View Single Post
  #18 (permalink)  
Old 18/07/06, 08:45
syphus's Avatar
syphus syphus is offline
Administrator
 
Join Date: Oct 2005
Location: Far away
Posts: 2,034
syphus is on a distinguished road
Send a message via ICQ to syphus Send a message via AIM to syphus Send a message via MSN to syphus Send a message via Yahoo to syphus
Re: cant detect virus

Quote:
Originally Posted by a-c-e
I've had this virus alert for a week and I've been trying to get it off ever since. I don't know where it came from so i checked system restore to see what had been downloaded and it said, Software Distribution Service 2.0, which was downloaded an hour after i got off. I ran Norton, Spybot, Spyware Doctor, Cleanup, Ewido Guard and others to get that virus alert off and it cant seem to take it off. Any suggestions? ???

<img src="http://i30.photobucket.com/albums/c3...46/alert.jpg">
Hi a-c-e

Unfortunately, you've been a victim of the most ironic sort of malware; the one which insist you are infected with something, and will try to entice you to download specific software to remove it.

This type of malware is very difficult to get rid of because it runs two seperate programs; one which is annoying you with stupid messages, and another which protects the first program. This means that even if detected and removed, the second "guardian" thread will simply restore the first program. The only way to effectively remove the infection is to get rid of both programs at once. Because of the way the program is starting up, this cannot be done from normal Windows mode. Any attempt to disrupt the program will be reversed. If you try to remove it from startup for example, it will simply re-add itself.

The best utility to remove start-up objects is probably HiJackThis, in favour of msconfig which doesn't actually remove entries, just replaces them with an instance of itself. HiJackThis is best downloaded from established sites, as in the past it has been the subject of phishing. I recommend getting it here.

HiJackThis itself is not an anti-spyware utility, and requires pretty careful usage. Going overboard and disabling ALL start-up items can cause problems with your general Windows operations. It also means you wont actually figure out where the problem is. In order to ensure that HiJackThis is not interfered with when removing items, it is best run from safe mode.

First, I recommend you run a scan and create a log file, then post it as an attachment. Because of the sensitive nature of many start-up items, it is best that someone more experienced advises you of which items to disable, else you end up crippling Windows.

Once you have attached the log, myself or one of our Moderators will advise you.
Reply With Quote