my computer is under attack!!!

17 replies [Last post]
Dewery's picture
Offline
Joined: 08/22/2003

Bahhh, I don't know what the heck is the matter. I wish sooo much that i didn't get comcast -- because it absolutely sucks!

Honestly, I MISS dialup at home. My school's network didn't do this stuff ... there isn't a trojan horse ... there's a trojan army and I can't contain it. I have lavasoft, spybot, mcafee virus scan, aol popup blockers, google popup blockers --- and the thing keeps pushing back. It doesn't help that it takes like an 2-3 hours to probably run a full system scan on a virus check... by the time its going to finish tonight, i'll need to run it again because i've been attacked about 4 major times since I started it.

For the 1st time ever lavasoft said I had "High Risk" ones that it deleted - a couple of them too. Spybot couldn't even kill everything on its first try - I have to reboot the system to let it start the scan again fresh.

And the thing that worries me the most is i've gotten 3 times a message from my system to run the microsoft cd because system files have been changed "that could effect" stability. I'm afraid I got a bad virus or something.

Anyway - is something new going on in the virus scene? Anyone have any suggestions? I just don't know how much more effort there is to possibly combat these things ... delete and its back with a vengence. Are there are programs I need to add to my lineup that will help me beyond spybot and lavasoft? They've both been ALL i've needed in the past.

I'm REALLY angry with comcast about this. If it is responsible for my computer to break ... well, let's just say it won't be pretty. I've invested way too much of my own money into this machine LOL (and let's not forget - i'm a poor college student Sticking out tongue LOL).

Sorry, this is mostly a rant guys, I'm just so fusterated, but any suggestions will be SERIOUSLY appreciated. Should I only browse on Aol? That's done the trick before, but I was getting stuff secretly downloaded anyway for the first time again today while sticking to aol.

Should I dump comcast? I'd hate to do it - its super fast and my mom spent a lot of money to get it (mostly hidden fees they didn't tell her about --- she originally wanted comcast because she thought she'd SAVE a couple dollars a month and it cost her more for installation than she'd "save" for about 5 years lol and they didn't even install it right --- IE they didn't install cable in my bedroom which was the primary reason the installation guy was supposed to come!!

Sorry, now I had to rant on comcast. I miss my old cable company. Stinking comcast had to buy it out /cries. and I REALLY miss my original one, time warner ... things just keep going down hill with each new cable company that has run our town.

time to open up cable companies to individual's to pick, not do the stupid townwide things ... should drive prices down too (they've skyrocketted the last couple years-- about a 10% increase this coming year too!!!!!)

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

bah ANOTHER round. GRRR

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Anonymous
my computer is under attack!!!

What are your browsing habits.
This is more then likley your problem not the cable company its not up to them to protect your system.
I dont browse any cheap ass sites that have hundreds or thousands of ppl putting stuff on them,real good way to get infected...
Also i use a router that has a hard wired firewall and nothing gets through it i dont even have virus protection on my system and never get anything on my system.
Anything that i download has to send a pre packet to my router and when the acual packet arrives if it isnt the same sive as the pre packet its blocked by the firewall hence no piggybacks by other software.

Boad's picture
Online
Joined: 03/20/2002
my computer is under attack!!!

My advice (Note, you already have adaware, spybot s&d, and a virus checker so I won't cover those).

1) Buy a router that does NAT (keeps all of those random packets from hitting your computer). - NOT FREE
2) Keep patched from windows update. - FREE
3) Use Firefox as your browser (http://www.mozilla.org). It's faster, safer, and has builtin popup blocking that beats most browsers - and it's FREE.
4) Use Thunderbird (http://www.mozilla.org) instead of Outlook. It's safer than Outlook and has built in Bayes spam filtering . - FREE

With doing these 4 things and the stuff you're already doing will cut down on 95% of the potential problems you could have in the future.

One last bit. This one is advanced so be careful. Sometimes spyware/viruses get started from the registry (thats where windows starts them up). Learning about manually cleaning the registry in safemode can be a very helpfull ability. Also, don't forget to check the system.ini to see if there is a [RUN] line and if anything is on it. But again, be carefull with this and always back up your registry.

