FacebookTwitter
Hatrack River Forum   
my profile login | search | faq | forum home

  next oldest topic   next newest topic
» Hatrack River Forum » Active Forums » Books, Films, Food and Culture » I have a weird virus on my pc

   
Author Topic: I have a weird virus on my pc
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
At least i think it's a virus. What it does is open up the system32 folder every time i boot up my computer. Also, once in a while my antivirus will pop up that it found a virus and quarenteened it, and when this happens the system32 folder will pop up again. Now, from what i can tell it doesn't really do anything else. And it's been around for a while. But at the same time, my system32 folder is not something i want an unknown program playing around with.

Adaware and spybot don't get rid of it. running norton antivirus doesn't find it. i can't find it in any of my running processes. and it's really bothering me.

also, on a maybe related note. i have this "IE search bar" thing that i don't remember ever downloading, can't find where to get rid of it from, and every time i download the google toolbar something happens and it doesn't stay. although i think it's still installed, but not available as one of the options when i right click up on the IE toolbar.

any ideas?

Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
slacker
Member
Member # 2559

 - posted      Profile for slacker   Email slacker         Edit/Delete Post 
Have you looked for "hijack this"? I've heard that it's pretty good in getting rid of the special toolbars for IE.

Also, you might want to give Firebird or Opera a shot. At least you won't have to worry about fun little toys being installed without your permission.

Posts: 851 | Registered: Oct 2001  |  IP: Logged | Report this post to a Moderator
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
well, i'd like to figure out a way to do this without having to change my browser, but thanks. [Smile]

i'll check out hijack this

Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
Dan_raven
Member
Member # 3383

 - posted      Profile for Dan_raven   Email Dan_raven         Edit/Delete Post 
Have you seen this article on A new Trojan Horse virus
Posts: 11895 | Registered: Apr 2002  |  IP: Logged | Report this post to a Moderator
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
it's definitely not that. i've had this for weeks. and it definitely didn't come through any email. I think the safest bet is to just blame it on something my girlfriend did. [Smile]
Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
Beren One Hand
Member
Member # 3403

 - posted      Profile for Beren One Hand           Edit/Delete Post 
That's always my first choice. [Wink]
Posts: 4116 | Registered: Apr 2002  |  IP: Logged | Report this post to a Moderator
Farmgirl
Member
Member # 5567

 - posted      Profile for Farmgirl   Email Farmgirl         Edit/Delete Post 
Just download Ad Aware 6.0 and use it to strip all those unwanted toolbars off (it will only work to take away unwanted programs you already have -- not anything more you get after running it).

See if that helps. We use it a lot at work to take off stupid things that people put on their PCs. Then we just uninstalled Ad Aware when we are done with it.

Farmgirl

Posts: 9538 | Registered: Aug 2003  |  IP: Logged | Report this post to a Moderator
fugu13
Member
Member # 2859

 - posted      Profile for fugu13   Email fugu13         Edit/Delete Post 
start -> control panel -> add/remove programs.

Go down the list. If you see anything that looks fishy, google for it to find out what it is, and if its adware/spyware, remove it.

Or just post the list here and I'll tell you what to remove [Smile] .

Posts: 15770 | Registered: Dec 2001  |  IP: Logged | Report this post to a Moderator
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
okay fugu, i got rid of the ie search bar thing, that was just stupid on my part. but the system32 thing is still here.

you think that's something that's in an installed program? i didn't see anything in my add/remove programs that could be causing that.

farmgirl, i do have ad-aware. and like I said, it's not finding anything. this little guy is tricky.

Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
celia60
Member
Member # 2039

 - posted      Profile for celia60   Email celia60         Edit/Delete Post 
quote:
I think the safest bet is to just blame it on something my girlfriend did.
this is how people get clowned.
Posts: 3956 | Registered: Jun 2001  |  IP: Logged | Report this post to a Moderator
fugu13
Member
Member # 2859

 - posted      Profile for fugu13   Email fugu13         Edit/Delete Post 
Hmm, the system32 thing is odd.

It could be an installed program, but a virus is also a possible suspect. I wouldn't worry about it too much, if the AV seems to have it under control . . . but you might try running a more thorough scan of your computer if your AV software has that option.

Posts: 15770 | Registered: Dec 2001  |  IP: Logged | Report this post to a Moderator
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
Maybe if i knew what clowned meant I could take that statement as having been

A) funny
B) a threat
C) utter nonsense anyway

Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
celia60
Member
Member # 2039

 - posted      Profile for celia60   Email celia60         Edit/Delete Post 
reference to a prank i had a minion pull in august. there was a pretty extensive description on the last grenme forum (or was that 2 iterations ago?).

if you read the thread, you might remember that i was seeking revenge against the person who installed a home made virus on bill's computer, mostly because bill's first reaction was, "i think my wife gave my computer a virus," even though there were 8 other people in the house that weekend.

Posts: 3956 | Registered: Jun 2001  |  IP: Logged | Report this post to a Moderator
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
hmmm...the majority of files that have been quarantined come from my content.ie5 directory. which i know is in my temp internet files folder. but which doesn't seem to exist when i access that folder.
Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
Nato
Member
Member # 1448

 - posted      Profile for Nato   Email Nato         Edit/Delete Post 
Try going to the System Configuration Utility (If you're not running Windows 2000) by entering "msconfig" in the Run.. dialog.

Look for anything susupicious in the "Startup" tab.

