Because newser isn't always better
This is a discussion on Computer Viruses within the General Discussion forums, part of the General Discussion category; I picked up a virus through a hole in my Internet Explorer 6.0 as a hijacking page hijacked my homepage. ...
|
|||||||
| Register | FAQ | Members List | Social Groups | Calendar | Search | Today's Posts | Mark Forums Read |
|
|
#1 (permalink) |
|
Guest
Posts: n/a
|
Windows 98 (4.10.2222 A) Windows dir: C:\WINDOWS Windows system dir: C:\WINDOWS\system AppData folder: C:\WINDOWS\Application Data Username: User Hosts file not present Found CWS.Control (if filesize is over 50k) file: C:\WINDOWS\control.exe (2112 bytes, A) Found CWS.Olehelp file: C:\WINDOWS\olehelp.exe (11776 bytes, A) Registry value: DefaultPrefix (should be http://) [] http:// Registry value: WWW Prefix (should be http://) [www] http:// Registry value: Mosaic Prefix (should be http://) [mosaic] http:// Registry value: Home Prefix (should be http://) [home] http:// Found Win.ini file: C:\WINDOWS\win.ini (8778 bytes, A) Found line in Win.ini: load=essspk.exe Found line in Win.ini: run= Found System.ini file: C:\WINDOWS\system.ini (2101 bytes, A) Found line in System.ini: shell=Explorer.exe - END OF REPORT - |
|
|
|
#2 (permalink) | ||
|
Super Moderator
Join Date: May 2003
Posts: 3,500
|
Quote:
The reason those files probably remain infected, is that your virus scanner is unable to alter them, such as deleting them, as they are inuse while windows is running. A problem with Windows based Anti-Virus apps is they can not alter any files that are currently inuse. So they quarantee the files. If you want to remove the files, you will have to start up the computer is DOS, and remove them. One good program for this is F-Prots DOS Anti-Virus program, which runs in DOS. This can repair, patch, delete any infected files, since the program runs in DOS, so that none of these infected files are loaded into memory. The use of DOS based Anti-Virus programs have this benefit to them that Windows based A/V apps do not have. They are really simple to use also. Just download the F-prot for DOS, unzip it into the root dir, such as into C:\f-prot. make a windows bootup floppy disk. Restart Windows with floppy inserted. Then it will boot up into DOS. on the command line, just type cd \ cd f-prot f-prot.exe pick the options you want, let it scan the system, also note that DOS A/V scanners will be faster than Windows scanner, and also much smaller, the F-prot download is just alittle less than 2megs. Quote:
the esspk.exe might be your soundcard related utility(?) What sound card do you have? an ESSolo? SoundBlaster? the comment about found explorer.exe is normal. this is the shell that windows loads that gives you your start menu, task bar.... your computer needs a hosts file, just create a txt file called hosts in the c:\windows folder. you need to insert just the line localhost 127.0.0.1, this is the loopback address, some program wont work properly without. Use this FREE app to prevent browser hi-jacking http://www.wilderssecurity.net/spywareguard.html also check out the posting on the forum for similar related apps http://www.oldversion.com/talk/index.php?a...t=ST&f=2&t=1405 |
||
|
|
|
|
|
#3 (permalink) |
|
Beta
Join Date: Dec 2003
Location: España
Posts: 217
|
I had a look at the F-prot web-site re. the F-Prot DOS antivirus. It doesn't sound very user friendly, but of course without downloading and trying it, one just can't tell.
