PDA

View Full Version : virus maybe?



LA_MERC_Drax
August 22nd, 2005, 04:43 AM
Took 2 screen shots, i get that pop up every once in awhile, and if you look at my display properties screen, theres a few tabs missing in there....

I ran microsoft antispyware, it found all kinda stuff, but it didn't fix this problem. Also i have two icons on my bottom right corner of my desktop. One is a red exclamtion point in a red circle, it says "your computer is infected" when i mouse over it, and i can't close it. Another one similar to it, cept its a shield with a red X emblem on it.

Any ideas on how to fix, or am i lookin at reformating....

LA_MERC_T4rg3T
August 22nd, 2005, 06:43 AM
What type of virus software do you run? When was the last time you updated the virus definitions and did a full virus scan?

That pop up could be from a spyware program trying to get you to download their software. You really should right click on "My Computer" and then click "manage". Go to services and find the "Messenger" service. Go to its properties and set it to disable.

Then go to Start >> Run and type "mmc". Go to File and then "Add/Remove Snap-in". Click "Add" and then find "Group Policy" and add it in. Select "Finish" to add it in and then "Close" and "OK". Expand it to "Local Computer Policy/User Configuration/Administrative Templetes/Control Panel/Display. Make changes as needed. As default, everything should be set to "Not Configured" but as you select a setting, it should tell you what the default is. After you make the changes, just close out, you don't have to worry about saving.

LA_MERC_T4rg3T
August 22nd, 2005, 06:45 AM
For the Icon in the bottom right, you need to find out what is presently running on your pc. Post a list of what is in your "Add/Remove" programs from Control Panel. Also, post a list of Processes from Task Manager. Some virus programs attack the anti-virus program first and disable it. Maybe do an online virus scan from symantec at http://symantec.com/cgi-bin/securitycheck.cgi. I would remove your anti-virus program and install one of the newest versions.

LA_MERC_Drax
August 22nd, 2005, 05:54 PM
all the screenies you asked for...

LA_MERC_T4rg3T
August 22nd, 2005, 10:18 PM
You got the Home Search Assistant. Thats one of the hardest spyware programs there is to remove. I mean, one of the hardest.

You can try to uninstall it but I'm 99% sure that it will not uninstall. Get rid of the PartyPoker, PokerStars, Search Extender, and Shopping wizard. Uninstall the Norton 2003 and download the Symantec Corporate Edition 10 that I just uploaded and install it, update it and then do a full system scan.

Did you try what I posted above and if so, to what success?

You can try this program to remove Home Search Assistant. Make sure to boot into safe mode before running this application.
http://www.majorgeeks.com/download.php?det=4286
http://www.hsremove.com/

Another thing. Click Start >> Run and type "regedit". In the new window, navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run and list what is currently in the right hand window. Also check your startup folder that is listed in your programs menu. Start >> Programs >> Startup.

LA_MERC_Dirge
August 23rd, 2005, 06:14 AM
You got the Home Search Assistant. Thats one of the hardest spyware programs there is to remove. I mean, one of the hardest.


:doh

Sorry drax, but lol :doh

Biggs
August 23rd, 2005, 12:44 PM
target, what is ur day job? u seem to know a boat load about computer stuff.

LA_MERC_Diesel
August 23rd, 2005, 12:59 PM
target?!?!?
hacker by day...
hacker by night....er

He is essential in the frying of chicken strips.
I am sure he has a fancy title but he is Computer God for Raising Cane's

-=C.O.P.S=-KOrruptED
August 23rd, 2005, 01:16 PM
Same thing happened to me.
You have to edit the registry. I did it manually but I think Kelly has a reg to fix it.

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\Explorer]
"NoActiveDesktopChanges"=hex:00,00,00,00
"NoActiveDesktop"=dword:00000000
"NoSaveSettings"=dword:00000000
"ClassicShell"=dword:00000000
"NoThemesTab"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System]
"NoDispAppearancePage"=dword:00000000
"NoColorChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"NoDispBackgroundPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoDispCPL"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoDispSettingsPage"=dword:00000000
"NoDispScrSavPage"=dword:00000000
"NoVisualStyleChoice"=dword:00000000
"NoSizeChoice"=dword:00000000
"SetVisualStyle"=-

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\ActiveDesktop]
"NoChangingWallPaper"=dword:00000000

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\ThemeManager]
"ThemeActive"="1"
"DllName"=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00, 52,00,6f,00,6f,00,\
74,00,25,00,5c,00,72,00,65,00,73,00,6f,00,75,00,72 ,00,63,00,65,00,73,00,5c,\
00,54,00,68,00,65,00,6d,00,65,00,73,00,5c,00,6c,00 ,75,00,6e,00,61,00,5c,00,\
6c,00,75,00,6e,00,61,00,2e,00,6d,00,73,00,73,00,74 ,00,79,00,6c,00,65,00,73,\
00,00,00

LA_MERC_T4rg3T
August 23rd, 2005, 01:55 PM
Removing it from the registery is fine but if you do not get rid of the dll files then it will just replicate itself back into the registry.

Also, no God by far. Just a humble helper.

-=C.O.P.S=-KOrruptED
August 23rd, 2005, 02:02 PM
That is correct, start in safe mode and run Ad-Aware, it will remove the desktophijack.

LA_MERC_Sniper
August 25th, 2005, 01:30 PM
if that dont work so what i did . heheheh REFORMAT!!! lol

-=C.O.P.S=-KOrruptED
August 25th, 2005, 02:31 PM
:p so wrong, I think Search & Destroy may prob work better to remove it.

Biggs
August 25th, 2005, 02:36 PM
taget,
u work for canes in br? mmmm good chicken that should be eating sparingly due to enourmous (spelling?) fat and caloire counts. but still mmmmmmmmmmmmm good. mmmmm canes sauce......mhmmmmmmm

LA_MERC_T4rg3T
August 25th, 2005, 03:22 PM
Yeah, I work in Baton Rouge along with Captain Obvious. When you hear about the culture and how much fun the crew has working at Canes, its true. Oh yeah, I like the chicken to.. mmmmm... Cane's Sauce.

LA_MERC_Diesel
August 25th, 2005, 03:37 PM
Toby since you arre avatarily challenged...I have one for you

LA_MERC_Drax
August 26th, 2005, 08:06 PM
heres my screen shot from symantec virus scan, should i delete those files or get a virus remover software to do that?

Also, when im playing BF2 now, i can play for a short while flying a jet, but after about 30 secs, i dip low to the ground and it stalls up and then some of the planes(usually the ground ones) come up black. Could this be associated with a virus or drivers maybe?

LA_MERC_T4rg3T
August 27th, 2005, 10:23 AM
What you should do is uninstall that old ass virus scanner and download and install the one I uploaded and told you about a few post back. Make sure you read through all the post.

42d3e78f26a4b20d412==