Author Topic: Avast stopped working, virus?  (Read 93401 times)

0 Members and 1 Guest are viewing this topic.

BJS

  • Guest
Re: Avast stopped working, virus?
« Reply #150 on: August 24, 2007, 03:17:48 AM »
Mauserme, I am not sure if this means anything but the Bagle virus that I believe started it all is still in my startup (it is inactive though) 
I traced it to this folder    wintems.exe.vir C:\QooBox\Quarantine\C\Windows\System 32

Can I delete it from my computer all together??

Also, the vsnpstd2.exe is located in C:\Windows and also in

 C:\Program Files\GE\98067 MiniCam Pro

I am pretty sure this file is some sort of spyware.
« Last Edit: August 24, 2007, 03:20:02 AM by BJS »

mauserme

  • Guest
Re: Avast stopped working, virus?
« Reply #151 on: August 24, 2007, 01:57:30 PM »
No sign of 1stbar, can't see anything else there.
Me neither.

At this point I'll go out on a limb and say the tool bar was actually gone before we started, but there are some left over registry entries that are pretty stubborn.


Mauserme, I am not sure if this means anything but the Bagle virus that I believe started it all is still in my startup (it is inactive though) 
I traced it to this folder    wintems.exe.vir C:\QooBox\Quarantine\C\Windows\System 32

Can I delete it from my computer all together??

Also, the vsnpstd2.exe is located in C:\Windows and also in

 C:\Program Files\GE\98067 MiniCam Pro

I am pretty sure this file is some sort of spyware.

Qoobox is the ComboFix quarantine.  Everything in there is safe - we'll take care of it later when we clean things up.


Everything I find on vsnpstd2.exe relates it to a USB camera and many sites do seem to think its spyware.  But it does give you some configuration options so I wasn't rushing into removing it.  If you don't care about whatever options these might be we can take of it now.  Let me know.


For the time being download AVG Antispyware.  Install, update, scan and quarantine anything found.  Then post the log. 

http://free.grisoft.com/doc/download-free-anti-spyware/us/frt/0


How is the computer running?

BJS

  • Guest
Re: Avast stopped working, virus?
« Reply #152 on: August 24, 2007, 04:39:32 PM »
OK, I will run the AVG antispyware when I get back.
As far as the vsnpstd2.exe file, we can get rid of it because we no longer have the camera.

The computer seems to be running fine (minus having no virus protection) now that I am using Firefox.
IE would not let me update security patches (because I could not install Windows Installer)
I am happy with Fierfox but a few things are of concern.

It takes about 2 minutes to get into my C drive folders and about the same amount of time to look at the add/remove programs. They do  come up but not instantly like before.

Also, for some reason I cannot shut the PC of via the start button. I either have to put it on standby via the taskbar or shut it of manually. 

I am not too concerned about those yet. I would just like to clean my system out and take care of those problems later.


BJS

  • Guest
Re: Avast stopped working, virus?
« Reply #153 on: August 26, 2007, 02:05:57 AM »
Mauserme,
I guess I was meant to take my wifes PC to the shop  :-\

Yesterday I was trying to post you a message stating that I could not download the AVG antivirus program (or Panda for that matter) when I was hit by the virus in the forum. It happened pretty quickly, something about spyware, then the screen went black and as I was rebooting, some new icon (it kinda looked like a knight or something) was on my desktop. After that, the computer just started to reboot over and over.
I tried safemode and it still would restart over and over.  I did use that bootdisc that Oldman had me make and I could get into some dos commands but that was it.

Everything seemed to be going good and then this happens....kind of discouraging.

Luckily my PC has Avast and caught it (I also run Firefox)....


Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Avast stopped working, virus?
« Reply #154 on: August 26, 2007, 04:01:40 AM »
When I was hit by the virus in the forum.
The virus wasn't on avast forum but at on a redirect iframe. Luckily it was on avast virus database and was stopped. I wish an explanation of which risk have we run into yesterday. I'm not bashing avast, far from this, just trying to learn how to improve security. I also run Firefox like you.

Everything seemed to be going good and then this happens....kind of discouraging.
For me it's encouraging to learn how to get even more protected.
The best things in life are free.

mauserme

  • Guest
Re: Avast stopped working, virus?
« Reply #155 on: August 26, 2007, 05:14:38 AM »
Mauserme,
I guess I was meant to take my wifes PC to the shop  :-\
Sorry to be so long responding.  Like many others I was unable to log in.  Avant (an IE shell), Opera, Firefox - nothing worked.  I could see that DavidR and Tech were logged in but I couldn't .  Maybe they will share their secrets with me.


Anyway, if you are able to boot the machine at all, we need to take a very deep look a things which we can do with a WinPfind log.

Download WinPFind3u.exe  to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the WinPFind3u folder and double-click on WinPFind3U.exe to start the program.
  • Under Additional Scans click the checkboxes in front of the following items to select them:
      Non-Microsoft Only
           Reg - BotCheck
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Use the Add Reply button and Copy/Paste the information back here. I will review it when it comes in. If, after posting, the last line is not < End of Report > then the log is too big to fit into a single post and you will need to split it into multiple posts.


I would also loke you to run SDFix:

Download SDFIX and save it to your desktop.
Please then reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.

