Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

VIRUS - please help!!!!!!!

Thread Tools
 
Search this Thread
 
Old 24 May 2002, 02:01 PM
  #1  
NeilT
Former Sponsor
Thread Starter
 
NeilT's Avatar
 
Join Date: Sep 2000
Location: www.scoobyworld.co.uk
Posts: 1,987
Likes: 0
Received 0 Likes on 0 Posts
Angry

Folks,

I need some urgent help from any virus experts out there!

I was sent an email with 2 attachments - 1 being a shot of an engine bay the other a batch file. They were from someone I knew so opened it and guess what....yep a Forking virus in the bat.

At the time I had no virus software running due to only just finished rebuilding the pc the day before, so I've just gone out and bought Dr Solomns Virus Scan for W98 and I cannot install it, it gets half way through and stops with the message "Internal Error 2735 stopavsyncmanager" then quits.

So i'm completely stuck. Regedit can no longer be run from the command line (file cannot be found) and If I try to uninstall Dr Solomons it gives the same error. The virus seems to be in a file called "PcC342.exe" which of course cant be deleted.

help!!! please!

I remember there used to be a utility called Magic Bullet which ran off a floppy for exactly this sort of thing but I cant track it down.

Anyone offer any help

kind regards

Desperate Neil

Old 24 May 2002, 02:06 PM
  #2  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Post

Goto McAfee Website & do a search for that virus. It should come up with instructions for best removal.

OK - It don't but lots of good advice there!

Into dos & edit the batch file & work out what it did. It may just have renamed some files, in which case poss to amend easily or undo some other things. Also, if the .exe is the load distributor, boot to a dos prompt from a bootable CD/Floppy, locate it & delete. Attrib PcC342.exe -s -r -h to change any dos attribs it may have.

[Edited by Puff The Magic Wagon! - 5/24/2002 2:14:34 PM]
Old 24 May 2002, 02:06 PM
  #3  
IanW
Scooby Regular
 
IanW's Avatar
 
Join Date: Jul 2001
Posts: 21,865
Likes: 0
Received 0 Likes on 0 Posts
Post

goto http://www.nai.com and download the trial of Virus Scan from there.
Old 24 May 2002, 02:10 PM
  #4  
NeilT
Former Sponsor
Thread Starter
 
NeilT's Avatar
 
Join Date: Sep 2000
Location: www.scoobyworld.co.uk
Posts: 1,987
Likes: 0
Received 0 Likes on 0 Posts
Red face

Thanks, but,

Puff - I dont know what the virus is called having no software on the pc to id it with.

Ian - I have and it wont complete the install - PC hangs (yes really hangs) and requires a reset

Old 24 May 2002, 02:16 PM
  #5  
IanW
Scooby Regular
 
IanW's Avatar
 
Join Date: Jul 2001
Posts: 21,865
Likes: 0
Received 0 Likes on 0 Posts
Post

IIRC NAI has a utility like that, Virus Scan Emergenct Boot Disk? Jack Clark should be able to confirm.
Old 24 May 2002, 02:17 PM
  #6  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Arrow

Updated advice...
Old 24 May 2002, 02:21 PM
  #7  
Puff The Magic Wagon!
Moderator
Support Scoobynet!
iTrader: (2)
 
Puff The Magic Wagon!'s Avatar
 
Join Date: May 2000
Location: From far, far away...
Posts: 16,978
Received 15 Likes on 9 Posts
Post

There's also a dos command line scanner in the buy/try section.

http://www.nai.com/naicommon/buy-try...ucts-evals.asp & select Dos as the Platform

Trending Topics

Old 24 May 2002, 02:23 PM
  #8  
Hanslow
Scooby Regular
 
Hanslow's Avatar
 
Join Date: Mar 2001
Location: Derbyshire
Posts: 4,496
Likes: 0
Received 0 Likes on 0 Posts
Smile

Could you try the free online one at http://www.pc-cillin.com?

Just click on the free scan button at the top. Might be able to get you a bit further
Old 24 May 2002, 02:31 PM
  #9  
NeilT
Former Sponsor
Thread Starter
 
NeilT's Avatar
 
Join Date: Sep 2000
Location: www.scoobyworld.co.uk
Posts: 1,987
Likes: 0
Received 0 Likes on 0 Posts
Post

just seen your update Puff - thre bat file was encrypted - so its all complete jargon.

