Become a supporter to remove this ad

User Tag List

+ Reply to Thread
Results 1 to 11 of 11

Thread: Virus Help

  1. #1
    Member BIGFELLA's Avatar
    Join Date
    Jul 2006
    Location
    PERTH/WANNEROO
    Motorbike
    1999 R1
    Liked
    0 times
    Posts
    1,351
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Mate is getting this virus through his Kaspersky antivirus and it will not go away.Any ideas...........

    Virus.Win32.Virut.q

    BIGFELLA
    BIGFELLA SAY'S " make love,not war. Get married have both.........."

  2. #2
    Member TYSON's Avatar
    Join Date
    Apr 2004
    Location
    Sweatshop
    Motorbike
    Turbo Hayabusa, 06 GSXR 1K, 09 700 Raptor SE
    Liked
    0 times
    Posts
    10,823
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Has he updated to the latest database? it was only detected a couple of days ago. Also try running a scan in safe mode.

    When all else fails look for services and startups in msconfig that aren't right.
    My Turbo Build

    Thanks to Sponsors:
    Motorcycle Panel & Paint
    Q-Zar Fremantle
    Rated-R Parts
    PerthStreetBikes.com and it's generous members
    Carlisle Printing - Deals for PSB members
    CIC - Competition & Industrial Coatings
    Carpet Liquidators - Midland

  3. #3
    Member MikeC's Avatar
    Join Date
    Jun 2007
    Location
    Scabs
    Motorbike
    '05 Ducati 749 Dark
    Liked
    0 times
    Posts
    1,216
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Update Kaspersky. Reboot in Safe Mode. Full scan.

    Possibly even download the latest Kaspersky update, reboot, update and scan. They released an update for it 2 days ago.
    Quote Originally Posted by zobo View Post
    I'd be more prolific in answering but I thought of a use for the othe

  4. #4
    Member BIGFELLA's Avatar
    Join Date
    Jul 2006
    Location
    PERTH/WANNEROO
    Motorbike
    1999 R1
    Liked
    0 times
    Posts
    1,351
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Cheers ill pass it on now as he put a new hard drive and updated all but it is comming from his storage drive..... love your work ill keep you guys posted.............


    BIGFELLA
    BIGFELLA SAY'S " make love,not war. Get married have both.........."

  5. #5
    Member Aphex's Avatar
    Join Date
    Nov 2006
    Location
    A private road
    Motorbike
    One thumps the other screams
    Liked
    1 times
    Posts
    13,934

    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    This is for the U variant but i dare say the Q variant is very similar. Or it may be that karspersky is seeing it differently.

    When the virus executes, it creates the following event so that only one instance of the threat runs on the compromised computer:
    Vx_4

    Next, the virus attempts to infect all .exe and .scr files on the compromised computer.

    It avoids infecting files where the file name starts with any of the following strings:

    PSTO
    WC32
    WCUN
    WINC


    Next, the virus checks the value for the following registry entry:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Explorer\"TargetHost"

    The above registry entry contains IP address and port number information. The virus may then use this information to open a back door on the compromised computer.

    If the value in the above registry entry is not available, the virus may open a back door on TCP port 80 using the following IRC server:
    ircd.zief.pl

    It uses the following name on the above channel:
    [EIGHT RANDOM CHARACTERS]

    The back door allows a remote attacker to download files on to the compromised computer and execute them.

    Symantec dont seem to be doing as many fancy targetted threat removal tools as a few years ago and there isnt one for this. Id try AGV or something similar if kasperski isnt getting it. Failing that, download a free trail of Nortons. I know some think its a dirty word but it works.

    Safe mode FTW.
    In complete darkness we are all the same. It is only our knowledge and wisdom that seperate us. Dont let your eyes deceive you.
    Its the little things that make the difference
    Quote Originally Posted by IPIT on relationships
    If either/both of you can take a dump with the other person being next to you within a week of meeting them then you're in with a VERY good chance.

  6. #6
    Member MikeC's Avatar
    Join Date
    Jun 2007
    Location
    Scabs
    Motorbike
    '05 Ducati 749 Dark
    Liked
    0 times
    Posts
    1,216
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Hopefully Kaspersky is stopping it doing all that, but it keeps popping up because it's living somewhere K can't get to it. The Safe Mode scan should fix it but good.

    Just FYI.



    EDIT: wrong stinkin' slash
    Quote Originally Posted by zobo View Post
    I'd be more prolific in answering but I thought of a use for the othe

  7. #7
    Member TYSON's Avatar
    Join Date
    Apr 2004
    Location
    Sweatshop
    Motorbike
    Turbo Hayabusa, 06 GSXR 1K, 09 700 Raptor SE
    Liked
    0 times
    Posts
    10,823
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    If it's coming from a storage drive after a fresh install it should be just a matter of deleting the offending file.
    My Turbo Build

    Thanks to Sponsors:
    Motorcycle Panel & Paint
    Q-Zar Fremantle
    Rated-R Parts
    PerthStreetBikes.com and it's generous members
    Carlisle Printing - Deals for PSB members
    CIC - Competition & Industrial Coatings
    Carpet Liquidators - Midland

  8. #8
    Member BIGFELLA's Avatar
    Join Date
    Jul 2006
    Location
    PERTH/WANNEROO
    Motorbike
    1999 R1
    Liked
    0 times
    Posts
    1,351
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    If it's coming from a storage drive after a fresh install it should be just a matter of deleting the offending file.[/b]
    Yes true its just he is not that flash my old mate Rusty Gates......... on computer stuff..................... It was a mission trying to tell him how to install a new hard drive and pin confic ect....... over the phone whilst i was working today..........

    BIGFELLA
    BIGFELLA SAY'S " make love,not war. Get married have both.........."

  9. #9
    Member TYSON's Avatar
    Join Date
    Apr 2004
    Location
    Sweatshop
    Motorbike
    Turbo Hayabusa, 06 GSXR 1K, 09 700 Raptor SE
    Liked
    0 times
    Posts
    10,823
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    <div class='quotetop'>QUOTE(TYSON @ Sep 19 2007, 05:17 PM) <{POST_SNAPBACK}>
    If it&#39;s coming from a storage drive after a fresh install it should be just a matter of deleting the offending file.[/b]
    Yes true its just he is not that flash my old mate Rusty Gates......... on computer stuff..................... It was a mission trying to tell him how to install a new hard drive and pin confic ect....... over the phone whilst i was working today..........

    BIGFELLA
    [/b][/quote]

    I understand bro, been there many times.Good luck.
    My Turbo Build

    Thanks to Sponsors:
    Motorcycle Panel & Paint
    Q-Zar Fremantle
    Rated-R Parts
    PerthStreetBikes.com and it's generous members
    Carlisle Printing - Deals for PSB members
    CIC - Competition & Industrial Coatings
    Carpet Liquidators - Midland

  10. #10
    Member MikeC's Avatar
    Join Date
    Jun 2007
    Location
    Scabs
    Motorbike
    '05 Ducati 749 Dark
    Liked
    0 times
    Posts
    1,216
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yes true its just he is not that flash my old mate Rusty Gates......... on computer stuff..................... It was a mission trying to tell him how to install a new hard drive and pin confic ect....... over the phone whilst i was working today..........[/b]
    Thanks the gods i don&#39;t do THAT for a job anymore. At least now i can just walk over and slap the person upside the head when they&#39;ve done something dumb.

    i&#39;d have thought if it&#39;s just an infected file, Kaspersky would have just gotten rid of it by now (quarantined/deleted/whatever). Full scan in safe mode FTW for my money.
    Quote Originally Posted by zobo View Post
    I'd be more prolific in answering but I thought of a use for the othe

  11. #11
    Member BIGFELLA's Avatar
    Join Date
    Jul 2006
    Location
    PERTH/WANNEROO
    Motorbike
    1999 R1
    Liked
    0 times
    Posts
    1,351
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Update............. All fixed.. Cheers PSB



    BIGFELLA
    BIGFELLA SAY'S " make love,not war. Get married have both.........."

+ Reply to Thread

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Content Relevant URLs by vBSEO 3.6.0