Virus/Dialler problem

Discussion in 'Technology' started by Congay, Jun 20, 2005.

Users Viewing Thread (Users: 0, Guests: 0)

  1. Congay

    Congay Registered User

    Joined:
    Aug 22, 2002
    Messages:
    20,033
    Likes Received:
    435
    Virus/Dialler problem

    Iv got some sort of fucking virus/dialler and its proving a c unt to get rid off. Its creating a .exe called svchos1at.exe and changing my dial up username to "nix" then dialling me into some isp but it still shows up as my normal isp..

    AVG will remove the virus when the svchos1at.exe exists but then shows as clean.. after a while i then get some program running in memory called "winoldap" this is defo something to do with the virus as it shows up as running about 3 times at once THEN i get disconnected and my machine attempts to dial back up on the sly... if it succeeds then after a reboot i have the svchos1at.exe back on my pc. I have tried all the online virus checks and they show me as clean.


    I am using WINME and I have got System restored disabled.
  2. 1615634792921.png
  3. Congay

    Congay Registered User

    Joined:
    Aug 22, 2002
    Messages:
    20,033
    Likes Received:
    435
    ps. is there anyway I can see what this memory resident program is (winoldap) ? can I see where on the C:\ its located and where its coming from?!
  4. Congay

    Congay Registered User

    Joined:
    Aug 22, 2002
    Messages:
    20,033
    Likes Received:
    435
    sorted this out i think...... there was something in the startup menu called AVsoft that was a avsoft.exe. deleted it and it has happened again so far. This must be a new virus tho as all checkers didnt pick up this exe.
  5. ManofScience

    ManofScience Guest

    More than likey spyware... Click Start > Run and type MSCONFIG - Click the Start up tab and have a read thru of whats there... owt that sounds dodgy - delete it. but be careful!

    Also, check the start up folder on the 'Programs Menu'
  6. Congay

    Congay Registered User

    Joined:
    Aug 22, 2002
    Messages:
    20,033
    Likes Received:
    435
    bastard this is back with a vengance, ad-aware hasnt zapped it either....

    there is nothing starting up in msconfig and nothing in the sratup menu..... there is nothing running memory resident then it just runs itself after about 10 mins and trys to dial up
  7. ManofScience

    ManofScience Guest

    Dodgy will probably be your man, he's "mr. how to fix things without flattening"

    Try something like : http://www.sysinternals.com/Utilities/RootkitRevealer.html (the link is at the very bottom) just run it - it will show u a list of hidden files - some genuine possibly some not - see if this gives u a clue as to how to clean it. Otherwise it's as per dodgy's help :



    HijackThis
    A very useful program, but do not delete anything it shows you unless you are 100% certain of what you are doing.

    Download it , extract it fully to a folder at the root of your drive (eg C:\Hthis\), run it and save a logfile (don't delete anything!). Copy and paste the full contents of the logfile to your post for help.
    http://www.majorgeeks.com/download3155.html
  8. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Teknofishy: have you tried using all those anti-spyware progs in that sticky, and the new verion of Housecall? That infection has been around for a few weeks, so should be easily cleanable - if you do try them and have no joy, post up a HJ this log, but it may be end of week before I'll get a chance to go thru it
  9. Alexander

    Alexander Registered User

    Joined:
    Jun 12, 2002
    Messages:
    14,252
    Likes Received:
    0
    This avg program that your always taking about is fucking class, everyday theres someone on here who uses it and they've got a virus.:rolleyes:
  10. Congay

    Congay Registered User

    Joined:
    Aug 22, 2002
    Messages:
    20,033
    Likes Received:
    435
    i think it may be dead at last... for some reason ad-aware was d/l its update but wasnt installing it. iv updated now and ran it twice and i seem clean *touchs wood*

    thanks the help tho chaps
  11. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    It's spyware you fucking moron.

    You of all people should not be criticising advice given on here... pot/kettle...
  12. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Still use the other progs to make sure, if it does come back up the HJThis log and will sort it.

    Adaware should have got that one though :up:
  13. Congay

    Congay Registered User

    Joined:
    Aug 22, 2002
    Messages:
    20,033
    Likes Received:
    435
    how is this kind of spyware spread?
  14. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,732
    Likes Received:
    0
    Location:
    Terra Firma
    Many ways - unpatched Internet Explorer being a main cause, or using the wrong security settings in IE and going to dubious sites. Even if you use Firefox it's a good idea to clean out your cache often (see sticky).

    You can also get it from programs you install, either pre-bundled with the software, or by the installer being tampered with (like a virus). Quite a few trojans nowadays also start downloading other trojans and spyware when active. Read the sticky, as I explained how to prevent most of it in there. :)
  15. Alexander

    Alexander Registered User

    Joined:
    Jun 12, 2002
    Messages:
    14,252
    Likes Received:
    0
    I'm just saying that people are always moaning about virus/adware on there computers, and its you who always tells them how to remove it not the software your recommending, maybe everyone should install a Dodgy on their computer and everything will be sweet.:D
  16. trance_fan

    trance_fan Registered User

    Joined:
    Nov 7, 2002
    Messages:
    9,079
    Likes Received:
    0
    Thats the worst attempt at a suck up i've ever seen :lol:

    Teknofish - Tried microsoft anti spyware? Worth a shot, it's very good.
  17. ManofScience

    ManofScience Guest

    it can take a while from when a virus/new spyware exploit is released onto the web to when it's discovered and the various spyware/AV programmes are updated... in that time it can easily get around...

Share This Page