PC Help Required!

Does exactly what it says on the tin. Some of the nonsense contained herein may be very loosely related to The Sisters of Mercy, but I wouldn't bet your PayPal account on it. In keeping with the internet's general theme nothing written here should be taken as Gospel: over three quarters of it is utter gibberish, and most of the forum's denizens haven't spoken to another human being face-to-face for decades. Don't worry your pretty little heads about it. Above all else, remember this: You don't have to stay forever. I will understand.
User avatar
Johnny M
A Very Nice Man
Posts: 1837
Joined: 03 Jun 2005, 12:08
Location: Immer mit Loki.

Something very strange has been happening to my work PC. Basically it appears 'something' has managed to secretly install itself. I'm no geek so bear with my description of what's happening.

Norton scans are automatically deleting diallers.

Spyfighter is automatically picking up registery keys which I then have to manually delete.

Spywareblaster doesn't seem to be doing alot and the strange thing is that approx 2000 restricted sites are having their protection unabled on a periodic basis.

My g oogle homepage is changing to 'about:blank'.

A daware scans seem to be saying that the main culprits are something called 'VX2' and 'Searchclick' which are some form of 'malware'.

But as soon as I delete anything it's coming back within minutes. The net result is that my PC is just grinding to a halt.

The other unpleasant aspect is that certain words in my attempted open forum posts or replies to PM are automatically transforming themselves into hyperlinks to sites most people don't really want to visit. Hence my lack of activity today. This is my fifth attempt at this post. The gaps in some of the above ie g oogle are to stop it becoming a hyperlink.

If anyone receives anything (PM or email) from me during work hours I would suggest you just delete it. With the exception of one PM to The Pope and one email to Ania which I know are OK.

Any suggestions gratefully received. Our IT people's response is to come down on wednesday, wipe windows completely and then re-install it.

Talk to me in basics please. Thank you.
[size=9:7c190484cc]Johnny Boy - JB - Loki - Johnny M

Heartland 14 Jul 03 - 05 Aug 06.[/size:7c190484cc]
User avatar
SkOs
Road Kill
Posts: 23
Joined: 10 Aug 2005, 14:36
Location: Back In Space

basicly:
make sure your anti-spyware-softwares are of the latest version and that they are all updated correctly.
When that is OK just do the same thing you did before (with 'ad-aware' AND 'Spybot Seek and Destroy', just download, install and update it) but in 'Safe Mode' and without the network cable connected to the PC.

This normally should do the trick.
Good Luck.
--- You can prove me right, you can prove me wrong, but you can never kill .... ---
User avatar
DerekR
Doobie Brother
Posts: 1860
Joined: 17 Apr 2003, 17:55
Location: lost

I'd go with the IT dept suggestion. Wipe Windows and start afresh, sounds like you've got yourself in a bit of a pickle. I do a 'clean install' every few months on my home PC anyway, it's no big deal.

How come I never get any trouble like this? I use Windows built-in firewall and only recently got around to installing a virus checker, I have no spyware detection software at all. Must be those dodgy sites you're visiting Johnny :oops:
User avatar
Johnny M
A Very Nice Man
Posts: 1837
Joined: 03 Jun 2005, 12:08
Location: Immer mit Loki.

What like Heartland? :lol:

I am reliably informed it email originating and not web originating. Presumably from an email spoofed on a client's domain.

It's the 'VX2' and 'Searchclick' that are the buggers. They're being deleted by a daware but they're not. Once active again they're inviting every other little gremlin to come and play on my PC. :urff:

Bastards.
[size=9:7c190484cc]Johnny Boy - JB - Loki - Johnny M

Heartland 14 Jul 03 - 05 Aug 06.[/size:7c190484cc]
User avatar
SkOs
Road Kill
Posts: 23
Joined: 10 Aug 2005, 14:36
Location: Back In Space

Just a little suggestion DerekR, but install ad-aware or Spybot (I Prefer SpybotSD) on your PC and let it run ...
You'll be suprised of what it finds on your computer.

A Firewall doesn't block everything, once you install something on your PC, even the main executable (setup.exe) can contain a Spyware that is installed with the main program...

