Virus-Need help

Darn Malware

Wednesday, January 14, 2009 by WeatherBound | Discussion: Personal Computing

I have vista and was running One-Care Anti virus and firewall.  Some how a virus came into my system.

I have uninstalled One-Care and installed Avast Antivirus software that has a boot scan. I did the boot scan and it found 5 viruses on my system. Avast took care of those. I installed Comodo firewall just because i think it better to have a firewall installed.

I then Installed MalwareByts Anti malware soft-wear and it found one attack. And deleted it.

 

So far all sounds good but

I am still receiving messages in my Email saying that my email i sent did not go thrue and gives me the email addresses where it was supposed to go. I do not Email very much and all these addresses where not sent by me.

I will also add that i did try Ad-Aware, Spy-blaster and Avg and others and all say everything is Good.

I am still getting theses could not be delivered emails that i did not send. when i look at the date the error message says the recent date of today.....

Has any one run in to this? If so how long does it take for those could not be delivered emails to get out of the Email system?

I will tell you it has been since Friday since all scans have been showing up with no viruses.

If you have had this virus. Let me know what you did to get rid of it.

Any help would be appreciated

Thanks

First Previous Page 2 of 6 Next Last
TerroR878
Reply #21 Thursday, January 15, 2009 12:25 PM

You could try downloading hijack this and looking for suspicious crap and booting in safe mode to delete them.

http://www.download.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html

http://www.computerhope.com/delhlp.htm

WeatherBound
Reply #22 Thursday, January 15, 2009 3:31 PM

 

but Spybot S&D is the way to go as for the other.

Found Nothing

You could try downloading hijack this and looking for suspicious crap

Ran the scan and seems way over my head.

Yrag sent me one more thing test and testing as i write this. He also says if the last scan i did did not find anything then more than likely there is nothing active in my computer.  I almost believe it because thing has slowed down a lot.

 

I also want everyone to know that i did two thing when virus got in.

1 -  I Bought a wireless printer/scanner/fax/photo/copier from hp.  so i had to install soft wear for it.

2 -  I did a search on goggle for Quest helper for World of Warcraft add-on. all i did was clicked on the search text and it seemed like something was suspicious. I want to let you know that i did no download. just clicked on search page to take me to quest helper web page.

Not sure which one i did first.

when i did a boot scan with Avast it did find a virus and it was in a hp connection.

This is what lead to this virus i got.

WeatherBound
Reply #23 Thursday, January 15, 2009 3:48 PM

Update-

TrojanHunter is about half done but it did find a virus.

C:\programs\HP|Digital Imaging\{20B3 bunch of #}setup\hpzshl01.exe(Adware.Vapsup.290)

I hope this is it.

DrJBHL
Reply #24 Thursday, January 15, 2009 3:50 PM

PuterDudeJim
That's lotsa fun. Believe me.

It's really ain't that bad Doc. I do it a few times a year, just for that new PC feel. The speed and freshness of a brand new rig come back after a format and reinstall. I do it at least twice a year. If you keep backups, it really ain't so bad. 

DrJBHL
Reply #25 Thursday, January 15, 2009 3:55 PM

WeatherBound
Update-

TrojanHunter is about half done but it did find a virus.

C:\programs\HP|Digital Imaging\{20B3 bunch of #}setup\hpzshl01.exe(Adware.Vapsup.290)

I hope this is it.

So, the HP drivers were infected?

Somebody better tell them!

PuterDudeJim
Reply #26 Thursday, January 15, 2009 4:00 PM

Update-

TrojanHunter is about half done but it did find a virus.

C:\programs\HP|Digital Imaging\{20B3 bunch of #}setup\hpzshl01.exe(Adware.Vapsup.290)

I hope this is it.

Don, I neglected to tell you about one of the best and first programs I use in the case of any virus, and it is free. Download RemoveitPro and run it, delete anything it finds. I swear by this app.

Locates & Removes many new dangerous files including Spyware, Malware, Virus, Worms, Trojan's and Adware that other popular AV programs do not find.

   http://www.incodesolutions.com/removeit.php

PuterDudeJim
Reply #27 Thursday, January 15, 2009 4:02 PM

 

Jhjm32087
Reply #28 Thursday, January 15, 2009 5:39 PM

The HP file that is "infected" could be a false postive. I would submit that to Virus Total.

WeatherBound
Reply #29 Thursday, January 15, 2009 7:57 PM

Ok.  Jim

I did a quick scan and it found this.

I have been infected with virus (Win32.Unknown.Random.X)  

Its funny that all other scans have not found this.  It is in my startup folder under Power Reg Schedule V3

Not sure Jim if i should delete it. or if the soft wear will clean it. Since you use it. let me know what you do.

PuterDudeJim
Reply #30 Thursday, January 15, 2009 8:35 PM

I did a quick scan and it found this.

