Re: Virus Detected Cannot get rid of!



From: "Mike S" <Mike S@xxxxxxxxxxxxxxxxxxxxxxxxx>

| My free AVG virus program alerted me to a virus and said
| it healed it. But my screen shows "Warning your in
| danger" a red x on the task bar says my computer is
| infected and takes me to AV Gold Antivirus. I also get
| a ! in a triangle that says my ISP might be tracking my
| private info.
|
| I have turned off restore, run Adaware, Spybot and AVG
| after undating.
|
| AVG shows two viruses Trojan Horses Puper.C and Puper.D
| but says it heals them.
|
| An online Symantec virus detection says I have
| Download.Trojan and SecurityRisk.Oleadm and the
| Trojan.Prova. It also says I have some adware problems
| but a search cannot find those files.
|
| Any suggestions?

There are anti virus News Groups specifically for this type of discussion.

microsoft.public.scripting.virus.discussion
microsoft.public.security.virus
alt.comp.virus
alt.comp.anti-virus

You failed to state the versions of the software.

Currently, the sofware you listed are...

AVG v7.xxx
SpyBot S&D v1.4
Ad-Aware SE v1.06

So if you used Adaware6, SpyBot S&D v1.2 or AVG v6 then they need to be replaced with their
newer couterparts and updated.

Please perform the following....

Dump the contents of the IE Temporary Internet Folder cache (TIF)
Start --> Settings --> Control Panel --> Internet Options --> Delete Files

Dump the contents of the Mozilla FireFox Cache { if you use FireFox }
Tools --> Options --> Privacy --> Cache --> Clear


Download CLEAN.EXE from the URL --
http://www.ik-cs.com/programs/virtools/clean.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter
{ http://kixtart.org Kixtart is CareWare } three batch files, two Kixtart scripts, two Link
(.lnk) files and a PDF instruction file.

GETFILES.BAT -- For downloading (FTP) the files needed to run the McAfee Command Line
Scanner. You may have to disable your FireWall or allow FTP.EXE to go through your FireWall
to allow the FTP utility to download the needed files

CLEAN.BAT -- For running within Windows after running c:\mcafee\GetFiles.BAT. If you choose
to scan again at a future date, run this batch file. It will automatically check the date
of the McAfee DAT files and if it is a couple of days old, it will download (FTP) the latest
signature files and install them before performing the scan.

DOSCLEAN.BAT -- For use on a Win9x/ME PC or on a Win2K/WinXP PC that is using FAT32 after
you have booted from an Emergency Boot Disk or DOS disk and have already executed;
c:\mcafee\GetFiles.BAT from within Windows. DOS disk boot images can be obtained from;
http://www.bootdisk.com/bootdisk.htm

I need you to perform the following...

Execute; CLEAN.EXE
Choose; Unzip
Choose; Close

Execute; c:\mcafee\GetFiles.BAT
{ or Double-click on 'GetFiles Link' in c:\mcafee }

Reboot the PC into Safe Mode [F8 key during boot]

Shutdown as many applications as possible !
It would also help for you to read - "How to perform a clean boot in Windows XP"
http://support.microsoft.com/kb/310353

Execute; c:\mcafee\CLEAN.BAT
{ or Double-click on 'Clean Link' in c:\mcafee }

A final report in HTML format called C:\mcafee\ScanReport.HTML will be generated. At the
end of the scan, it will be displayed in your browser (Opera, FireFox or Internet Explorer).
It is suggested that you move the report out of c:\mcafee before performing another scan.
It would be a good idea to scan in Safe Mode and in Normal Mode and save a copy of the HTML
report for each session.


* * * Please report back your results * * *

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


.



Relevant Pages

  • Re: Backdoor.Trojan virus
    ... | files infected with a Trojan virus, but was unable to quarantine or delete ... DOS disk boot images can be obtained from; ... Execute; CLEAN.EXE ... It is suggested that you move the report out of c:\mcafee before performing another scan. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: AVG or AVAST ?
    ... I have used AVG for some time with no problems and before I tell ... I much prefer Avast as it is rated higher than AVG and has a boot ... If there is a virus there before it ... why didn't the virus checker find the virus before Windows was ...
    (microsoft.public.windowsxp.general)
  • Win2000 non dos partition
    ... I use AVG which I have found better than any ... run the program from normal mode, safe mode ... it will not find ALL virus corruptions but I ... On a FAT32 system I can also boot from a bootable floppy, ...
    (microsoft.public.win2000.file_system)
  • Re: Cant boot into Safe Mode
    ... I am properly chastised for not writing down the name of the virus before ... trying to send it to the AVG virus vault. ... Is there such a thing as a "boot CD" (such as the Boot ... AVG popped up to inform me that it had ...
    (microsoft.public.windowsxp.general)
  • Re: New virus worm alert ....
    ... | Antivirus Version Update Result ... | AntiVir 6.30.0.15 05.27.2005 no virus found ... DOS disk boot images can be obtained from; ... Execute; CLEAN.EXE ...
    (microsoft.public.security.virus)