For Exemple even MS Windows installs a spyware (Alexa) on your computer.
No PC is as clean as you think and the danger of Spyware should never be underestimated!
--- You can prove me right, you can prove me wrong, but you can never kill .... ---
User avatar
hallucienate
Overbomber
Posts: 4602
Joined: 17 Apr 2002, 01:00
Location: /\/¯¯¯¯¯\/\
Contact:

I haven't tried this but:
VX2 Cleaner from Lavasoft
User avatar
Quiff Boy
Herr Administrator
Posts: 16794
Joined: 25 Jan 2002, 00:00
Location: Lurking and fixing
Contact:

hallucienate wrote:I haven't tried this but:
VX2 Cleaner from Lavasoft
i have. piece of cake to install and use 8)
What’s the difference between a buffalo and a bison?
User avatar
SkOs
Road Kill
Posts: 23
Joined: 10 Aug 2005, 14:36
Location: Back In Space

--- You can prove me right, you can prove me wrong, but you can never kill .... ---
User avatar
Eva
Intercontinental Assassin
Posts: 1196
Joined: 26 Jan 2002, 00:00
Location: Zureich

I can't help but I enjoyed reading your post, Johnny - it's better than a thriller on TV. :lol: Besides, of course I wish you good luck, and tell your employer to buy macs, they're less likely to catch this vicious stuff.... 8)
You can't fix stupid.
User avatar
Dan
Overbomber
Posts: 2013
Joined: 25 Sep 2002, 01:00
Location: Leeds

Reboot to safe mode, download and run hijackthis and delete the bad files then reboot to normal mode.

If you don't understand the hijackthis readout use the "save log" option and post the log and I can advise.

EDIT: Since you say ad aware is deleting them and they're returning, forget hijackthis, just run ad aware in safe mode and that should fix it.
User avatar
Johnny M
A Very Nice Man
Posts: 1837
Joined: 03 Jun 2005, 12:08
Location: Immer mit Loki.

Eva wrote:I can't help but I enjoyed reading your post, Johnny - it's better than a thriller on TV. :lol: Besides, of course I wish you good luck, and tell your employer to buy macs, they're less likely to catch this vicious stuff.... 8)
Thank you Eva. I'm glad my misfortune makes you smile. :roll: :wink: :lol:

Macs!!! :eek: :? :urff: :innocent:

Well ...it's always famous last words but I've done everything suggested and things appear to have returned to normal. So a big :notworthy: to you wonderful geeky boys (and maybe girl) for your technical advice. :D

It's at moments like this that I'm glad that you are all geeks and don't have a life. :wink: :kiss:
[size=9:7c190484cc]Johnny Boy - JB - Loki - Johnny M

Heartland 14 Jul 03 - 05 Aug 06.[/size:7c190484cc]
User avatar
Eva
Intercontinental Assassin
Posts: 1196
Joined: 26 Jan 2002, 00:00
Location: Zureich

Johnny M wrote: Thank you Eva. I'm glad my misfortune makes you smile. :roll: :wink: :lol:
Sorry. I have my bitchy moment at times :oops: . Meant no harm. :innocent:
You can't fix stupid.
User avatar
hallucienate
Overbomber
Posts: 4602
Joined: 17 Apr 2002, 01:00
Location: /\/¯¯¯¯¯\/\
Contact:

now that it looks clean:
go to http://update.microsoft.com and update your windows.
think about installing and using Thunderbird for mail and Firefox for surfing.

The updating is a command (and do it regularly), firefox and thunderbird are friendly suggestions ;)
User avatar
Johnny M
A Very Nice Man
Posts: 1837
Joined: 03 Jun 2005, 12:08
Location: Immer mit Loki.

Eva wrote:
Johnny M wrote: Thank you Eva. I'm glad my misfortune makes you smile. :roll: :wink: :lol:
Sorry. I have my bitchy moment at times :oops: . Meant no harm. :innocent:
No apology necessary. I was joking. Maybe English humour doesn't always translate into Swiss/Italian. :wink:
[size=9:7c190484cc]Johnny Boy - JB - Loki - Johnny M

Heartland 14 Jul 03 - 05 Aug 06.[/size:7c190484cc]
User avatar
lazarus corporation
Lord Protector
Posts: 3443
Joined: 09 May 2004, 17:42
Location: out there on a darkened road
Contact:

I've got to agree with Hal - use Firefox.
A lot of malware gets onto your computer because of Internet Explorer.

Firefox - combined with a good firewall and anti-spyware software all mentioned in posts above - will help enormously.

My anti-spyware software hardly ever shouts "INCOMING" at me anymore since I switched to Firefox.
User avatar
Dan
Overbomber
Posts: 2013
Joined: 25 Sep 2002, 01:00
Location: Leeds

I was forced to update to thunderbird as my outlook express started freezing for 2 minutes everytime I opened it (but worked fine after that), and nothing I tried including reinstalling outlook seemed to work, and I still don't know why it started doing it.
I'd recommend thunderbird, and it automatically imports your emails from outlook when you first run it. Mine did anyway.

If you don't wanna do that there's an option in outlook to display all emails in plain text, which would also be a solution.
Last edited by Dan on 22 Aug 2005, 16:46, edited 1 time in total.
User avatar
Johnny M
A Very Nice Man
Posts: 1837
Joined: 03 Jun 2005, 12:08
Location: Immer mit Loki.

