Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Computer Virus: Help Requested
March 30, 2004 | Self

Posted on 03/29/2004 11:02:58 PM PST by bd476

About 7 hours ago a Security Alert pop-up from Norton Anti-Virus appeared suddenly on this computer screen.

Then followed another pop-up with text about closing Windows, then another pop-up followed that in the form of an adult content page, followed by yet another pop-up window with another adult content page, and then one more pop-up window with text about paying for a website using advertising pop-up windows.

I couldn't close the pop-up windows, so I unplugged the cable connection and then ran my updated Norton Virus Scan. It found nothing.

However, the Norton Anti-Virus Security Alert Log showed that in fact a virus "Download. Trojan" (there was a space between the dot and Trojan on the Norton log) had been found on my computer and that Norton Anti-Virus had failed to fix it.

Somehow I managed to get to Norton's website, where there were instructions on how to get rid/fix the virus.

Per Norton's online site instructions, I disabled System Restore, restarted this computer, ran Norton Virus Scan in regular Windows (XP) and then again in Safe Mode. Both times my Norton Anti Virus Program failed to locate the reported virus.

I had also updated virus definitions for Norton sometime earlier in the day, but decided to try updating them again. Norton's website added more virus definitions to the virus engine.

I have increased the Security options on this computer to "High." Yet still there is a concern that the reported trojan virus was not found nor fixed during the several runs of Norton's Virus Scan.

Any suggestions? Thanks in advance.


TOPICS:
KEYWORDS:
Navigation: use the links below to view more comments.
first previous 1-2021-40 last
To: bd476
Norton is sub-par.

Buy Kaspsersky Anti-virus. kaspersky.com.

(Unfortunately, NAV is made in the USA and Kaspersky is made in Russia. This sad state of affairs is what we have come to, though.

(I blame the capital markets. Too much of a premium on short-term speculation and not enough on long-term capital accumulation.))
21 posted on 03/29/2004 11:36:05 PM PST by rogueleader
[ Post Reply | Private Reply | To 1 | View Replies]

To: bd476
bunp for info later read
22 posted on 03/29/2004 11:38:40 PM PST by CONSERVE
[ Post Reply | Private Reply | To 1 | View Replies]

To: bd476
Zone alarm Pro (pay for it, well worth the duckets) , AVG, Norton AV, Spybot, Ad-aware, and get the google tool bar that has pop up stopper on it. Best I have found for my amature surfing and freeping pukin puter security needs. Also the tren micro sysclean pkg is well worth using as the post above suggests.....I use it too .

Stay Safe !!

23 posted on 03/30/2004 12:12:49 AM PST by Squantos (Be polite. Be professional. But, have a plan to kill everyone you meet.)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Rodney Dangerfield
Really ? Ad aware does that ?............where can I get the spy sweeper ya mention ?
24 posted on 03/30/2004 12:14:38 AM PST by Squantos (Be polite. Be professional. But, have a plan to kill everyone you meet.)
[ Post Reply | Private Reply | To 20 | View Replies]

To: bd476
bump
25 posted on 03/30/2004 12:20:03 AM PST by Conservative4Ever (EVIL.......thy name is Hillary)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Squantos
AdAware is spyware, and Ad-Aware is a spyware removal program. The hyphen is important.
26 posted on 03/30/2004 12:24:24 AM PST by Hawkeye's Girl
[ Post Reply | Private Reply | To 24 | View Replies]

To: Squantos
Spy Sweeper:

http://www.webroot.com
27 posted on 03/30/2004 1:25:00 AM PST by Drammach (Freedom; not just a job, it's an adventure..)
[ Post Reply | Private Reply | To 24 | View Replies]

To: edeal
Hey, lighten up! I actually like macs.

Well, I'm starting to like veggies... even Brocolli and Cauliflower. Do you suppose my G5 Mac has something to do with it? On the other hand, I eat them with a 10 ounce Top Sirloin... Medium Rare.

28 posted on 03/30/2004 2:21:23 AM PST by Swordmaker (This tagline shut down for renovations and repairs. Re-open June of 2001.)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Swordmaker
Aw, a G5 Mac!
Must be nice!
I'm limping along on a G4.
Still running a powermac 6100/66!
29 posted on 03/30/2004 6:57:25 AM PST by MaryFromMichigan (We childproofed our home, but they are still getting in)
[ Post Reply | Private Reply | To 28 | View Replies]

To: ccmay
But I can't use a Mac. I'm a heterosexual.
30 posted on 03/30/2004 7:01:20 AM PST by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 11 | View Replies]

To: bd476
I've gotten something similar. And I think it's from my provider, after close examination and calming down after a panic.