In Safe Mode, right click the SDFix.zip folder and choose "Extract All",
Open the extracted folder and double click "RunThis.bat" to start the script.
Type Y to begin the script.
It may remove Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot.
Press any Key and it will restart the PC.
Your system will take longer that normal to restart as the fixtool will be running and removing files.
When the desktop loads the Fixtool will complete the removal and display Finished, then press any key to end the script and load your desktop icons.
Finally open the SDFix folder on your desktop and copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log.



BJS

  • Guest
Re: Avast stopped working, virus?
« Reply #156 on: August 26, 2007, 06:53:55 AM »
I can boot to DOS (using the bootdisc) but I cannot get to my desktop in Windows   :-\
« Last Edit: August 26, 2007, 06:55:29 AM by BJS »

mauserme

  • Guest
Re: Avast stopped working, virus?
« Reply #157 on: August 26, 2007, 03:28:54 PM »
How would you like to proceed?

I mean, our patience with these things is virtually endless around here (even if our abilities have limits).  And from my point of view I want to know what's going on and solve this.  But we have to face another re-install of the OS, this time with an XP Home disc.  With or without the current problem we would have to do this to get you back to the correct OS.

I just want to make sure you're OK with this.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Avast stopped working, virus?
« Reply #158 on: August 26, 2007, 04:59:16 PM »
I agree with mauserme. Somewhere along the line you have to get back to xp home. Whether here or at a shop. And I too am interested in what is happening. But it's your call.

BJS

  • Guest
Re: Avast stopped working, virus?
« Reply #159 on: August 26, 2007, 08:53:29 PM »

Ok, I will try to find a copy of XP (home edition) once I find it and upgrade I will post.

Thanks again

mauserme

  • Guest
Re: Avast stopped working, virus?
« Reply #160 on: August 26, 2007, 09:46:26 PM »
Ok, I will try to find a copy of XP (home edition) once I find it and upgrade I will post.
8)


When you install use the key from the computer case.

After installation see if you find c:\windows\system32\chkdsk.exe     If it's missing copy it from c:\windows\system32\dllcache  to  c:\windows\system32


Download a fresh copy of ComboFix and scan.   Also scan with WinPFind and save the log.  Then post those two logs plus a fresh HJT log.

Keep the computer off line as much as possible except to download the tools, post the logs, or get Windows updates.   

mauserme

  • Guest
Re: Avast stopped working, virus?
« Reply #161 on: August 28, 2007, 11:04:11 PM »
Please don't run ComboFix yet.  I have been advised of a problem that I beleive is not common but we will avoid it all together.

The WinPFind3U log will be best for now.

BJS

  • Guest
Re: Avast stopped working, virus?
« Reply #162 on: September 20, 2007, 12:18:47 PM »
Mauserme,
I did get a copy of XP Home and could get back into my desktop. But I did not want to risk getting a 3rd virus (having no virus protection at all)
 so I just made backup disks of my documents and files and then formatted my hard drive. I then did a scan on the disks to make sure they were clean and added them back.

Now that I have reinstalled XP and reformatted my drive, everything is great. Pretty much like a new PC and Avast! is working again.  I did learn quite a few things from you and Oldman (some tools such as Erunt, Combofix, F-secure blacklight and toolbar cop) along with a few handy websites (virus total) but hopefully I will not need them again.   

I also learned the hard way about the bagle virus.  No more downloading scrabble games for me!

Thanks again for all your help...

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89065
  • No support PMs thanks
Re: Avast stopped working, virus?
« Reply #163 on: September 20, 2007, 02:52:58 PM »
That is what it is all about, learning and to do that mostly you have to make mistakes to truly learn ;D

All the tools for cleaning are great but what you should be trying for is prevention and a back-up and recovery strategy if the dark brown stuff hits the fan, much less painful all round. This topic is also quite long so I don't recall if these points have been mentioned:

1. Run applications that connect to the internet under DropMyRights to limit the potential for infection. You might also consider proactive protection, in order to place files in the system folders and create registry entries you need permission. Prevention is much better and theoretically easier than cure.

Whilst browsing or collecting email, etc. if you get infected then the malware by default inherits the same permissions that you have for your user account. So if the user account has administrator rights, the malware has administrator rights and can reap havoc. With limited rights the malware can't put files in the system folders, create registry entries, etc. This greatly reduces the potential harm that can be done by an undetected or first day virus, etc.

Browsing the Web and Reading E-mail Safely as an Administrator. This obviously applies to those NT based OSes that have administrator settings, winNT, win2k, winXP. Check Bob's, setup instructions and importantly the dropmyrights.msi file needed as MS have now cleared the original link. http://mysharedfiles.no-ip.org/dropmyrights

2. A long time ago I purchased some hard disk imaging software and every now and then I got the later versions to work with my updated OS, etc. This software takes an exact copy of your Partitions or Hard Disk and saves the 'image' to another location, which could be a second HDD or DVD or to an external storage device. I do this bak-up image weekly as part of my system maintenance.

If you have a serious problem and this would certainly come under that heading (or a crash resulting serious corruption, etc.), then you restore the last back-up image and your problem is resolved. This type of software has hauled my a** out of the fire many times (not virus issues) as to more than compensate from what I paid for the software and I can be up and running in a little over 15 minutes.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Avast stopped working, virus?
« Reply #164 on: September 20, 2007, 05:21:35 PM »
Hello BJS

Glad you got it going again. Still haven't got that disk made, just no time.