Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

HELP! repeated infections HELP! Please.....

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
nostamj Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:18 AM
Original message
HELP! repeated infections HELP! Please.....
this morning I had the third attack in about a 3-week period. this time, it remapped my KEYBOARD.

the filth has been:

Sidesearch
nCase
Ezula
ClientMan


leaving as many as hundreds of parasites in memory, registry, cookies and files (ezula dlls)

I don't open attachment and have not downloaded anything in this period.

SpyHunter has located and removed them, but they've gotten back in twice now. (this is triggered by a pop-up of some kind)

I'm freaking out. Losing HOURS of work time.

I'm on AOL (and no, I can't change at this time).

Is there a firewall I need to install? (I haven't added anything to the basic setup of the laptop (Presario 900/XP).

Does anyone know HOW this filth is getting through?
Is SpyHunter REALLY cleaning things up or is a timebomb being left which re-installs this crap?

Is there a class-action suit against the people behind these horrors?

Printer Friendly | Permalink |  | Top
LoZoccolo Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:28 AM
Response to Original message
1. I use MacAfee for viruses and ZoneAlarm as a firewall...
...and I never have a problem that doesn't get fixed right away by those two.
Printer Friendly | Permalink |  | Top
 
Old and In the Way Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:36 AM
Response to Original message
2. Couple of suggestions
(1) If it's infected the Windows OS, check add/remove programs and see if you can locate a suspicious prgram that might be the malware installed on your machine.

(2) Could be an Acyive X program installed on in your browser. Check your Tools/Internet Options/Settings/View Objects file. Check the properties of this objects and see if they might be malware programs that take over your browser.

Also, if you don't have it, I'd suggest getting/installing Zone Alarm to control the ports that allow unfettered access into your computer.
Printer Friendly | Permalink |  | Top
 
smiley_glad_hands Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:37 AM
Response to Original message
3. I use Spybot Search & Destroy (free), ZoneAlarmPro, and Norton Antivirus.
I would try Spybot.
Printer Friendly | Permalink |  | Top
 
jmowreader Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:39 AM
Response to Original message
4. No, no class-action suit, sorry...
but if you catch 'em below the Mason-Dixon Line, the classic "he needed killin" defense would work.
Printer Friendly | Permalink |  | Top
 
nostamj Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:41 AM
Response to Original message
5. thanks to all
I am downloading ZoneAlarm right now.

I have Norton, SpyBot and SpyHunter already.

will take a look at the OS when the download is complete.

god i HATE these people. they all should have their hands hacked off so they can never touch a computer again...
Printer Friendly | Permalink |  | Top
 
Catshrink Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:55 AM
Response to Reply #5
7. I'm taking your lead...
and downloading Zone Alarm also. I haven't had a virus (I use NAV obsessively!) but the pop ups suddenly became obnoxiously intense. Since I installed ZAP just minutes ago, it's killed about a dozen popups. I just got the trial.... $50 is gonna hurt a bit but may well be worth it. Keep me posted on how it works for you, Mr. NY Bureau!
Printer Friendly | Permalink |  | Top
 
charlie Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:01 PM
Response to Reply #7
9. $50 for a popup blocker?!
When IE was my main browser, I used KillAd:

http://www.iomagic.org/fsc/

It's free. It's also tiny, with no installation -- it doesn't splatter gunk into your system folders or registry.
Printer Friendly | Permalink |  | Top
 
nostamj Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:28 PM
Response to Reply #7
10. $39.95 from www.zonelabs.com n/t
Printer Friendly | Permalink |  | Top
 
mobuto Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:58 AM
Response to Reply #5
8. Are they all updated?
Edited on Sat May-01-04 12:00 PM by mobuto
If you have Norton, for example, and the virus defs aren't newer than about 12 minutes, you're going to get hit.

At least some of the parasites you listed typically come from filesharing apps. You have Kazaa or something similar? You might want to consider an alternative.
Printer Friendly | Permalink |  | Top
 
DS1 Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:54 PM
Response to Reply #5
16. dude, no zonealarm? brave, brave man
Printer Friendly | Permalink |  | Top
 
charlie Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 11:47 AM
Response to Original message
6. Using IE?
Select Tools --> Internet Options --> Security
Choose the Internet Zone (the one with the globe), then click Custom Level.

Then with all the options under the ActiveX and Plugins subheading, choose either Disable or Prompt.

If you choose Disable, you won't be able to see plugin content, like Flash stuff.

If you choose Prompt, you'll get a lot of warning popups about ActiveX and ActiveX scripting that you'll have to acknowledge before you can view the content.

When I used IE, I opted for the latter. It was a hassle, but I never downloaded a virus.
Printer Friendly | Permalink |  | Top
 
nostamj Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:34 PM
Response to Reply #6
11. well, it's like this
I have IE but use the browser within AOL--usually.

I can no longer launch the stand-alone browser. I immediate get hit with dozens of pop-ups (this is still happening AFTER installing ZoneAlarm)

when I am not connected, I cannot access "Internet Options" as I get a message saying I do not have permission and to contact my system administrator.

further, I can't FIND this instance of IE to remove it!

Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:36 PM
Response to Original message
12. I'm switching a lot of my clients to McAfee
because it's way ahead of the game on spotting adware and trojans.

In combination with that I use Zone Alarm as the firewall, and also use such spyware killers as Ad-Aware (there are others that will be recommended as this conversation progresses).

The two main infection points are spam email and malicious web sites. It's next to impossible to judge a web site, but you CAN practice safe email-- NEVER OPEN ANYTHING FROM ANYONE YOU DO NOT RECOGNIZE. And even if you do recognize the name, don't open any attachments unless you are specifically expecting them.

Printer Friendly | Permalink |  | Top
 
Catshrink Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:40 PM
Response to Reply #12
13. Okay... I've installed Zone Alarm but it's messed up Outlook
now I can't send/receive email unless I go into the ZA settings and disable them. So what's the freaking point? Damn I hate computers.
Printer Friendly | Permalink |  | Top
 
Prisoner_Number_Six Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:45 PM
Response to Reply #13
14. Hopefully easy to fix
Edited on Sat May-01-04 12:46 PM by Prisoner_Number_Six
Try going into the Program Control module and locate Outlook, and enable it. There are other email protection settings you can play with-- look for settings having to do with POP3 and SMTP. If blocked, change them to allow.

BTW, I repair computers for a living, and I hate them too. So I know how you feel!
Printer Friendly | Permalink |  | Top
 
Catshrink Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 12:51 PM
Response to Reply #14
15. I worked in IT for ten years
I was a traveling technical trainer and did my share of network fixes, software/hardware installs, etc. I can do a lot of stuff -- and then I get easily frustrated and flummoxed by this kind of crap.

It's a patience issue I think.
Printer Friendly | Permalink |  | Top
 
Bossy Monkey Donating Member (1000+ posts) Send PM | Profile | Ignore Sat May-01-04 01:05 PM
Response to Original message
17. Another suggestion: HijackThis
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
Small and quick. On the other hand, you have to sort throught the results and decide which items to delete. On the other other hand, there are many many help desks on the 'Net, and they are easy to find by googling "hijackthis log" and the name of whatever item you're wondering about.

Second Prisoner_Number_Six's suggestion of AdAware. They update definitions/reference files much more frequently than Spybot.

On Spybot, do yourself a favor and use the Immunize function. It'll block any spyware/malware/scumware the program recognizes. (You'll always see a little Do Not Enter warning sign on the bottom bar of IE, especially when visiting long threads at DU, but you'll get used to it.)
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Thu May 09th 2024, 06:49 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC