HELP I think I have a virus, but norton says no

Operating System, Common Application & ThinkPad Utilities Questions...
Post Reply
Message
Author
Jmmmmm
Sophomore Member
Posts: 129
Joined: Tue Jul 12, 2005 3:28 am

HELP I think I have a virus, but norton says no

#1 Post by Jmmmmm » Wed Mar 21, 2007 8:36 am

I think i accidentally installed a virus. I clicked on the install program for some program i downloaded yesterday, and it immediately disappeared. I figured I was f-d and immediately turned off my wireless connection, and a minute later i got a message telling me i was trying to connect to the internet. :(

I ran my norton antivirus corp, which is up to date in definitions, but it did not find any viruses. Now today, I'm getting these popup ads...and they're opening up in internet explorer, even though I'm using firefox (which is the default browser). Ironically, the last two popups were about winvirus pro. I also ran a windows defender spyware scan, which came up empty too.

I'm concerned about leaving my internet connected, I don't want it to be stealing my info or whatever.

What should i do??

here is a picture of what procexp says is running on my computer. I don't think I see anything unusual, although i don't know what every one is. (i was running windows defender at the time...) http://i172.photobucket.com/albums/w29/ ... rocexp.jpg
Last edited by Jmmmmm on Wed Mar 21, 2007 8:53 am, edited 1 time in total.
T43 - 75U - 2.0ghz : 14.1" SXGA

GomJabbar
Moderator
Moderator
Posts: 9765
Joined: Tue Jun 07, 2005 6:57 am

#2 Post by GomJabbar » Wed Mar 21, 2007 8:50 am

Run a virus scan from Windows SAFE MODE. Also I would download and install Spybot and also run a Spybot scan from SAFE MODE. Some virus' can cloak themselves in Windows Normal mode, but the cloaking often doesn't work in SAFE mode.

http://www.safer-networking.org/
DKB

rkawakami
Admin
Admin
Posts: 10055
Joined: Sun Jun 04, 2006 1:26 am
Location: San Jose, CA 95120 USA
Contact:

#3 Post by rkawakami » Wed Mar 21, 2007 9:24 am

According to this site:

http://answers.yahoo.com/question/index ... 254AAI3TOG

booting into Safe Mode and then running Control Panel/Add-Remove Programs worked. YMMV.

If not, then try Spyware Doctor and Ad-Aware. Sometimes using Windows System Restore can help.
Ray Kawakami
X22 X24 X31 X41 X41T X60 X60s X61 X61s X200 X200s X300 X301 Z60m Z61t Z61p 560 560Z 600 600E 600X T21 T22 T23 T41 T60p T410 T420 T520 W500 W520 R50 A21p A22p A31 A31p
NOTE: All links to PC-Doctor software hosted by me are dead. Files removed 8/28/12 by manufacturer's demand.

Kyocera
Moderator Emeritus
Moderator Emeritus
Posts: 4826
Joined: Wed Aug 10, 2005 8:00 pm
Location: North Carolina, ...in my mind I'm going to Carolina.....
Contact:

#4 Post by Kyocera » Wed Mar 21, 2007 9:40 am

System restore is a great troubleshooting tool, always create a restore point first, if you experience odd behaviour after installing any program or device go back to that point.

carbon_unit
Moderator Emeritus
Moderator Emeritus
Posts: 2988
Joined: Sat Apr 24, 2004 9:10 pm
Location: South Central Iowa, USA

#5 Post by carbon_unit » Wed Mar 21, 2007 9:59 am

T60 2623-D7U, 3 GB Ram.
Dual boot XP and Linux Mint.
Registered linux user #160145

steveg47
Senior Member
Senior Member
Posts: 723
Joined: Wed Sep 13, 2006 11:11 am
Location: Northern NJ

#6 Post by steveg47 » Wed Mar 21, 2007 10:01 am

Don't forget to check for rootkits. This utility works very well to detect rootkits: http://www.microsoft.com/technet/sysint ... ealer.mspx
Also, run msconfig and check the startup tab for suspicious entries.
X220(Win8.1pro)~T60p~X100e(Win8pro)~S10~X31~X40~T42~T43~560X~600X

RealBlackStuff
Admin
Admin
Posts: 17517
Joined: Mon Sep 18, 2006 5:17 am
Location: Mt. Cobb, PA USA
Contact:

#7 Post by RealBlackStuff » Wed Mar 21, 2007 10:06 am

acs.exe could be a baddie.
If it is located: c:\windows\acs.exe it is most likely an Atheros wireless utility.
If it is located: c:\program files\acs-style\acs.exe you got a WORM W32.Kelvir.W
see here: http://www.softwaretipsandtricks.com/da ... csexe.html

All the others look OK to me.
Lovely day for a Guinness! (The Real Black Stuff)

Check out The Boardroom for Parts, Mods and Other Services.

carbon_unit
Moderator Emeritus
Moderator Emeritus
Posts: 2988
Joined: Sat Apr 24, 2004 9:10 pm
Location: South Central Iowa, USA

#8 Post by carbon_unit » Wed Mar 21, 2007 11:52 am

If you are really serious about cleaning it up go build this: http://www.ubcd4win.com/
It takes some effort but it is worth it. Booting from a live cd that is known not to be compromised allows for better virus/rootkit detection.
I use this every day fixing computers.
T60 2623-D7U, 3 GB Ram.
Dual boot XP and Linux Mint.
Registered linux user #160145

Jmmmmm
Sophomore Member
Posts: 129
Joined: Tue Jul 12, 2005 3:28 am

#9 Post by Jmmmmm » Wed Mar 21, 2007 6:15 pm

Thanks for the help everyone.

I ran a virus scan in safe mode, did a rootkit scan, and did a virus scan with activescan (couldn't get kaspersky to work), and they all came up pretty empty. Luckily, i had a system restore point from yesterday, so I restored it to then, and everything seems to be OK right now. I wanted to try to delete it first, but whatever it is, it seems to be gone.

I'd like to try that ultimate boot cd, but I just don't have time to mess with it right now. Hopefully i won't have any more problems with this, though. Thanks again.
T43 - 75U - 2.0ghz : 14.1" SXGA

tyanlion
Sophomore Member
Posts: 169
Joined: Thu Feb 15, 2007 12:30 pm
Location: Singapore

#10 Post by tyanlion » Wed Mar 21, 2007 8:01 pm

its probably something from IE or firefox like a plugin or add on. best bet is to do system restore. But i don't think its a trojan or anything like that your procs are all standard.

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “Windows OS (Versions prior to Windows 7)”

Who is online

Users browsing this forum: No registered users and 1 guest