Posts: 1592 | Registered: Jan 2001  |  IP: Logged | Report this post to a Moderator
Nato
Member
Member # 1448

 - posted      Profile for Nato   Email Nato         Edit/Delete Post 
Also check this if you haven't:

Go to the "Folder Options" dialog in Windows Explorer (Open up your C:\ drive or any folder).
(In XP this is Tools> Folder Options, but in older versions of windows, I think it was under the View menu.)

Go to the "View" tab.

Scroll down and make sure the checkbox is deselected next to "Restore previous folder windows at logon"

Posts: 1592 | Registered: Jan 2001  |  IP: Logged | Report this post to a Moderator
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
that worked Nato, i went into msconfig and saw some suspicious stuff there. disabled it and the pc started up fine. thanks. [Smile]

although i know this stuff still exists on my pc. i've just stopped it from running at startup.

Celia, i have a vague recollection of that thread. But i have this horrible condition, you may have heard of it. what it does is it makes me not really pay attention to stuff that isn't immediately pertinant to me. It's horribly disabling. [Razz]

Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
celia60
Member
Member # 2039

 - posted      Profile for celia60   Email celia60         Edit/Delete Post 
good, then you won't see it coming. [Wink]
Posts: 3956 | Registered: Jun 2001  |  IP: Logged | Report this post to a Moderator
Leonide
Member
Member # 4157

 - posted      Profile for Leonide   Email Leonide         Edit/Delete Post 
quote:
I think the safest bet is to just blame it on something my girlfriend did
He only put this in here because he's required to mention me in any thread he starts.

Please, continue with your computery-type discussions.

(and I remember the clowns, celia) [Big Grin]

Posts: 3516 | Registered: Sep 2002  |  IP: Logged | Report this post to a Moderator
Liquor and Fireworks
Member
Member # 5785

 - posted      Profile for Liquor and Fireworks   Email Liquor and Fireworks         Edit/Delete Post 
You should Google for the "suspicious stuff" and see if anyone else has had this virus and knows how to remove it.
Posts: 331 | Registered: Oct 2003  |  IP: Logged | Report this post to a Moderator
Strider
Member
Member # 1807

 - posted      Profile for Strider   Email Strider         Edit/Delete Post 
lol, i think "suspicious stuff" may be a bit too broad.

that's like me looking for a new car and googling "things that may or may not go places".

Posts: 8741 | Registered: Apr 2001  |  IP: Logged | Report this post to a Moderator
Leonide
Member
Member # 4157

 - posted      Profile for Leonide   Email Leonide         Edit/Delete Post 
<- laughed so hard started coughing and had to take a ricola.

Thanks a lot, jerk

Posts: 3516 | Registered: Sep 2002  |  IP: Logged | Report this post to a Moderator
Nick
Member
Member # 4311

 - posted      Profile for Nick           Edit/Delete Post 
quote:
that's like me looking for a new car and googling "things that may or may not go places".
That sounds like something my dad would say, but still funny. (edit to add that) [Razz]

[ January 12, 2004, 06:46 PM: Message edited by: Nick ]

Posts: 4229 | Registered: Dec 2002  |  IP: Logged | Report this post to a Moderator
Icarus
Member
Member # 3162

 - posted      Profile for Icarus   Email Icarus         Edit/Delete Post 
Related question: my laptop has somehow contracted something that makes my homepage www.websearch.ne+ (url misspelled to not inadvertantly send any business to these jerks). I can change the homepage, but when I restart the computer, the websearch page returns. [Mad] I'm embarrassed not to know how to get rid of this, because once upon a time I was really tech-savvy, but I'm not so embarrassed that I want to leave it there!
Posts: 13680 | Registered: Mar 2002  |  IP: Logged | Report this post to a Moderator
Nato
Member
Member # 1448

 - posted      Profile for Nato   Email Nato         Edit/Delete Post 
Have you tried Ad-Aware, Spybot Search & Destroy?

Running through updated versions of both of those would probably get rid of it. If not, you could look through your startup list in the "msconfig" System Configuration Utility to see if there's anything that might look like it.

Posts: 1592 | Registered: Jan 2001  |  IP: Logged | Report this post to a Moderator
fugu13
Member
Member # 2859

 - posted      Profile for fugu13   Email fugu13         Edit/Delete Post 
That's definitely adware or spyware. Run those two programs, and if neither works check your add/remove programs list for suspicious stuff.
Posts: 15770 | Registered: Dec 2001  |  IP: Logged | Report this post to a Moderator
Icarus
Member
Member # 3162

 - posted      Profile for Icarus   Email Icarus         Edit/Delete Post 
I looked through MSConfig and didn't see anything that stood out. I haven't done the adware or spyware thing. I guess I'll try that.
Posts: 13680 | Registered: Mar 2002  |  IP: Logged | Report this post to a Moderator
slacker
Member
Member # 2559

 - posted      Profile for slacker   Email slacker         Edit/Delete Post 
Icarus, try running, "hijack this" and see if that helps.

hijack this

Posts: 851 | Registered: Oct 2001  |  IP: Logged | Report this post to a Moderator
Icarus
Member
Member # 3162

 - posted      Profile for Icarus   Email Icarus         Edit/Delete Post 
Ad-Aware seems to have done the trick!

Thanks!

[Smile]

Posts: 13680 | Registered: Mar 2002  |  IP: Logged | Report this post to a Moderator
   

   Close Topic   Feature Topic   Move Topic   Delete Topic next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:


Contact Us | Hatrack River Home Page

Copyright © 2008 Hatrack River Enterprises Inc. All rights reserved.
Reproduction in whole or in part without permission is prohibited.


Powered by Infopop Corporation
UBB.classic™ 6.7.2