Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 what happened .. is this due to virus?, -- need helps --

views
     
TSots
post Dec 6 2006, 10:00 PM, updated 20y ago

Getting Started
**
Junior Member
113 posts

Joined: Dec 2004
My antivirus prgm expired this am without me noticing.

What is happening now: i tried to download the free AVG version but the moment i click the web site from google, my IE or firefox will shut down automatically. But I can still browse web page of any other sites, so long it got nothing to do with antivirus prgm download.

Alternatively, I tried to install the antivirus software from disk (ahem version), but the moment i click the program set-up, the window explorer just close by itself and there is no way that i could install any progm.

What's happening?

What do i do now?

Thank you!
natakaasd
post Dec 6 2006, 11:31 PM

Look at all my stars!!
*******
Senior Member
2,188 posts

Joined: Nov 2005


You are having a malware infection. Please attach a HijackThis Log. People can help you from there. Cheers!
hkpoh
post Dec 7 2006, 02:15 AM

Casual
***
Junior Member
311 posts

Joined: Jul 2005
From: Negeri Sembilan


This is the old news
http://www.zdnet.com.au/news/security/soa/...39187608,00.htm

Here is the solution, try that if your are in a bad sitituation.
http://antivirus.about.com/cs/allabout/a/mydoomb.htm

Just a quick check if your pc is infected by MYdoom.
1) Go to search and key in this "hosts.ini" and start seaching
2) then double click the hosts.ini and open it with notepad, if you cant find it, then it might b a hidden file, so unattribe it first and then search again
3) if your hosts.ini having below or any of below line, then it means your pc is infected by Mydoom. And so everyone be able to help ya.

ad.doubleclick.net
ad.fastclick.net
ads.fastclick.net
ar.atwola.com
atdmt.com
avp.ch
avp.com
avp.ru
awaps.net
banner.fastclick.net
banners.fastclick.net
ca.com
click.atdmt.com
clicks.atdmt.com
dispatch.mcafee.com
download.mcafee.com
download.microsoft.com
downloads.microsoft.com
engine.awaps.net
fastclick.net
f-secure.com
ftp.f-secure.com
ftp.sophos.com
go.microsoft.com
liveupdate.symantec.com
mast.mcafee.com
mcafee.com
media.fastclick.net
msdn.microsoft.com
my-etrust.com
nai.com
networkassociates.com
office.microsoft.com
phx.corporate-ir.net
secure.nai.com
securityresponse.symantec.com
service1.symantec.com
sophos.com
spd.atdmt.com
support.microsoft.com
symantec.com
update.symantec.com
updates.symantec.com
us.mcafee.com
vil.nai.com
viruslist.ru
windowsupdate.microsoft.com
www.avp.ch
www.avp.com
www.avp.ru
www.awaps.net
www.ca.com
www.fastclick.net
www.f-secure.com
www.kaspersky.ru
www.mcafee.com
www.microsoft.com
www.my-etrust.com
www.nai.com
www.networkassociates.com
www.sophos.com
www.symantec.com
www.trendmicro.com
www.viruslist.ru
www3.ca.com
eXPeri3nc3
post Dec 7 2006, 08:57 AM

It's coming! 3ɔu3ıɹǝdxǝ ♥
*******
Senior Member
9,257 posts

Joined: Aug 2005
From: Not so sure myself Status: 1+3+3=7



QUOTE(hkpoh @ Dec 7 2006, 03:15 AM)
This is the old news
http://www.zdnet.com.au/news/security/soa/...39187608,00.htm

Here is the solution, try that if your are in a bad sitituation.
http://antivirus.about.com/cs/allabout/a/mydoomb.htm

Just a quick check if your pc is infected by MYdoom.
1) Go to search and key in this "hosts.ini" and start seaching
2) then double click the hosts.ini and open it with notepad, if you cant find it, then it might b a hidden file, so unattribe it first and then search again
3) if your hosts.ini having below or any of below line, then it means your pc is infected by Mydoom. And so everyone be able to help ya.

ad.doubleclick.net
ad.fastclick.net
ads.fastclick.net
ar.atwola.com
atdmt.com
avp.ch
avp.com
avp.ru
awaps.net
banner.fastclick.net
banners.fastclick.net
ca.com
click.atdmt.com
clicks.atdmt.com
dispatch.mcafee.com
download.mcafee.com
download.microsoft.com
downloads.microsoft.com
engine.awaps.net
fastclick.net
f-secure.com
ftp.f-secure.com
ftp.sophos.com
go.microsoft.com
liveupdate.symantec.com
mast.mcafee.com
mcafee.com
media.fastclick.net
msdn.microsoft.com
my-etrust.com
nai.com
networkassociates.com
office.microsoft.com
phx.corporate-ir.net
secure.nai.com
securityresponse.symantec.com
service1.symantec.com
sophos.com
spd.atdmt.com
support.microsoft.com
symantec.com
update.symantec.com
updates.symantec.com
us.mcafee.com
vil.nai.com
viruslist.ru
windowsupdate.microsoft.com
www.avp.ch
www.avp.com
www.avp.ru
www.awaps.net
www.ca.com
www.fastclick.net
www.f-secure.com
www.kaspersky.ru
www.mcafee.com
www.microsoft.com
www.my-etrust.com
www.nai.com
www.networkassociates.com
www.sophos.com
www.symantec.com
www.trendmicro.com
www.viruslist.ru
www3.ca.com
*
Very informative, but how sure are you it's mydoom?
There are tons of virus that has the capability on modifying hosts file to redirect once you reach a AV site.
natakaasd
post Dec 7 2006, 10:49 AM

Look at all my stars!!
*******
Senior Member
2,188 posts

Joined: Nov 2005


I agree with eXPeri3nc3. But assuming that the TS mentioned about unsuccessful installation of AVs. I guess, it is possible to deduce which type or which malware in particular is playing pranks.

Anyway, TS, please post a HijackThis Log. No point keeping us all in a limbo.
Cheers!
TSots
post Dec 7 2006, 09:05 PM

Getting Started
**
Junior Member
113 posts

Joined: Dec 2004
QUOTE(natakaasd @ Dec 7 2006, 10:49 AM)

Anyway, TS, please post a HijackThis Log. No point keeping us all in a limbo.
Cheers!
*
thanks all ... sorry for this question wub.gif

how to go about and get this Hijack This Log?
hkpoh
post Dec 7 2006, 09:25 PM

Casual
***
Junior Member
311 posts

Joined: Jul 2005
From: Negeri Sembilan


I had mydoom before, so when reading this thread, i assume it's mydoom, anywhere it's no harm to try.
natakaasd
post Dec 7 2006, 10:57 PM

Look at all my stars!!
*******
Senior Member
2,188 posts

Joined: Nov 2005


Download the File from here.

Scan then create a log. Please attach it. Cheers!

 

Change to:
| Lo-Fi Version
0.0151sec    1.11    5 queries    GZIP Disabled
Time is now: 24th December 2025 - 10:42 PM