![]() |
||
|
|
Welcome to the Exploding Garrmondo Weiner Interactive Swiss Army Penis. |
GFF is a community of gaming and music enthusiasts. We have a team of dedicated moderators, constant member-organized activities, and plenty of custom features, including our unique journal system. If this is your first visit, be sure to check out the FAQ or our GFWiki. You will have to register before you can post. Membership is completely free (and gets rid of the pesky advertisement unit underneath this message).
|
![]() |
|
Thread Tools |
Infected with Adware + virus
I already did a full virus scan with AVG Free Edition, and Search and Destroy because random ads were popping up when I opened firefox/ie.
Anyways, now these two programs - winspool.exe and lsass.exe - are opening and taking up alot of RAM. I can hear the computer struggling to keep up. I researched and found that sometimes viruses can be disguised as windows programs. So I end process, and it seemed to be okay. However, they keep coming back... is there a way to remove it? How ya doing, buddy? ![]() Want obscure Classical Music CDs? Search: http://www.lib.uwo.ca/ PM me the code, I'll rip it for ya [MAX 2 CDS/User] |
Edit: Oh nevermind. Those 2 programs are obviously don't belong to the scanners you used.
Try Registry Cleaner.. It isn't free.. but it will scan your computer for free(getting rid of them isn't the free part). It should tell you what is wrong. I have the full version. Well had. ^_^ My HDD died and took it with it. There's nowhere I can't reach.
Last edited by Winter Storm; Apr 21, 2007 at 10:27 AM.
|
Download the W32.Sasser Removal Tool from http://www.symantec.com/security_res...050114-1706-99 to get rid of the lsass.exe problem.
The other one I'm not too sure about, you could try downloading Hijack this from http://www.spywareinfo.com/~merijn/programs.php and removing the relevant entry. This thing is sticky, and I don't like it. I don't appreciate it. |
I'm having a sorta similiar problem. I noticed earlier this morning while I was on warcraft and went to my other PC to thott something, when an IE ad popped up without warning. I hadn't even clicked firefox when it popped up. (I haven't even clicked on an IE browser in years) So I was like "Oooop, malware!" and did a Adaware search. At first it froze up Adaware so I was like "Hmmmm...." I did a Spybot Search and Destroy and it found a buttload of shit I haven't even heard of. One was something like winviruscleaner or something like that. SystemDoc? I dunno. I know when I'd go on Wrestlezone sometimes I'd get a pop up that would "take over" the current page with what looked like a page for a Virus/Trojan remover. I'd go to hit cancel or no and it would try to install anyway, and I would stop it from doing so.
Last night it started to install ANYWAY as in began downloading and installing on my computer and I disabled internet connection, did another Spybot sweep and it came up with something like Smitfraud-C, that SystemDoc (or whatever it's called) and a few other things. Adaware search dug up just about 100 critical entries and got rid of all but 20. I decided to try that Housecall and it will completely kick me out of firefox every single time the scanner would start. I had to actually download the free trail version and even then, the pop up windows (which some re-direct to Gamesradar) still cause my computer to run really slow. If I knew what to look for in Hijack This, I'd run it and post my findings here. I just want this crap gone and I really don't want to have to reformat. I am a dolphin, do you want me on your body? |
This is at dagget. Basically, you're looking for suspicious startup entries, and odd-looking processes. Though, if you like, run Hijack and post the log here--I'll be glad to take a look at it for you.
Have you tried doing your scans with Adaware and Spybot in Safe Mode, yet? Doing so there can get more done, generally speaking. I was speaking idiomatically.
Last edited by Duminas; Apr 21, 2007 at 01:37 PM.
|
Here's what I got from Hijackthis:
Okay... now it's hiding as "taskmgr.exe". Thats one smart ass virus. -_- What kind of toxic man-thing is happening now? ![]() Want obscure Classical Music CDs? Search: http://www.lib.uwo.ca/ PM me the code, I'll rip it for ya [MAX 2 CDS/User]
Last edited by Sepharite; Apr 22, 2007 at 10:03 AM.
Reason: This member got a little too post happy.
|
FELIPE NO |
and here's mine
What, you don't want my bikini-clad body? |
Thanks!
Also, I think I found my virus. It's "Vundo". And here's the removal, assuming it deals with your case too: http://www.softpedia.com/get/Antivirus/VundoFix.shtml But just looking at your log, you have x10 more than what I had xD Good luck. Jam it back in, in the dark. ![]() Want obscure Classical Music CDs? Search: http://www.lib.uwo.ca/ PM me the code, I'll rip it for ya [MAX 2 CDS/User] |
Yeah, I don't know what the hell happened. Might have been a bad google search or something.
![]() There's nowhere I can't reach. |
I underlined the things I've came across that are viruses. I google'd them to make sure.
edit: and apparently, I bolded them too o_O
This thing is sticky, and I don't like it. I don't appreciate it. ![]() Want obscure Classical Music CDs? Search: http://www.lib.uwo.ca/ PM me the code, I'll rip it for ya [MAX 2 CDS/User] |
Sweeeet. Thanks man. I tried google searching some of these files and I could never get a straight answer if they were viruses or not. Running spybot and adaware again then rebooting to see if the problems are gone!
![]() I am a dolphin, do you want me on your body? |
Sepharite did a good job and got pretty much all of them, but you may also want to get rid of these two as well.
O4 - HKCU\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe I was speaking idiomatically. |
I keep trying to get rid of viewpoint, but for some reason it finds its way right back. :\
hahaha. Well, I get a RUNDLL error when it restarts now. something called oxvfphl.dll (or something like that) isn't found. But after removing those last two things as well as most of that other stuff from before, it loads up pretty quickly. What kind of toxic man-thing is happening now? |
I think you can just uninstall it from the Control Panel.
How ya doing, buddy? ![]() Want obscure Classical Music CDs? Search: http://www.lib.uwo.ca/ PM me the code, I'll rip it for ya [MAX 2 CDS/User] |