Author Topic: Can you help me with this virus?  (Read 5108 times)

0 Members and 1 Guest are viewing this topic.

Mad_doc

  • Guest
Can you help me with this virus?
« on: November 24, 2005, 09:13:30 PM »
I have this little problem on my computer and I cant find the reason because when I try to start avast message "access forbidden" ..or something like that (I don't have english version of avast program)

Here are the problems on my computer:
- I can't install anything
- Any program can't start another program exept few exeptions
- Some of my programs don't work and I don't get any reason
- Avast can't update
- Avast scan can't be started
- my printer don't work (I don't know if this have anything to do with the rest of the problems)

Do you have some solution for this? I'm ready to try allmost anything.

Thanks anyway

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Can you help me with this virus?
« Reply #1 on: November 24, 2005, 10:16:05 PM »
This doesn't sound like a infection.
What OS are you using?

Mad_doc

  • Guest
Re: Can you help me with this virus?
« Reply #2 on: November 27, 2005, 08:52:37 PM »
Microsoft windows XP home

Spiritsongs

  • Guest
Re: Can you help me with this virus?
« Reply #3 on: November 28, 2005, 09:05:39 AM »
 :) Would recommend you seek assistance on the forums of
     your antiSPYWARE provider  .
« Last Edit: December 03, 2005, 04:59:47 AM by Spiritsongs »

galooma

  • Guest
Re: Can you help me with this virus?
« Reply #4 on: November 28, 2005, 10:19:41 AM »
Does your user account have admin priviledges?

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Can you help me with this virus?
« Reply #5 on: November 28, 2005, 10:34:19 AM »
This could be a security program blocking applications. Have you installed a firewall with application control, PrevX, Process Guard, an anti-Trojan program with real time protection?

To check for malware, try running Trend Micro Sysclean in safe mode:

Download link:

http://www.trendmicro.com/ftp/products/tsc/sysclean.com

Download both Sysclean and the latest definitions (Pattern files).

http://www.trendmicro.com/download/pattern.asp

Unzip the file and move Sysclean to the same folder and run from there.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Mad_doc

  • Guest
Re: Can you help me with this virus?
« Reply #6 on: November 29, 2005, 04:28:22 PM »
:) Would recommend you seek assistance on the forums of
     your antiSPYWARE provider or at www.geekstogo.com .

Okay I try that..
Does your user account have admin priviledges?
no

This could be a security program blocking applications. Have you installed a firewall with application control, PrevX, Process Guard, an anti-Trojan program with real time protection?

To check for malware, try running Trend Micro Sysclean in safe mode:

Download link:

http://www.trendmicro.com/ftp/products/tsc/sysclean.com

Download both Sysclean and the latest definitions (Pattern files).

http://www.trendmicro.com/download/pattern.asp

Unzip the file and move Sysclean to the same folder and run from there.

Yes I have installed "Kerio Personal Firewall"

I'll try sysclean and tell you the result
Thank you all

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Can you help me with this virus?
« Reply #7 on: November 29, 2005, 05:57:54 PM »
Sounds like you have application control turned on in Kerio but are not allowing applications to start, and you are not allowing internet connections, or even internal connections. Your printer will not work if you block internal connections.

Make sure Network Security > Trusted Area > Loopback is ticked as trusted.

Your internet connection should not be ticked as trusted.

In Intrusions, untick Enable Application behaviour blocking.

In Network Security > Applications, you should see rules like this:



If you see any 'deny' rules in any other columns, delete the rules unless you have set that rule for a reason. When that application again tries to connect out, allow it (as long as you trust the application of course.)

Make sure the rule for any other application is set to 'deny' for 'internet in'.

Go to Shields Up! and test you settings. Create a rule to permanently block any incoming connections.

https://www.grc.com/x/ne.dll?bh0bkyd2

(You may need to allow incoming connections for messenger programs and online games or P2P networks: change the rule to internet/in to ask if you need programs like this to accept incoming connections.)




     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog