, which could leave the door open for another virus.
Reply
Old Oct 18, 2005 | 07:08 PM
  #12  
doink's Avatar
Contributing Member
 
Joined: Jul 2002
Posts: 3,112
Likes: 0
From: Atl. Georgia
that was going around here too i think.

my friend used this i think...http://jayloden.com/VirusClean.htm
Reply
Old Oct 22, 2005 | 11:43 AM
  #13  
DH6twinotter's Avatar
Contributing Member
 
Joined: Oct 2002
Posts: 1,661
Likes: 0
From: Charlotte, North Carolina
Same thing happened to me. One of my Roommates downloaded AOL (not AIM), and the next morning I had a bunch of Ad-aware threats and a few Trojans. 91 total and I was only able to delete like 19 I think.

I tried the Panda site again, but nothing happens when I click on the HUGE green button. :cry:
Reply
Old Oct 22, 2005 | 11:49 AM
  #14  
DH6twinotter's Avatar
Contributing Member
 
Joined: Oct 2002
Posts: 1,661
Likes: 0
From: Charlotte, North Carolina
Oh, my Window's Media Player won't work either
Reply
Old Oct 22, 2005 | 12:09 PM
  #15  
jimbo74's Avatar
Banned
 
Joined: Jan 2004
Posts: 6,590
Likes: 0
From: Nor*Cal
Originally Posted by 4-RUNNIN' FREAK
Never knew there was so much crap on the net.

this comment isnt actually directed at you but for all....

there is a lot of crap on the net, even sites liek htis that you wnat to see there are peopel that post crap all the time.....


sure a lot of you here don't like me or care what i have to say... please read the line in my signature...... thank you and have a nice day......
Reply
Old Oct 22, 2005 | 01:20 PM
  #16  
dwh91102's Avatar
Contributing Member
 
Joined: Nov 2004
Posts: 1,285
Likes: 0
From: Aurora, Indiana
I run spybot search & destory, adaware se, and microsoft antispyware. They will all find something the other doesn't. As for antivirus I run AVG, and if I was you I'd keep that firewall on........
And for someone else lighten up a bit Mr Postmaster general.
Reply
Old Oct 22, 2005 | 06:29 PM
  #17  
TDiddy's Avatar
Contributing Member
 
Joined: Sep 2002
Posts: 7,112
Likes: 0
From: Urbandale, IA
Originally Posted by jimabena74
there is a lot of crap on the net, even sites liek htis that you wnat to see there are peopel that post crap all the time.....


Have another
Reply
Old Oct 22, 2005 | 06:36 PM
  #18  
DH6twinotter's Avatar
Contributing Member
 
Joined: Oct 2002
Posts: 1,661
Likes: 0
From: Charlotte, North Carolina
I'm getting a pup (what's a pup?) called Adware-POP, Adware Qoolaid, and Adware-surfsidekick.dll. Also getting Adclicker-BA.dll, Adware Casclient.dr, and Downloader-DC Trojans.

Any ideas/suggestions? I think this is from my roommate downloading AOL on it, but not sure.

Thanks.
Daniel
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
kawazx636
The Classifieds GraveYard
34
Oct 6, 2021 03:03 PM
some drunk guy
86-95 Trucks & 4Runners
23
Aug 3, 2021 06:09 PM
dbollier123
Pre 84 Trucks
8
Sep 29, 2015 05:23 PM




All times are GMT -8. The time now is 03:26 PM.