-Boad

Boad Redblades
KOTG Webmaster and badly dressed retired Ranger

Offline
Joined: 04/17/2004
my computer is under attack!!!

Supax Silverstorm
aka Gorrash

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

After my virus software picked up a 'potentially unwanted program' (took about 2 hours for it to do it lol) I stopped it from searching for more and rebooted my system with lavasoft and spybot starting up at the system's start (therefore enabling them to kill off the programs that it couldn't earlier).

Now, I'm going to rerun my anti virus software and have it do everything again whilst turning off the internet -- and going to see a movie, just to make sure I don't have anything.

Should I run my microsoft cd to do a system restore on its programs, like my computer asked me to? Or think I killed the program that cuased the changes?

_________

And I'm downloaded that webbrowser. I don't think I need the 'better version of outlook' because, well, I don't think I even have outlook to begin with =)

Thanks for all those ideas - I'm sure they'll work. Google pop up blocker just isn't cutting it anymore. I'm sure the only reason why I kept getting the rounds of trojans is because my system really needed to be rebooted bcause of whatever couldn't have been deleted originally with lava/spybot --- because now I'm not having any problems so far.

Heeeh, I think its time to clean up my hard drive too with that condenser or whatever too .... been a couple months since I last did that. Could help make my virus software faster, I just can't get over how slow Mcafee is.

____________________

Boad - How do I do those manual cleanings - and back up the registry, etc. ?

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

Supax, that's a cool sounding website. I'll give that a try after I'm back from seeing farenhieght 9/11

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Boad's picture
Online
Joined: 03/20/2002
my computer is under attack!!!

This is offtopic but I found F9/11 to be a very interesting movie. While it was slightly biased, some of the connections made durring it really raised my brow Smiling

Here's a little tutorial about the registry: http://www.akadia.com/services/windows_registry_tutorial.html
(be sure to read the part about backing it up Smiling

Most of the startup stuff is located in HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Or change hout HKEY_CURRENT_USER with HKEY_LOCAL_MACHINE.

Note: Some things are supposed to be in there, others aren't... oh yea, and some spywhere trys to look like it belongs in there.

-Boad

Boad Redblades
KOTG Webmaster and badly dressed retired Ranger

Offline
Joined: 04/17/2004
my computer is under attack!!!

Even though you have an AV Scanner, still use an online web scanner.
There are some viruses that can hide from certain AV programs (usually Nortons or McaFee), so its always good to have a second opinions.

Here is another one I use:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Supax Silverstorm
aka Gorrash

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

Ya... I looked through that area and saw a lot that I wanted to delete - but I found a good internet site that said how to use it and deleted the only one that had the virus that I had - wsyv.exe - ewww trojans. Hopefully its gone now. I'm goign to use that online virus thing too and see if mine isn't missing something. How do we know if the stuff on the registry start up thing is legitamte or not? A couple of them didn't even have descriptions.

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Offline
Joined: 05/19/2004
my computer is under attack!!!

If you need to restore any system files that might be corrupted you can go to run on your start menu on XP and type sfc \scannow and system file checker will start and ask you to insert youre windows XP disk.. BE WARNED... that if you stop SFC before it is done youre windows might be corrupted because its in the middle of restoring files and sometimes takes a long time. Also if you have anything you purposely installed that altered the "protected system files" it may not work properly unless you repair the installation of that program.

Kratha

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

Hmm reading more about it I think I do need to run my windows in safe mode to get rid of it ... the best I could do otherwise was to quarintine it - and goodness knows how good that works.

Farenhieght 9/11 wasn't bad at all ... does moore use the editing feature liberally? sure, but he captures the essense of what's really going on, and most of the editing is more for humor than anything else. He makes a movie that could open some people's minds up to new possibilities exposing a lot of truth and makes it interesting enough that the average Joe will probably go and see it.

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

Thanks kratha - now I know how to run that without my windows prompting me to do it.

also, to whoever knows about working the registry- this file was on the registry in some form, but was also listed on the list of things that i looked up on the internet associated with the virus i got (wssdsu.exe) --- think its okay if I delete it from the registry?

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Boad's picture
Online
Joined: 03/20/2002
my computer is under attack!!!