Once again gents, thank you all for your advice. My brain is on the verge of techie-speak overload but I'll get there. :wink: :notworthy:
[size=9:7c190484cc]Johnny Boy - JB - Loki - Johnny M

Heartland 14 Jul 03 - 05 Aug 06.[/size:7c190484cc]
User avatar
lazarus corporation
Lord Protector
Posts: 3443
Joined: 09 May 2004, 17:42
Location: out there on a darkened road
Contact:

I use Thunderbird at home, but due to the MS Exchange server etc at work, I'm forced to use Outlook here.

I use Firefox across the board - it's the dog's bollocks.

Edit: plus you get to change the 'look' of Firefox - and use d00mw0lf's favourite downloadable style, which I think you might like...
nick the stripper
Slight Overbomber
Posts: 1732
Joined: 16 Dec 2004, 01:02
Location: Somewhere between Athens and Jerusalem.
Contact:

I dunno if this is any good but I use:
  • Firefox
  • SpyBotSD
  • Avast anti-virus
  • AVG
  • Sygate
  • Norton Anti-Virus
I hardly ever have trouble with viruses.

I'm thinking about switching Sygate to ZoneAlarm and removing Norton from my computer. Should I do this?
aims
Overbomber
Posts: 3211
Joined: 27 Mar 2005, 13:16
Location: in between

No reason why not. AVG is more than capable of doing its job, as is Zone Alarm. That said, if you're behind a router, fully patched and never run suspicious executables you could do without either.
User avatar
scotty
Overbomber
Posts: 4880
Joined: 10 Jun 2005, 23:03
Location: Behind the Door.........

I don't have any adaware or spyware but I'm going to get some right now!,dodgy sites :innocent: :lol: ?
Being brave is coming home at 2am half drunk, smelling of perfume, climbing into bed, slapping the wife on the arse and saying,"right fatty, you're next!!"
User avatar
Zuma
Slight Overbomber
Posts: 1831
Joined: 24 Jan 2003, 00:36

Another thought if you suspect the nasties came from e mail, is turn off the auto preview feature - sometimes this can allow code to run even if you do not click anything or open the mail.

Just by tuppence worth!
Todays sarcasm is tomorrow's news
User avatar
CellThree
Slight Overbomber
Posts: 1730
Joined: 14 Feb 2003, 22:05
Location: 4200 miles from my record collection
Contact:

nick the stripper wrote:I dunno if this is any good but I use:
  • Firefox
  • SpyBotSD
  • Avast anti-virus
  • AVG
  • Sygate
  • Norton Anti-Virus
I hardly ever have trouble with viruses.

I'm thinking about switching Sygate to ZoneAlarm and removing Norton from my computer. Should I do this?
You really don't need 3 Virus scans on your computer, 1 is enough! If you use any p2p programs (soulseek etc) then don't switch to Zone Alarm, it has issues. Sygate is a perfectly good firewall. Personally I use Kerio Personal Firewall because I find it easier to configure than Sygate.

You should install Spyware Blaster though.

I have :
  • AVG
  • Kerio Personal Firewall
  • Adaware SE
  • Spybot S&D
  • Spyware Blaster
  • Microsoft Anti-Spyware
  • Firefox
  • Thunderbird
I have only been troubled by one virus in the past two years and I know that was my fault it got on the system.
24.24.2.489 Deceased
User avatar
Eva
Intercontinental Assassin
Posts: 1196
Joined: 26 Jan 2002, 00:00
Location: Zureich

Johnny M wrote:Maybe English humour doesn't always translate into Swiss/Italian. :wink:
Probably. And I never quite know how my comments come across, although I can't keep my mouth shut anyway... :wink:

However, I've learned something from this thread and thus wanted to install Thunderbird on my baby. It works fine, BUT: I can't transfer the old emails I'm collecting in folders from MS Entourage to Thunderbird. :urff: Anybody got a solution for me how I can keep my old emails (you know, my personal archives)? :?

Cheers! :notworthy:
You can't fix stupid.
User avatar
hallucienate
Overbomber
Posts: 4602
Joined: 17 Apr 2002, 01:00
Location: /\/¯¯¯¯¯\/\
Contact:

Eva wrote:
Johnny M wrote:Maybe English humour doesn't always translate into Swiss/Italian. :wink:
Probably. And I never quite know how my comments come across, although I can't keep my mouth shut anyway... :wink:

However, I've learned something from this thread and thus wanted to install Thunderbird on my baby. It works fine, BUT: I can't transfer the old emails I'm collecting in folders from MS Entourage to Thunderbird. :urff: Anybody got a solution for me how I can keep my old emails (you know, my personal archives)? :?

Cheers! :notworthy:
try this? it's quite easy to do on a PC. :P

If you're installing Thunderbird I highly recommend the quick file extension. Filing your messages the normal way is a complete bugger.
Post Reply