Did you also get something about "the FBI and others can trace your surfing" or something similar?
Along with an offer for "true anonymous surfing, click here?"

I have AdAware, Spybot, Norton Systemworks, Zone Alarm, and a hardware firewall, and I got that message. I used my scanning software and found nothing. It's a hoax.

I think it's just a sneaky sales pitch.
31 posted on 03/30/2004 7:09:08 AM PST by MrB
[ Post Reply | Private Reply | To 1 | View Replies]

To: AppyPappy
But I can't use a Mac. I'm a heterosexual.

Sure you can. You just have to be secure in your masculinity. Like Bush, for instance.

32 posted on 03/30/2004 7:34:39 AM PST by LexBaird (Tyrannosaurus Lex, unapologetic carnivore)
[ Post Reply | Private Reply | To 30 | View Replies]

To: LexBaird
You just have to be secure in your masculinity.

Yeah. That's what they say at the beauty salon when a guy walks in. He must be REALLY secure. (wink, wink)

33 posted on 03/30/2004 8:09:17 AM PST by AppyPappy (If You're Not A Part Of The Solution, There's Good Money To Be Made In Prolonging The Problem.)
[ Post Reply | Private Reply | To 32 | View Replies]

To: AppyPappy
Beauty salons are where all the hot chicks work.
34 posted on 03/30/2004 9:06:04 AM PST by LexBaird (Tyrannosaurus Lex, unapologetic carnivore)
[ Post Reply | Private Reply | To 33 | View Replies]

To: Drammach
Thanks..........got it and found 4.....:o)

Stay safe !

35 posted on 03/30/2004 10:35:20 AM PST by Squantos (Be polite. Be professional. But, have a plan to kill everyone you meet.)
[ Post Reply | Private Reply | To 27 | View Replies]

To: Hawkeye's Girl
Kewl.........I learned something !

Stay safe !

36 posted on 03/30/2004 10:40:15 AM PST by Squantos (Be polite. Be professional. But, have a plan to kill everyone you meet.)
[ Post Reply | Private Reply | To 26 | View Replies]

To: GeronL
I NEVER advise clients to reformat their HDs. My suggestion is always to put the faulty HD down range and see how well it functions after a dose of buckshot from a 12 ga. pump gun. Reformatting is for wusses.
37 posted on 03/30/2004 10:43:45 AM PST by dcwusmc ("The most dangerous man, to any government, is the man who is able to think things out for himself.)
[ Post Reply | Private Reply | To 8 | View Replies]

To: bd476
From link:http://www.annoyances.org/exec/forum/win2000/t1061426385

I had a user today that was experiencing symptoms similar to those from "download.trojan".
She had Symantec anti-virus, which detected it, but could not remove it. I had
her try ZoneAlarm and told her to send me a HijackThis log.

ZoneAlarm immediately found C:\WINDOWS\System32\wintsvsu.exe trying to make an outbound
connection.

HijackThis also showed this suspicious entry

O4 - HKCU\..\Run: [WCPS] C:\WINDOWS\System32\wintsvsu.exe

which was in this Registry key:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]

Usually I find a lot of viruses/worms hiding in

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

but the Run key in HKEY_CURRENT_USER was new to me.

The user deleted the entry from her Registry, went into TaskManager->Processes and
killed the wintsvsu.exe entry, and was then able to delete the file from System32.

There isn't a lot of info about wintsvsu.exe through Google, but the 1 or 2 references
to it do mention spyware.

Good luck
38 posted on 03/30/2004 10:26:01 PM PST by Drammach (Freedom; not just a job, it's an adventure..)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Drammach; Squantos
Moosoft.com has The Cleaner, it keeps track of registry keys, files and folders and alerts you to any changes the moment that they occur. You can edit the necessary files because it shows old data and new data.

I love it because it has caught more than Norton ever dreamed of
39 posted on 03/30/2004 11:09:50 PM PST by B4Ranch (Most Of Us Are Wasting Rights Other Men Fought and Died For!)
[ Post Reply | Private Reply | To 38 | View Replies]

To: B4Ranch
Kewl .............Thank Yeeeeeew !

Stay safe !

40 posted on 03/31/2004 1:11:55 AM PST by Squantos (Be polite. Be professional. But, have a plan to kill everyone you meet.)
[ Post Reply | Private Reply | To 39 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-40 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson