Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

What's Going On?

Thread Tools
 
Search this Thread
 
Old 07 May 2005, 10:04 AM
  #1  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Question What's Going On?

Strange things happen when I log on to my PC and onto ScoobyNet.

I don't just mean my affect on SN either!

On PC log-on - I get a warning come up that says:-

'Publisher cannot be verified - do you want to run this software'?

Software:- System.EXE

Application:- C:\WINDOWS\System32

RUN or CANCEL

Of course, I consider it to be a virus or an attack on my PC so I do not run ...

Any thoughts? And how do I get it to stop asking? The PC runs fine without clicking RUN!

Another weirdo is that when I open ScoobyNet, ADOBE ACROBAT 4.0 READER appears to start up in the background ...... this started when the above happened so I consider them related.

Any Ideas??

I have run my Anti-Virus Software and it has put 3 virus/worms into the vault

Pete
Old 07 May 2005, 10:06 AM
  #2  
Hanslow
Scooby Regular
 
Hanslow's Avatar
 
Join Date: Mar 2001
Location: Derbyshire
Posts: 4,496
Likes: 0
Received 0 Likes on 0 Posts
Default

Oh dear...I thought you Labour voters were intelligent? I would help, but I'm just a thick Tory voter
Old 07 May 2005, 10:08 AM
  #3  
ru'
Scooby Regular
 
ru''s Avatar
 
Join Date: Feb 2005
Location: Brighton no more
Posts: 2,170
Likes: 0
Received 0 Likes on 0 Posts
Default

This is purely one of the advantages of giving Labia a third term. Probably that facist Blunkett's fault...
Old 07 May 2005, 10:09 AM
  #4  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by Hanslow
Oh dear...I thought you Labour voters were intelligent? I would help, but I'm just a thick Tory voter
Well, it was worth a try ........................ any Labour voters out there??

BTW I actually said that the Tories were thick ... their voters are merely mis-led!

Pete
Old 07 May 2005, 10:11 AM
  #5  
Hanslow
Scooby Regular
 
Hanslow's Avatar
 
Join Date: Mar 2001
Location: Derbyshire
Posts: 4,496
Likes: 0
Received 0 Likes on 0 Posts
Default

Oooh back track back track....now where have we seen that before

Now, is this the slightest it annoying that it's been taken completely off topic and directed towards politics? Hmmm?
Old 07 May 2005, 10:13 AM
  #6  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by Hanslow
Oooh back track back track....now where have we seen that before

Now, is this the slightest it annoying that it's been taken completely off topic and directed towards politics? Hmmm?
I'll talk about any topic you wish ....... I love conversations that drift, I cannot get enough of them!

Drift away

Pete
Old 07 May 2005, 10:15 AM
  #7  
Hanslow
Scooby Regular
 
Hanslow's Avatar
 
Join Date: Mar 2001
Location: Derbyshire
Posts: 4,496
Likes: 0
Received 0 Likes on 0 Posts
Default

Snails....why do they climb up houses? What's the point? Do they just like looking through your windows?
Old 07 May 2005, 10:16 AM
  #8  
ru'
Scooby Regular
 
ru''s Avatar
 
Join Date: Feb 2005
Location: Brighton no more
Posts: 2,170
Likes: 0
Received 0 Likes on 0 Posts
Default

It's probably your MAF, or the way you changed your oil...
Old 07 May 2005, 10:28 AM
  #9  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

I can see that I'm not going to get much help here ...... I feel like Al Johnson who has just walked into a KluKlux Clan party!!

Pete
Old 07 May 2005, 10:38 AM
  #10  
Hanslow
Scooby Regular
 
Hanslow's Avatar
 
Join Date: Mar 2001
Location: Derbyshire
Posts: 4,496
Likes: 0
Received 0 Likes on 0 Posts
Default

Cheer up Pete, we're only pulling your leg

I've got to pop out now, but will have a look tonight to see if I can find anything out for you

Do you know what virus'/worms were put into the vault?
Old 07 May 2005, 10:45 AM
  #11  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Hanslow

WORM/KELVIR AI and AG

There are 4 of these worms now 3off AI and 1off AG ... the 4th has appeared since I tried to do a Restore!

Could I get this virus from a PDF File? Its funny how the ADOBE ACROBAT opens when I start ScoobyNet?

Pete
Old 07 May 2005, 11:56 AM
  #12  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

W32.Kelvir.AI
http://securityresponse.symantec.com...kelvir.ai.html

W32.Kelvir.AI is a worm that spreads a variant of W32.Spybot.Worm through MSN Messenger and exploits remote vulnerabilities.

AG will be similar

Upgrade Acrobat might help there's a version 7

Last edited by Nicks VR4; 07 May 2005 at 11:58 AM.
Old 07 May 2005, 12:14 PM
  #13  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Default

Call me thick but the only way of spreading files through MSN messenger is accepting file transfers and/or clicking on links supplied by people?

Now I only accept files/click links if I'm actually having a chat with the person concerned & know what it is that I'm accepting/clicking. Very simple security system that should mean you never get a virus unless the person you are talking with deliberately infects you.

Or have I missed something?
Old 07 May 2005, 12:29 PM
  #14  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Puff The Magic Wagon!
Call me thick but the only way of spreading files through MSN messenger is accepting file transfers and/or clicking on links supplied by people?

Now I only accept files/click links if I'm actually having a chat with the person concerned & know what it is that I'm accepting/clicking. Very simple security system that should mean you never get a virus unless the person you are talking with deliberately infects you.