I have been infected with virus (Win32.Unknown.Random.X)

Its funny that all other scans have not found this. It is in my startup folder under Power Reg Schedule V3

Not sure Jim if i should delete it. or if the soft wear will clean it. Since you use it. let me know what you do.

Delete the sucker. Anytime theres Unknown or noName in the name, which I am sure you saw in HiJack this, delete it. If it has no name, it ain't good.

 

As for it being funny that the other scans missed it, remember my post:   Locates & Removes many new dangerous files including Spyware, Malware, Virus, Worms, Trojan's and Adware that other popular AV programs do not find

WeatherBound
Reply #31 Thursday, January 15, 2009 9:01 PM

Well I am keeping that tool.

Now comes the test. Will i keep getting the emails.

 

Time will Tell

Ill keep you posted

 

Thanks Everyone! Thanks Yrag!

psychoak
Reply #32 Friday, January 16, 2009 3:16 AM

Getting on good terms with your registry is a good idea when you run into a problem like this.

WeatherBound
Reply #33 Friday, January 16, 2009 10:22 AM

I think the removit software nailed the virus. not 100% sure yet because i got on demon error mail like i have been getting and at the same time i got a email from spam master.uk.  And looked like it was trying to do some test. It had a bunch of symbols and then A bunch of attempt Failed in the email.

 

If anyone out there think they have a Mal-wear or Trojan or virus.   Give Removit a try

DrJBHL
Reply #34 Friday, January 16, 2009 10:50 AM

Jim...just downloaded it for myself as well. Many thanks for a valuable addition to my "armor". 

tippytoenail
Reply #35 Friday, January 16, 2009 2:30 PM

I have been watching this post also and couldn't do any better on the advice then that that you received from here. Talking about the armor up part. I have used Norton for 7 years now and it dose not catch all of it and sometimes I wonder if it was worth the money involved but it has saved my neck in searching on the web and the mail more then once! I use the Malware remover,RemoveIt Pro v4 - SE ,  and Adaware . I have been working on getting familiar with the registry also. I have learned to be some what comfortable with it. But I stress this point now! I am not comfortable enough to take on the HiJack program with out the help of those who know what they are doing. The first time I tried it even with help I still had to reinstall Windows so be careful. Even advanced users of (HiJack This) make mistakes. Keep your system backed up ever so often so you can help them help you.

Hey Don, send me an email as I am ready to reinstall Windows anyhow. I agree with PuterDudeJim as I like to reinstall Windows ever so often anyways. Ill let you know what what happens in this post here!

WeatherBound
Reply #36 Friday, January 16, 2009 7:40 PM

Emails have come to almost a stop. i have only gotten 2 of the spam master.uk. emails. Which looks like its a test but its says a failed.

I have used the RemoveIT tool on my sons computer and it caught 3 viruses that the others did not see.

Thanks Jim once again.

Mary. I am ready to test again

PuterDudeJim
Reply #37 Friday, January 16, 2009 11:11 PM

You are welcome Don. 

tippytoenail
Reply #38 Saturday, January 17, 2009 2:32 AM

Here I sit at 2:00 in the morning baking chicken for the raccoons and working on the WB. Should have something to send to you in a short while Don. Glad your back on track !

Ausvet
Reply #39 Saturday, January 17, 2009 4:31 AM

Be a bit careful with Remove-it, it gives false positives to Digital Persona fingerprint software installed with many fingerprint readers including on some HP systems, the file it recommends to delete is DpPwdFlt.dll in system32 directory, doing so could cause you to be locked out of your user account and/or laptop.

If it recommends deletion of dll s right click on them to inspect properties and which programs they are needed for, Dependency Walker can be helpful too.

DrJBHL
Reply #40 Saturday, January 17, 2009 5:26 AM

tippytoenail
I have been watching this post also and couldn't do any better on the advice then that that you received from here. Talking about the armor up part. I have used Norton for 7 years now and it dose not catch all of it and sometimes I wonder if it was worth the money involved but it has saved my neck in searching on the web and the mail more then once! I use the Malware remover,RemoveIt Pro v4 - SE ,  and Adaware . I have been working on getting familiar with the registry also. I have learned to be some what comfortable with it. But I stress this point now! I am not comfortable enough to take on the HiJack program with out the help of those who know what they are doing. The first time I tried it even with help I still had to reinstall Windows so be careful. Even advanced users of (HiJack This) make mistakes. Keep your system backed up ever so often so you can help them help you.

Hey Don, send me an email as I am ready to reinstall Windows anyhow. I agree with PuterDudeJim as I like to reinstall Windows ever so often anyways. Ill let you know what what happens in this post here!

I agree about Norton which is why I added Avast!

Have fun with the reinstall....uh! I guess I dislike it for the same reason I never went into surgery.

Very good advice, Ausvet!

Please login to comment and/or vote for this skin.

Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:

  • Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
  • Access to a great community, with a massive database of many, many areas of interest.
  • Access to contests & subscription offers like exclusive emails.
  • It's simple, and FREE!



web-wc01