PDA

View Full Version : super annoying problem...help please


MorGoth
07-12-04, 02:21 PM
Ok....when i press ctrl+alt+delete to see my task manager...it opens for like 2 seconds, then disapears....its really pssing me of because i think i may have some malacious executable running or something and i can't close it because i can't get to the task manager...any help anyone?

thanks

MorGoth
07-12-04, 02:30 PM
just to add...i'm pretty sure its some malware....every couple a minutes, on aim, an away message puts itself up that says...
"LOOK http://www.angelfire.com/empire2/fast2/bestfriends.scr !"

and a stupid web page flashes up on my desktop....anyone else having this problem, or know how to get rid of it?

thanks

redduc900
07-12-04, 02:31 PM
This symptom is caused by a virus(es), and as such I would recommend running a full system scan. Be sure you update your anti-virus software definitions beforehand.

The following viruses terminate REGEDIT.EXE and TASKMGR.EXE

W32.HLLW.Kefy:
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.kefy.html

W32.HLLW.Cydog@mm:
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.cydog@mm.html

Backdoor.IRC.Yoink.A:
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.irc.yoink.a.html

Backdoor.Volac.dr:
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.volac.dr.html

W32.Kwbot.R.Worm:
http://www.symantec.com/avcenter/venc/data/w32.kwbot.r.worm.html

The following viruses delete Regedit.exe, Regedt32.exe, Msconfig.exe, and Taskmgr.exe...

W32.Petch.B:
http://www.symantec.com/avcenter/venc/data/w32.petch.b.html

W32.HLLW.Maax.B@mm:
http://securityresponse.symantec.com/avcenter/venc/data/w32.hllw.maax.b@mm.html

MorGoth
07-12-04, 02:42 PM
ok, thanks...i'll do that and see what happens

MorGoth
07-12-04, 11:27 PM
i updated my definitions and scanned my system and it came up with nothing...any other ideas/suggestions?

Drec
07-13-04, 01:09 AM
a bud of mine had one of them aim viruses from clicking on sum1s away message with the link, thats how they spread, it was pretty nasty he ended up reformating, but runn hijackthis adaware cwsshredder and all the trojan removers you can find. see if you can snag it.

engjohn
07-13-04, 08:47 AM
Boot to safe mode, check all items in HKLM\software\microsoft\windows\curent version\run also look in HKCU\software\microsoft\windows\curent version\run this is where you will most likely find the virus that is running. Remove all pointers to it from the registry, remove all traced from the HD. Use one of the online scanners like Panda or something. Then you should be in a better place.

Remember that AV technology is a reactive technology... That means that sometimes people have to get infected first, before a cleaner is available...