PCBUILD Archives

Personal Computer Hardware discussion List

PCBUILD@LISTSERV.ICORS.ORG

Options: Use Forum View

Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
John Sproule <[log in to unmask]>
Reply To:
PCBUILD - Personal Computer Hardware discussion List <[log in to unmask]>
Date:
Fri, 4 Nov 2005 13:35:33 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (76 lines)
It will be important to note the names of the viruses found and any other
information about them that the virus scanner produces.  Usually, the web
site for your virus scanner will provide you with more information about the
virus, including detailed directions for manually removing it and perhaps an
automated tool for doing the same.

TrendMicro's page on the Bagel.AB trojan is here, http://tinyurl.com/bycvz.
Note, that under solution, they seem to have some sort of automated tool.

Their java/bytever.b page is here, http://tinyurl.com/e2x9g.  It looks like
the virus scanner, itself, should be sufficient for removing this virus.

As has been noted by others, you'll need to disable system restore when
removing these viruses.  It is possible that some of these viruses have done
significant damage, either directly or indirectly, if they opened up your
computer to outside access.  Although it is a drasctic step, the surest way
to make sure nothing has been left behind is to do fresh installation of
windows on a drive that you've wiped with a utility that writes zeros to it
(or something similar).

John Sproule

----- Original Message -----
From: "Dianne" <[log in to unmask]>
To: <[log in to unmask]>
Sent: Thursday, November 03, 2005 2:43 PM
Subject: [PCBUILD] Mess that Virus created?


> Hi Moderator,
> Ok, this is going to be a long one, I will log what has happened from
> beginning to end.
> 1.I received a WinZip file, I had been expecting one so I opened it, it
> failed to open twice.  Then things started happeing this was probably a
> virus.
> 2.  I had been running AVG free and it was completely updated daily.
> 3.  Then my AVG wouldnt work, I was told it might be corrupted, uninstall
> and re-install, so I did.
> 4.  I got "Installation failed: "error action failed for file avgcc.exe,
> creating file.... Bad File Descriptor"
> 5.  Keep receiving message that "windows explorer has encountered a
> problem and must shut down" - Wthe Windows Explorer wasnt open at the
> time.
> 5A.  I installed Avast!, hoping to get some interim protection, it
> installed, but then refused to work, telling me there was an "RPC error".
> 6.  On your advice, I downloaded and used: CW Shredder, Trend Micro
> Anti-Spyware, Ad-Aware (which I use anyway) and SpyBot.
> 7.  When I used Anti-Spyware 3.0 (Trend Micro), after the entire scan, I
> select all and delete the spyware/viruses/trojans, in the middle of the
> delete process it tells me "Anti-Spyware Main Module has encountered a
> problem and needes to close".  I tried again and the same message occured
> at the same  time.
> 8.  I then downloaded and used Trend Micro-House Call.  It took 1 hour to
> go through all the files on the computer and told me it found "25
> infections" (my heart turned upside down).
> 9. I continued the program and had them all deleted, it showed mainly
> Troj_Bagel.AB and Java/ByTever.B as the viruses.  Why didnt AVG pick them
> up in the first place?
> 10.  I shut down, rebooted and then attempted a clean install of AVG, only
> to get the the same point in the installation and be told "Installation
> Failed, Bad File Descriptor".
> 11.  When going to the Security Centre Icon in Control Panel, to make sure
> the Windows Firewall is working, I get "Windows Firewall settings cannot
> be displayed because the associated service is not running. Do you want to
> start the Windows Firewall/Internet Connection Sharing (ICS) service?"
> When I say yes, all is well until I reboot the computer, and we start all
> over again.
> 12.  I have been to the MY COMPUTER-MANAGE-SERVICES location, and turned
> on everything: ICS, RPC, etc.  But when I reboot it goes back to zero.
> Any ideas.
> Dianne

              The NOSPIN Group is now offering Free PC Tech
                     support at our newest website:
                          http://freepctech.com

ATOM RSS1 RSS2