Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > OS & Software > Security and the Web

Super antispyware infected?

Reply
 
Thread Tools
  #1  
Old 05-17-2008, 07:01 AM
Habylab's Avatar
Habylab Habylab is offline
TechSpot Member
 
Location: England
Member since: Sep 2007, 149 posts
System specs
Super antispyware infected?

I have just swapped from avast to avg and during my first scan, it found superantispyware to be a virus(I-Worm/Bagle) It also found the same problem with the driver that runs my wireless mouse. It also found lots of spyware, which is surprising, considering i has just run a S&D test, which found nothing. It found Virtumonde, CoolWebSearch and titan antipyware among many others, which were all found in the same folder, and internet explorer one, which i don;'t even use! (100 i think)
I haven't deleted anything yet but when i had installed avg my computer kept restarting for some random reason. Until i found this process called 11701 (something like that) that was running and during the scan avg had detected it as I-Worm/Bagle AKA, so i stopped the process, which stopped the restarting.
I have attached a hijackthis log
Cheers,
Habylab
Attached Files
File Type: log hijackthis.log (7.0 KB, 1 views)
Reply With Quote
  #2  
Old 05-17-2008, 09:41 AM
kimsland's Avatar
kimsland kimsland is offline
TechSpot Guru
 
Member since: Dec 2007, 6,429 posts
Actually I had that issue too

I did a full scan, and it came up with all these registry errors (CoolWebSearch and others)
I found it strange too, because I scan with lots of other prgrams, and didn't realize I had 100+ entries in registry (?) What's AVG doing?

Anyway, I said remove them all, which took ages.
I restarted thinking, here we go Windows won't work, but all was ok.

So maybe just do a full scan, and allow it to do its thing, probably just tracks (left overs) I decided not to go through the list (ie too many)
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
  #3  
Old 05-17-2008, 12:32 PM
Habylab's Avatar
Habylab Habylab is offline
TechSpot Member
 
Location: England
Member since: Sep 2007, 149 posts
System specs
I have done that, and have just deleted them from my virus vault, but my wireless is playing up now... I have to edit the registry and restart it to make it work, same with the security centre.
Thank you for replying though!
Anyway i did another S&D scan and it found the same thing, but one more item. I deleted them and restarted, so i am assuming everything is ok.
Also my avg isn't showing up in CCleaner as a start-up icon, and it isn't in the system tray when i close the main window.How can i change this? It also says that the "Email Scanner" Isn't active.
EDIT: also my COMODO isn't starting up now.. It says it isn't a valid W32 Application, something like that
Please help me!!!

Last edited by Habylab; 05-17-2008 at 12:35 PM.
Reply With Quote
  #4  
Old 05-17-2008, 07:09 PM
kimsland's Avatar
kimsland kimsland is offline
TechSpot Guru
 
Member since: Dec 2007, 6,429 posts
Start AVG Free Setup program up again. Here's the link to it again: http://free.grisoft.com/ww.download?prd=afe
Reply With Quote
  #5  
Old 05-18-2008, 06:29 AM
Habylab's Avatar
Habylab Habylab is offline
TechSpot Member
 
Location: England
Member since: Sep 2007, 149 posts
System specs
I have sorted that out, but i can't go on the internet, it keeps connecting to "BTopenzone". It can't find any wireless networks, and it can't find the one i am usually connected to, which i ha a 70-80% signal... What should i do! The virus keeps popping back up, and because of this, i can't connect to the internet meaning no avg updates...
PLEASE HELP ME!!!!!!!!

I can't boot into save mode either... I found a virus and it was in the sytstem32\drivers\downld directory, and it keeps popping back up. Now i think it is stopping me from going into safe mode. When I try to boot into safe mode, it does that list of things, something like system32\driver\.... and then it reboots
Reply With Quote
  #6  
Old 05-18-2008, 08:12 AM
kimsland's Avatar
kimsland kimsland is offline
TechSpot Guru
 
Member since: Dec 2007, 6,429 posts
Sorry I'm not a malware expert (so others may reply)

But I'd hard wire it to the modem, not wireless
Also run MSCONFIG and turn off everything starting (except avg stuff)
Remove all the temp files in IE (including all the ones in Start->Run->%temp%)
Go to C:\windows\system32\drivers and checkout this download directory and probably remove all the stuff in that.

Hopefully after restart, (+ hard wired using ethernet cable) you can get on the net
Reply With Quote
  #7  
Old 05-18-2008, 03:23 PM
Habylab's Avatar
Habylab Habylab is offline
TechSpot Member
 
Location: England
Member since: Sep 2007, 149 posts
System specs
Quote:
Originally Posted by kimsland
Sorry I'm not a malware expert (so others may reply)

But I'd hard wire it to the modem, not wireless
Also run MSCONFIG and turn off everything starting (except avg stuff)
Remove all the temp files in IE (including all the ones in Start->Run->%temp%)
Go to C:\windows\system32\drivers and checkout this download directory and probably remove all the stuff in that.

Hopefully after restart, (+ hard wired using ethernet cable) you can get on the net
Sorry but a direct connection isn't available, its in the next room, and wouldn't reach.I'll try what you say, but some of my files on my desktop aren't "valid wins32 applications".
Should i just go back to avast or should i stick with avg?
How can i get into safe mode? i think it restarts when it reaches a avg__ files but it could be a coincidence...
Reply With Quote
  #8  
Old 05-18-2008, 04:48 PM
kimsland's Avatar
kimsland kimsland is offline
TechSpot Guru
 
Member since: Dec 2007, 6,429 posts
Safe Mode (repeatively pressing F8 at system startup, then selecting Safe Mode) will allow your computer to startup with minimal set of drivers (ie Without: AntiVirus and Wireless drivers and sound; and others)

Inside Safe Mode you can turn off any startups (happening in Normal Mode)
Run MSCONFIG and remove startup programs
Remove temp files (that may usually be locked by the system)
And a number of other things (remove faulty drivers so forth)

I prefer AVG (but AVG Free Ver.8 I mean) if you have version 7.5 this can be removed (and must be removed to install version 8)

edit:

Also if you can, move the computer to the Modem/Router

Last edited by kimsland; 05-19-2008 at 04:22 PM.
Reply With Quote
  #9  
Old 05-19-2008, 11:00 AM
Habylab's Avatar
Habylab Habylab is offline
TechSpot Member
 
Location: England
Member since: Sep 2007, 149 posts
System specs
I can't get inot safe mode! Thats the thing it stops at a avg__ file...
I'm going to unistall avg, and install avast, much better, apart from the lentghy scanning...
Reply With Quote
You can remove this banner by registering, join the TS Community for free.
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Infected PC - Please Help ingvar.hanna Security and the Web 1 05-01-2008 09:27 AM
infected siedog Security and the Web 17 10-25-2007 04:36 AM
Im Infected Untamed Desirez Security and the Web 39 08-29-2007 08:25 PM
Infected and need help Zough Security and the Web 14 04-22-2007 03:09 PM
Infected (again) pmcdevitt Security and the Web 2 11-08-2005 10:23 AM


All times are GMT -4. The time now is 02:31 AM.