Outline ·
[ Standard ] ·
Linear+
what happened .. is this due to virus?, -- need helps --
|
TSots
|
Dec 6 2006, 10:00 PM, updated 20y ago
|
Getting Started

|
My antivirus prgm expired this am without me noticing.
What is happening now: i tried to download the free AVG version but the moment i click the web site from google, my IE or firefox will shut down automatically. But I can still browse web page of any other sites, so long it got nothing to do with antivirus prgm download.
Alternatively, I tried to install the antivirus software from disk (ahem version), but the moment i click the program set-up, the window explorer just close by itself and there is no way that i could install any progm.
What's happening?
What do i do now?
Thank you!
|
|
|
|
|
|
natakaasd
|
Dec 6 2006, 11:31 PM
|
|
You are having a malware infection. Please attach a HijackThis Log. People can help you from there. Cheers!
|
|
|
|
|
|
hkpoh
|
Dec 7 2006, 02:15 AM
|
|
This is the old news http://www.zdnet.com.au/news/security/soa/...39187608,00.htmHere is the solution, try that if your are in a bad sitituation. http://antivirus.about.com/cs/allabout/a/mydoomb.htmJust a quick check if your pc is infected by MYdoom. 1) Go to search and key in this "hosts.ini" and start seaching 2) then double click the hosts.ini and open it with notepad, if you cant find it, then it might b a hidden file, so unattribe it first and then search again 3) if your hosts.ini having below or any of below line, then it means your pc is infected by Mydoom. And so everyone be able to help ya. ad.doubleclick.net ad.fastclick.net ads.fastclick.net ar.atwola.com atdmt.com avp.ch avp.com avp.ru awaps.net banner.fastclick.net banners.fastclick.net ca.com click.atdmt.com clicks.atdmt.com dispatch.mcafee.com download.mcafee.com download.microsoft.com downloads.microsoft.com engine.awaps.net fastclick.net f-secure.com ftp.f-secure.com ftp.sophos.com go.microsoft.com liveupdate.symantec.com mast.mcafee.com mcafee.com media.fastclick.net msdn.microsoft.com my-etrust.com nai.com networkassociates.com office.microsoft.com phx.corporate-ir.net secure.nai.com securityresponse.symantec.com service1.symantec.com sophos.com spd.atdmt.com support.microsoft.com symantec.com update.symantec.com updates.symantec.com us.mcafee.com vil.nai.com viruslist.ru windowsupdate.microsoft.com www.avp.ch www.avp.com www.avp.ru www.awaps.net www.ca.com www.fastclick.net www.f-secure.com www.kaspersky.ru www.mcafee.com www.microsoft.com www.my-etrust.com www.nai.com www.networkassociates.com www.sophos.com www.symantec.com www.trendmicro.com www.viruslist.ru www3.ca.com
|
|
|
|
|
|
eXPeri3nc3
|
Dec 7 2006, 08:57 AM
|
|
QUOTE(hkpoh @ Dec 7 2006, 03:15 AM) This is the old news http://www.zdnet.com.au/news/security/soa/...39187608,00.htmHere is the solution, try that if your are in a bad sitituation. http://antivirus.about.com/cs/allabout/a/mydoomb.htmJust a quick check if your pc is infected by MYdoom. 1) Go to search and key in this "hosts.ini" and start seaching 2) then double click the hosts.ini and open it with notepad, if you cant find it, then it might b a hidden file, so unattribe it first and then search again 3) if your hosts.ini having below or any of below line, then it means your pc is infected by Mydoom. And so everyone be able to help ya. ad.doubleclick.net ad.fastclick.net ads.fastclick.net ar.atwola.com atdmt.com avp.ch avp.com avp.ru awaps.net banner.fastclick.net banners.fastclick.net ca.com click.atdmt.com clicks.atdmt.com dispatch.mcafee.com download.mcafee.com download.microsoft.com downloads.microsoft.com engine.awaps.net fastclick.net f-secure.com ftp.f-secure.com ftp.sophos.com go.microsoft.com liveupdate.symantec.com mast.mcafee.com mcafee.com media.fastclick.net msdn.microsoft.com my-etrust.com nai.com networkassociates.com office.microsoft.com phx.corporate-ir.net secure.nai.com securityresponse.symantec.com service1.symantec.com sophos.com spd.atdmt.com support.microsoft.com symantec.com update.symantec.com updates.symantec.com us.mcafee.com vil.nai.com viruslist.ru windowsupdate.microsoft.com www.avp.ch www.avp.com www.avp.ru www.awaps.net www.ca.com www.fastclick.net www.f-secure.com www.kaspersky.ru www.mcafee.com www.microsoft.com www.my-etrust.com www.nai.com www.networkassociates.com www.sophos.com www.symantec.com www.trendmicro.com www.viruslist.ru www3.ca.com Very informative, but how sure are you it's mydoom? There are tons of virus that has the capability on modifying hosts file to redirect once you reach a AV site.
|
|
|
|
|
|
natakaasd
|
Dec 7 2006, 10:49 AM
|
|
I agree with eXPeri3nc3. But assuming that the TS mentioned about unsuccessful installation of AVs. I guess, it is possible to deduce which type or which malware in particular is playing pranks.
Anyway, TS, please post a HijackThis Log. No point keeping us all in a limbo. Cheers!
|
|
|
|
|
|
TSots
|
Dec 7 2006, 09:05 PM
|
Getting Started

|
QUOTE(natakaasd @ Dec 7 2006, 10:49 AM) Anyway, TS, please post a HijackThis Log. No point keeping us all in a limbo. Cheers! thanks all ... sorry for this question how to go about and get this Hijack This Log?
|
|
|
|
|
|
hkpoh
|
Dec 7 2006, 09:25 PM
|
|
I had mydoom before, so when reading this thread, i assume it's mydoom, anywhere it's no harm to try.
|
|
|
|
|
|
natakaasd
|
Dec 7 2006, 10:57 PM
|
|
Download the File from here. Scan then create a log. Please attach it. Cheers!
|
|
|
|
|