Thanks for the others - I'll try some things this pm.

whoever writes these F'ing virus's should have their nuts chopped off GRRRR!!!

thanks for all the help so far....
Old 24 May 2002, 02:51 PM
  #10  
druddle
Scooby Regular
 
druddle's Avatar
 
Join Date: Mar 2001
Location: Berkshire
Posts: 5,528
Likes: 0
Received 0 Likes on 0 Posts
Post

What was the .bat file called ??
Old 24 May 2002, 02:56 PM
  #11  
NeilT
Former Sponsor
Thread Starter
 
NeilT's Avatar
 
Join Date: Sep 2000
Location: www.scoobyworld.co.uk
Posts: 1,987
Likes: 0
Received 0 Likes on 0 Posts
Post

I'm not at the pc at the moment, but will check the batch files name later and let you know.

I reckon the Pc-cillin online scan may do the job...

Old 24 May 2002, 02:57 PM
  #12  
druddle
Scooby Regular
 
druddle's Avatar
 
Join Date: Mar 2001
Location: Berkshire
Posts: 5,528
Likes: 0
Received 0 Likes on 0 Posts
Post

I pointed a friend at PC-Cillin from Trend and it sorted him out when he got a virus.

Cheers
Old 28 May 2002, 09:40 AM
  #13  
NeilT
Former Sponsor
Thread Starter
 
NeilT's Avatar
 
Join Date: Sep 2000
Location: www.scoobyworld.co.uk
Posts: 1,987
Likes: 0
Received 0 Likes on 0 Posts
Talking

hi folks,

quick update....the virus our machine was infected with was W32/Klez.h@MM a right nasty b'stard.

McAfee wouldnt install as the virus had already trashed the registry, Pc-Cillin wouldnt work as the virus hund the pc half way through the scan and the DOS McAfee scan didnt find it. At this stage I was contemplating putting the pc through the patio door

So I ended up loading a previous version of the registry from before the virus existed then installing the McAfee virus scan at the stage and low and behold it worked and found 16 occurences of W32/Klez.h@MM. After deleting them and reinstalling the affected files we're all back up and running and then off to bed at 2am

anyway, thanks for all your help folks....and watch out for this one!

Neil

ps - if you know of anyone writing these f'ing things let me know their name and address - I need revenge!
Old 28 May 2002, 11:30 AM
  #14  
WREXY
Scooby Regular
 
WREXY's Avatar
 
Join Date: Feb 2001
Location: Greece, previously Syd Australia
Posts: 2,833
Likes: 0
Received 0 Likes on 0 Posts
Post

I received that virus yesterday, but Norton picked it up as it was scanning the mail as it was coming through. I quarantined it then deleted it quick smart. Make sure you update frequently and if you have an option to update automatically while on the web, do it.

Cheers,

Wrexy.
Old 28 May 2002, 11:36 AM
  #15  
bioforger
Scooby Regular
iTrader: (1)
 
bioforger's Avatar
 
Join Date: Jan 2002
Location: Pig Hill, Wiltsh1te
Posts: 16,995
Received 5 Likes on 5 Posts
Angry

ah good old klez [img]images/smilies/mad.gif[/img] read this http://www.theregister.co.uk/content/55/25461.html

Neil u need to tell your mate to clean his system to, Symantec has a removal tool from the above URL.
Old 28 May 2002, 11:59 AM
  #16  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Post

Sorry people missed this thread, sounds like it's all good now.

Removal instructions in can you need them later

http://vil.nai.com/vil/content/v_994...alInstructions
Old 28 May 2002, 12:23 PM
  #17  
NeilT
Former Sponsor
Thread Starter
 
NeilT's Avatar
 
Join Date: Sep 2000
Location: www.scoobyworld.co.uk
Posts: 1,987
Likes: 0
Received 0 Likes on 0 Posts
Talking

Bioforger - actually it wasnt my mate that sent it - his system is clean - the virus has the ability to spoof the senders email address so it could have come from anywhere

Neil
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Big RS Dave
ScoobyNet General
5
14 April 2001 08:12 PM



Quick Reply: VIRUS - please help!!!!!!!



All times are GMT +1. The time now is 06:50 PM.