[Virus Problem...] - Computers



Search Tech-Forums - link takes you to our Forum's search page.

Note: The following is only a text archive!


To view the actual forum discussion, please visit our website at http://www.tech-forums.net

Pages:1



Virus Problem...

(Click here to view the original thread with full colors/images)



Posted by: Abhi255

I am using AVAST on my win XP.
it is prompting me for a virus
details of the virus that it gives is:

File name: [url]http://installs.180solutions.com/downloads/dll/3.0/ncmyb.dll[/url]
Malware name: Win32:Trojan-gen. {other}
Malware type: Virus/Worm
VPS version: 0509-3,03/01/2005

i m really sick n tired of it bcoz it keeps prompting in every 2-3 min.

I have tried
Spybot
Microsoft antispyware
scanned entire disk by Avast

still no luck....

please tell me wat should i do

Thanks a ton in advance



Posted by: Trotter

[url]http://housecall.trendmicro.com/[/url]

This is a link to a free online scan. Try it first.

Then go to:
[url]http://tinyurl.com/6ywv5[/url]. This Computer Associates. Download either ezAntiVirus, or ezArmor if you don't have a firewall. I will vouch for them, as I use ezArmor. They offer a thirty day free trial, but I was told that they were doing the whole year trial again.



Posted by: HeeLiX

The particular file you are working with is spyware.

Ad-aware should remove it, if not, you should remove it manually from registry and from the program files list.

Good luck.



Posted by: rstones12

Abhi255,
Welcome

We are going to need to remove a few things, but first I would like you do to the following: The reason I am asking for these first initial steps is that it can clear up some items in the first part of the fix if needed.

I have outlined some preliminary steps that we need to address. [b]You may want to print out these intructions for reference.[/b] This process will take a few steps so please be patient and follow the provided directions.

[b][1.][/b]
First Download [url=http://cwshredder.net/bin/CWShredder.exe][color=blue]CWShredder[/color][/url]
And save it to your desktop.
Close all open browser windows and any other open windows.

Install CWShredder, then:

Open CWS and click [b]Check for Updates[/b]
Then click [b]"FIX"[/b]

[b][2.][/b]
Please run at least one of these online scans, allow it to delete anything it finds:
You may have to select the auto-fix option prior to scanning, it should be a selection box on the screen. If you are a dial-up user just do one, this can take some time.
If you are a broadband user, I would suggest at least 2 of the 3. One extra scan is most often times enough.
[list]
[url=http://housecall.trendmicro.com/housecall/start_corp.asp][color=blue]TrendMicro HouseCall[/color][/url]
[url=http://www.pandasoftware.com/activescan/com/activescan_principal.htm][color=blue]Panda ActiveScan[/color][/url]
[url=http://www3.ca.com/virusinfo/virusscan.aspx][color=blue]eTrust AntiVirus Web Scanner[/color][/url]
[/list]Please make a note of anything that wasn't or couldn't be fixed.
Reboot your machine when finished.

[b][3.][/b]
You [b]may have[/b] run these programs already, make sure they are up to date and run per provided instructions.
Current Versions are:
[b]Spybot S&D Ver: 1.3[/b] [url=http://www.safer-networking.org/en/download/index.html][color=blue]Download Here[/color][/url]
[b]Ad-Aware SE Build 1.05[/b] [url=http://www.majorgeeks.com/download506.html][color=blue]Download Here[/color][/url]

Download and install both Spybot S&D and Ad-Aware SE.

Instructions:

[b]Spybot S&D:[/b]
Go to your Start Menu >> Programs >> Spybot S&D >> then choose Spybot S&D.

[b]*[/b]Close [b]ALL [/b]windows except Spybot S&D
[b]*[/b]Click the button to [b]"Search for Updates"[/b] and download and install the Updates.
[b]*[/b]Close Spybot then launch it again
[b]*[/b]Click the button [b]"Check for Problems" [/b]
[b]*[/b]When Spybot is done scanning, it will be showing "RED" (RED) entries, "BLACK" entries and "GREEN" (GREEN) entries in the window
[b]*[/b]Put a check mark beside the RED [color=red](RED) entries ONLY.[/color]
[b]*[/b]Choose "Fix Selected Problems" and allow Spybot to fix the RED [color=red](RED)[/color] entries.


[b]Ad-Aware SE FULL SCAN:[/b]
Go to your Start Menu >> Programs >> Lavasoft Ad-Aware SE >> then choose Ad-Aware SE Personal.

When the main window opens look in the bottom right corner and click on [b]Check For Updates Now[/b] then click Connect and download the latest reference files.

From main window:
[b]*[/b]Click Start then under Select a scan Mode check [b]Perform Full System Scan.[/b]
[b]*[/b]Next [color=red]deselect [/color]Search for negligible risk entries.
[b]*[/b]To scan just click the [b]Next[/b] button.

When the scan has finished [b]mark everything for removal [/b]and get rid of it.
[i](Right-click the window and choose [b]select all[/b] from the drop down menu and click Next)[/i]
The program will ask if you want to fix/delete selected items, choose yes/fix.

[b][4.][/b]
Enable show hidden files and folders:

* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

[b][5.][/b]
[b]Update[/b] your current Virus Scan Definitions:

[b][6.][/b]
Reboot into Safe Mode and [b]Scan[/b] with Spybot S&D and Ad-Aware SE
Then Scan with your Anti-Virus Program

[b][7.][/b]
Delete your temp files:

Navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.

Empty Your Recycle Bin.

[b][8.][/b]
Reboot normally and post a new HJT log by using [b]Post Reply[/b]:

You can download the latest version of HijackThis from my signature.


Thanks,
rstones12





vBulletin Copyright ©2000 - 2003, Jelsoft Enterprises Limited.


PPC Management
vB Easy Archive Final - Created by Xenon