Boad Redblades
KOTG Webmaster and badly dressed retired Ranger

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

lol that's exactly what i found when i googled it. so just follow those instructions and everything should go fine? I deleted the file on the registry, but I think I need safe mode. Just sounded complicated doing safe mode with all that stuff about the floppy disks and what not ... I'm going to have to back up my system first I think before I do it (and I have a LOT of backing up to do!!!)

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk

Offline
Joined: 11/21/2003
my computer is under attack!!!

I don't know what version of windows you are using but one reason you may be having so much trouble removing the virus's and trojan's is because of the windows automated restore feature. You will need to make sure this is turned off and that the cached files have been erased. This can however, if sufficient critical files are damaged bring your computer to a halt, so make sure you have all the disks, CD's and DVD's required for a complete reinstall.

Info on how to turn this off here:
http://vil.nai.com/vil/SystemHelpDocs/DisableSysRestore.htm

Once this is turmed off and teh cache cleared, then perform your virus and trojan scanning.

Another thing to consider is the use of a firewall. This can stop a highe degree of snooping from outside your system and if the firewall is sufficiently clever enough alert you programs and/or virus's trying to transmit data from your computer to somewhere/someone else.

A hardware firewall is best but if you want something cheap and quick (this does not always mean easy by the way) then try ZoneAlarm a software firewall that you install on your computer. ZoneAlarm do a version that is free for home use only.

Go here:
http://www.zonelabs.com/store/content/home.jsp

Your running Adaware and Spybot which is good and the advice about changing from Interent Explorer to another browser and also your email/newsreader from Outlook/Outlook Express is certainly worth considering. You must however bear in mind that a huge number of websites are specifically written with IE in mind and will no longer function properly with another browser, I can attest to this with having used a number of Browsers in my time Smiling

And I totally agree that running a scanner like that linked to above is well worth while HOWEVER be aware of one little detail that is often never stated, you cannot have more than one active antivirus software running on a single computer as almost all these scanners will conflict with each other.

Offline
Joined: 04/17/2004
my computer is under attack!!!

Here are some good links to free stuff for everyone!

AVG Antivirus:
http://www.grisoft.com/us/us_dwnl_free.php

Sygate Firewall:
http://smb.sygate.com/products/spf_standard.htm

Those are the AV/Firewall combo I use. Tried Symantec/Nortons, Mcafee, Zonealarm...and many others. Like these two the best.

A2 Trojan Scanner:
http://www.emsisoft.com/en/software/free/

Spybot Search & Destroy:
http://www.safer-networking.org/index.php?page=mirrors

Eraser:
http://www.heidi.ie/eraser/download.php

RegScrubXP:
http://www.majorgeeks.com/download.php?det=2048

And of course, free online scanners incase a virus killed your AV software:

Trend Micro - Housecall:
http://housecall.trendmicro.com/

PandaSoftware- ActiveScan:
http://www.pandasoftware.com/activescan/com/activescan_principal.htm

Symantec - Security & AV check:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

McaFee - FreeScan:
http://us.mcafee.com/root/mfs/default.asp?cid=9914

And for all your boot disk needs + other tools:

Bootdisk.com
http://www.bootdisk.com/

Don't forget about these two either..always good(well sometimes...it is Microsoft)

Windows Update:
http://v4.windowsupdate.microsoft.com/en/default.asp

Office Update:
http://office.microsoft.com/OfficeUpdate/default.aspx

Here is some information on TCP/IP Ports, incase you have a wierd port showing up when you run netstat:

TCP/IP Port info:
http://www.chebucto.ns.ca/~rakerman/port-table.html

Lookup File Extensions:
http://filext.com/index.php

Alternate Web Browser :
http://www.mozilla.org/

Google Toolbar for IE to help stop pop-ups:
http://toolbar.google.com/

Supax Silverstorm
aka Gorrash

Dewery's picture
Offline
Joined: 08/22/2003
my computer is under attack!!!

I especially loved Trend Micro gorrash ... I honestly like it better than my Mcafee which costs money every month to be able to update it! lol.

~Lionhearted
Battle Druid
http//www.magelo.com/eq_view_profile.html?num=675156

Dewery Greenmyst, 52 Ranger
Umaa Impedence, 40 Chantress
Aerick Del'Arathorn, 40 Monk