Downloaded a virus HELP!!

Downloaded a virus HELP!!

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Downloaded a virus HELP!! Clueless blonde 11-11-2006
Posted by =?Utf-8?B?Q2x1ZWxlc3MgYmxvbmRl on November 11, 2006, 7:53 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I stupidly dowloaded Drive Cleaner which popped up on my computer today. I
am absolutely clueless when it comes to computers and need to know what to do
next. I have the Shield Anti Virus and Firewall already installed on my
system and have run a scan which has not detected anything. I then
downloaded Spyware Doctor which detected the Drive Cleaner virus amongst 104
others threatening my system and it is saying I have to register to remove
these ($29.95). I haven't done this yet and downloaded Microsoft Malicious
Software Removal Tool which ran a full scan and it says there are no threats,
no viruses. I don't know what to do now as the only scan that has detected
these are with Spyware Doctor which I have to pay for. I just paid out for
Shield anti virus 2 weeks ago which I thought would have protected me so I
don't want to shell out even more money if I don't have to. I would really
appreciate anyones help on this but please be aware I am not computer
literate and any answers have to be an idiots guide. The viruses that
Spyware Doctor detected were - Drive Cleaner at low risk, Tracking Cookies at
low risk, Caishow at elevated risk, Seekmo at elevated risk and Winfixer at
elevated risk. What do you experts think? Please please help me!!!

Posted by Malke on November 11, 2006, 8:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Clueless blonde wrote:

> I stupidly dowloaded Drive Cleaner which popped up on my computer
> today. I am absolutely clueless when it comes to computers and need
> to know what to do
> next. I have the Shield Anti Virus and Firewall already installed on
> my
> system and have run a scan which has not detected anything. I then
> downloaded Spyware Doctor which detected the Drive Cleaner virus
> amongst 104 others threatening my system and it is saying I have to
> register to remove
> these ($29.95). I haven't done this yet and downloaded Microsoft
> Malicious Software Removal Tool which ran a full scan and it says
> there are no threats,
> no viruses. I don't know what to do now as the only scan that has
> detected
> these are with Spyware Doctor which I have to pay for. I just paid
> out for Shield anti virus 2 weeks ago which I thought would have
> protected me so I
> don't want to shell out even more money if I don't have to. I would
> really appreciate anyones help on this but please be aware I am not
> computer
> literate and any answers have to be an idiots guide. The viruses that
> Spyware Doctor detected were - Drive Cleaner at low risk, Tracking
> Cookies at low risk, Caishow at elevated risk, Seekmo at elevated risk
> and Winfixer at
> elevated risk. What do you experts think? Please please help me!!!

The Shield is malware. You need to get rid of it and get a real
antivirus installed. The DriveCleaner garbage is one of the many
variants of WinAntivirus/Winfixer which is also malware. I'll give you
links to removal steps for all of this cr*p you've got on your machine,
but I'll be frank and say that your best course of action would be to
either take the machine to a professional computer repair shop (not
your local version of BigStoreUSA) OR back up your data and
clean-install Windows. It's going to be quite the ordeal cleaning up
this machine. You know your own skill level and will have to make the
decision about what to do for yourself.

Go through the preparatory work here:
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Here are specific removal steps for The Shield and
Winfixer/Winantivirus:

Titan Shield removal how-to using Siri's smitfraudfix -
http://www.bleepingcomputer.com/forums/topic55288.html

http://www.elephantboycomputers.com/page2.html#Winfixer

I would also go through the rest of the general malware removal steps,
including scanning with either Sysclean or Multi_AV, plus Ewido. Do all
prep/finishing work and follow instructions to do all scans in Safe
Mode.

When all else fails, run HijackThis and post your log in one of the
specialty forums listed at the link above (not here, please).

If you decide to just bite the bullet and clean-install Windows, here
are links to help you with that:

http://michaelstevenstech.com/cleanxpinstall.html - Clean Install How-To
http://www.elephantboycomputers.com/page2.html#Reinstalling_Windows -
What you will need on-hand

After you get your machine cleaned up, go to at least some of the links
below to see how to practice "Safe Hex" and keep your computer clean in
the future. Don't skip MVP Eric Howes' page on rogue antispyware
programs.

http://www.wilderssecurity.com/showthread.php?t=27971 - So How Did I Get
Infected Anyway?
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://www.claymania.com/safe-hex.html
http://www.aumha.org/a/parasite.htm - The Parasite Fight
http://msmvps.com/blogs/harrywaldron/archive/2006/02/05/82584.aspx - MVP
Harry Waldron - The Family PC - How to stay safe on the Internet
http://www.spywarewarrior.com/rogue_anti-spyware.htm - Eric Howes on
Rogue Antispyware Programs
http://www.getsafeonline.org/

Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User

Posted by David H. Lipman on November 11, 2006, 8:45 am
If you were  Registered and logged in, you could reply and use other advanced thread options

| I stupidly dowloaded Drive Cleaner which popped up on my computer today. I
| am absolutely clueless when it comes to computers and need to know what to do
| next. I have the Shield Anti Virus and Firewall already installed on my
| system and have run a scan which has not detected anything. I then
| downloaded Spyware Doctor which detected the Drive Cleaner virus amongst 104
| others threatening my system and it is saying I have to register to remove
| these ($29.95). I haven't done this yet and downloaded Microsoft Malicious
| Software Removal Tool which ran a full scan and it says there are no threats,
| no viruses. I don't know what to do now as the only scan that has detected
| these are with Spyware Doctor which I have to pay for. I just paid out for
| Shield anti virus 2 weeks ago which I thought would have protected me so I
| don't want to shell out even more money if I don't have to. I would really
| appreciate anyones help on this but please be aware I am not computer
| literate and any answers have to be an idiots guide. The viruses that
| Spyware Doctor detected were - Drive Cleaner at low risk, Tracking Cookies at
| low risk, Caishow at elevated risk, Seekmo at elevated risk and Winfixer at
| elevated risk. What do you experts think? Please please help me!!!



If you are using any version of Sun Java that is prior to JRE Version 5.0 update
9,
then you are strongly urged to remove any/all versions.
There are vulnerabilities in them and they are actively being exploited.

It is highly suggested that you update to the latest version which is Sun Java
JRE/JSE
Version 5.0 Update 9

Simple check, look under...
C:\Program Files\Java

The only folder under that folder should be the latest version.

Such as...
C:\Program Files\Java\jre1.5.0_09

http://java.sun.com/javase/downloads/index.jsp
http://www.java.com/en/download/manual.jsp

FYI:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102557-1
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102648-1


For non-viral malware...

Please download, install and update the following software...

* Ad-aware SE v1.06
http://www.lavasoft.de/
http://www.lavasoftusa.com/
http://www.lavasoft.de/ms/index.htm

* SpyBot Search and Destroy v1.4
http://security.kolla.de/
http://www.safer-networking.org/microsoft.en.html

* SuperAntiSpyware
http://www.superantispyware.com/superantispywarefreevspro.html

After the software is updated, I suggest scanning the system in Safe Mode.

I also suggest downloading, installing and updating BHODemon for any Browser
Helper Objects
that may be on the PC.

* BHODemon

http://www.majorgeeks.com/downloadget.php?id=3550&file=11&evp=245a87539eea8ed6904332b4b8b8442d

For viral malware...

* Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by =?Utf-8?B?UGFuZGFfbWFu?= on November 11, 2006, 9:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
"Clueless blonde" wrote:

> I stupidly dowloaded Drive Cleaner which popped up on my computer today. I
> am absolutely clueless when it comes to computers and need to know what to do
> next. I have the Shield Anti Virus and Firewall already installed

...

> I just paid out for
> Shield anti virus 2 weeks ago which I thought would have protected me

...

>What do you experts think? Please please help me!!!


Who did you pay for this pest *Shield Anti Virus* ?
Start by removing all of them from Add/Remove programs

Then -> click here http://pandaman.my.contact.bg/Gen_MRI.htm

--
Panda_man
Silver level Contributor

Posted by =?Utf-8?B?Q2x1ZWxlc3MgYmxvbmRl on November 11, 2006, 10:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Oh my God, this is worse than I thought. I paid and downloaded from
pcsecurityshield.com from a recommendation on another site for their value
for money and ease of use (one of these comparison sites). My Norton Anti
Virus etc had just run out and I was trying to find a cheaper version. If I
remove these from my system I am going to have nothing protecting the system
so do you recommend I have a back up ready to install when I remove the
Shield. Going from what you have all said The Shield is not protecting me
then but instead threatening me. I can't believe I've been so stupid.

"Panda_man" wrote:

> "Clueless blonde" wrote:
>
> > I stupidly dowloaded Drive Cleaner which popped up on my computer today. I
> > am absolutely clueless when it comes to computers and need to know what to
do
> > next. I have the Shield Anti Virus and Firewall already installed
>
> ...
>
> > I just paid out for
> > Shield anti virus 2 weeks ago which I thought would have protected me
>
> ...
>
> >What do you experts think? Please please help me!!!
>
>
> Who did you pay for this pest *Shield Anti Virus* ?
> Start by removing all of them from Add/Remove programs
>
> Then -> click here http://pandaman.my.contact.bg/Gen_MRI.htm
>
> --
> Panda_man
> Silver level Contributor

Similar ThreadsPosted
HELP: Virus is preventing me from installing anti virus software!! January 11, 2007, 2:17 am
I have a virus that uses "anti virus software" downloads as a cover up March 24, 2007, 1:40 pm
I have a worm or virus that does not allow me to go to ANY anti-virus website January 28, 2006, 10:29 pm
Caught a Virus: Virus:Trj/Shutdown.Z -- need advice June 13, 2007, 12:59 am
Vundo fix not finding vundo virus - windows tool deletes virus May 14, 2008, 2:06 pm
Does anybody know what virus i've got? July 5, 2005, 8:23 am
New Virus? July 6, 2005, 11:22 am
virus July 19, 2005, 12:20 pm
Virus help August 8, 2005, 10:34 am
Virus Help August 13, 2005, 8:00 am

The site map in XML format XML site map

Contact Us | Privacy Policy