Or have I missed something?
Nope you aint missed anything it does need that person to download and execute the file
(Sends the following message to all the MSN Messenger contacts on the compromised computer)
So you could be talking too your mate and get the file sent beliving he/she has sent you it
And some people will download / click on anything thats way a lot of Corporate companies have disable MSN etc
Old 07 May 2005, 12:30 PM
  #15  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

My daughter uses the PC as well ..... and she is always on MSN Messenger!

She's cautious - but not like me!

Thanks NicksVR4 - I'll upgrade to version 7

Pete
Old 07 May 2005, 01:54 PM
  #16  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Upgraded to version7 .... still the same quirky behaviour!

Pete
Old 07 May 2005, 05:54 PM
  #17  
Hanslow
Scooby Regular
 
Hanslow's Avatar
 
Join Date: Mar 2001
Location: Derbyshire
Posts: 4,496
Likes: 0
Received 0 Likes on 0 Posts
Default

Back again

When you say on logon, when exactly during the logon does it come up with this?

Do you have visibility of the windows desktop at this point?

Can you press CTRL-SHIFT-ESC to bring up the windows task manager and list here what processes are running at the time under the process tab? In case it's something simple, have you got anything in your Startup folder (Start button -> Programs -> Startup).

Can you also do Start->Run and then type in msconfig and hit enter. In the popped up window, select the Startup tab and list here what's in there.

Cheers

Steve
Old 07 May 2005, 07:12 PM
  #18  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Steve, thanks for getting back ......

The PC starts up as per usual, goes cleanly into the first screen of XP where the names of the accounts/users are ....

When a user clicks on their account - the desktop opens and can be seen ... its now that the offer to run a program appears .....

Any help??

Pete
Old 07 May 2005, 07:16 PM
  #19  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by pslewis
Hanslow

WORM/KELVIR AI and AG

There are 4 of these worms now 3off AI and 1off AG ... the 4th has appeared since I tried to do a Restore!

Could I get this virus from a PDF File? Its funny how the ADOBE ACROBAT opens when I start ScoobyNet?

Pete
To put it crudely Pete - you're fcuked then. I had this last week, via MSN from Fulham71. It has taken me all week to clear my laptop as new things happened every time I tried to clear it, as it manifested itself into something else.

I got help from THIS FORUM in Cyber Safety

Good luck.
Old 07 May 2005, 07:44 PM
  #20  
Nicks VR4
Scooby Regular
 
Nicks VR4's Avatar
 
Join Date: May 2003
Posts: 1,165
Likes: 0
Received 0 Likes on 0 Posts
Default

What Antivirus are you using ?

You could try going to Trend or Panda and doing a online scan

Or use your existing AV software and make sure it deletes them and not puts them in a vault , What ever a fault is as it sounds like they are still running on your PC
Old 07 May 2005, 08:12 PM
  #21  
Hanslow
Scooby Regular
 
Hanslow's Avatar
 
Join Date: Mar 2001
Location: Derbyshire
Posts: 4,496
Likes: 0
Received 0 Likes on 0 Posts
Default

I agree with Nick and Red in that it sounds like they may still be lurking

Good luck with sorting it (give the online scanners a crack as suggested by Nick). As Red pointed out, they can be a bugger to get rid of. Give your daughter a good slap as well and tell her not to accept things from strangers, or even from people she knows

Just to show I care and help a bit ()....

Here is the Trendmicro online virus checker, and Here is the Pandasoft one.

Last edited by Hanslow; 07 May 2005 at 08:15 PM.
Old 07 May 2005, 08:21 PM
  #22  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Don't use Panda, that caused even more problems....

Get help from the experts on that link I posted.
Old 07 May 2005, 08:40 PM
  #23  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Thanks to all ....

I am using AVG AV Software ... it has found them and isolated them in the vault

First time I have been infected in over 7 years of Internet activity

Pete
Old 07 May 2005, 10:58 PM
  #24  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Default

Go to the well too often and...

Old 07 May 2005, 11:50 PM
  #25  
Redkop
Scooby Regular
 
Redkop's Avatar
 
Join Date: Oct 2001
Posts: 11,403
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by pslewis
Thanks to all ....

I am using AVG AV Software ... it has found them and isolated them in the vault

First time I have been infected in over 7 years of Internet activity

Pete
Hate to tell you Pete, but AVG did that to mine too. But they replicate and manifest as BHOs and all sorts. You should really turn off System Restore when you remove any viruses too and preferably run the scan whilst in Safe Mode.
Old 09 May 2005, 09:26 PM
  #26  
pslewis
Scooby Regular
Thread Starter
 
pslewis's Avatar
 
Join Date: Jun 2000
Location: Old Codgers Home
Posts: 32,398
Likes: 0
Received 1 Like on 1 Post
Default

Cheers ... I need to get rid of them somehow!

Pete
Old 10 May 2005, 01:10 AM
  #27  
PALATINE
Scooby Regular
 
PALATINE's Avatar
 
Join Date: Nov 2002
Location: back from, and now plotting to return to, Nordschleife
Posts: 1,104
Likes: 0
Received 0 Likes on 0 Posts
Default

joy!
Old 10 May 2005, 10:28 AM
  #28  
fast bloke
Scooby Regular
 
fast bloke's Avatar
 
Join Date: Nov 2000
Posts: 26,619
Likes: 0
Received 0 Likes on 0 Posts
Default

Its probably new laybout spyware infecting your PC so they can expand the nanny state




All times are GMT +1. The time now is 10:37 AM.