I'm probably wrong but isn't a virus scan more effective if it is run in windows safe mode :unsure: |
|
|
|
|
|
#4 (permalink) | |
|
Super Moderator
Join Date: May 2003
Posts: 3,500
|
Quote:
For those users who never seen a commandline prompt, never had to type in a command to execute a program, then I suppose F-port may not be easy for those users, but for someone who has used DOS in the past or present, it's simple to use. I wrote out exactly how to run it in the last posting, if you read it, it really is not that difficult to run. I feel if anyone can use an ATM these days to withdrawl money, they can handle running F-prot. It only looks difficult til you try it. Safe-mode for window's just disables certain drivers for hardware, such as the VGA, sound, ethernet. It is not "safe" from virus. When your in Safe-Mode, your still loading part of the OS into memory, things such as kernel, certain .dlls, .exe's, .drv's. Any number of these could be infected with trojaned or virus's. Which will not be fixed while in-use. So you run the anti-virus app in DOS, not DOS-Mode either, but from a floppy disk with DOS, this way that none of the Systems DOS files are in-use as well. This way absolutely nothing pertaining to the Windows OS is loaded into memeory, so that any and all files can be examined.
Title: Living with F-Prot for DOS Antivirus, might find this write-up useful if planning to run a DOS A/V scanner |
|
|
|
|
|
|
#5 (permalink) | ||
|
Beta
Join Date: Dec 2003
Location: España
Posts: 217
|
Quote:
Quote:
|
||
|
|
|
|
|
#6 (permalink) |
|
Super Moderator
Join Date: May 2003
Posts: 3,500
|
Yes, I do understand that most new computer users will never had the experience of running in DOS. Thats too bad too since there is alot of things you can do in dos that is still faster, and more stable than in Windows.
Yes, running in safe-mode would be better than running in real mode, but DOS mode, for those who can still run in DOS would be better than both. But if your runing XP, then you would have to use safe mode. Just for amusement purposes, I ran a DOS A/V scanner and a Windows A/V scanner, not a scientific with controlled variables either, test, just to see how much difference scanning took. I used F-prot, a DOS scanner, and Free A/V Persion Edition 6 for Windows. I scanned 14,743 files, I ran the DOS scanner from a Windows DOS prompt even. It took 2:02 minutes for the DOS scanner, and over 4 minutes for the Windows scanner to perform the same tests. |
|
|
|
|
|
#7 (permalink) |
|
Guest
Posts: n/a
|
I succesfully downloaded, unzipped, extracted, updated and ran the f-prot antivirus software with some results. It scanned and found only 1 of the 3 infected files that I have. When I ran it , the infected file that it found was the msdos.exe file which says it had a virus name of Backdoor.Jeemp.A. The f-prot software said that the file could not be disinfected, but could only be deleted. Reluctantly I did. My questions are: 1. Do you think that was the right thing to do ? 2. Was the msdos.exe file was essential to properly running Windows ? If so, is there a website available where an .exe file like msdos can be downloaded ? And 4. was the msdos.exe file a junk file created by the author of the virus ? Also, the other infected files were not picked up by f-prot even though I ran it in all 3 available file modes with a very new and fresh update. The other 2 infected files along with the other one which I restored from my virus vault to their original places for the purposes of giving f- prot access to them, are now back in my virus vault until I can decide what to do with them. Do you know of any anti-virus software that can handle these 2 infected files with the names of olehelp.exe which has a virus name of Trojan horse Startpage.3.AR and xwxload.exe which has the virus name of Trojan horse Downloader.X , or should I just delete them ? You were right when you said that the downloading and installation of f-prot was simple. I can say that now because now I have actually done it. But at first, looking at your instructions, I wasn't so sure. I am one those computer users of a new generation, accustomed to new OSs like Windows, but I did it. It took me a little time to find a website that could spell out all of the major and minor details of installing f-prot, complete with pictures correlating to every detail. Anyone needing this website can find it at www.computerjunk.net/fprot.html . I look forward to hearing any ideas. Thank You for all of your help.
|
|
|
|
#8 (permalink) |
|
Super Moderator
Join Date: May 2003
Posts: 3,500
|
The msdos.exe is not a valid MS Windows file. The ONLY files with that similar name that do exist on the system are;
1.) msdos.sys optionally may exist 1.) msdos.inf 2.) msdosdrv.txt So your safe deleting it, as long as it was named MSDOS.exe. More than likely it was a file from the virus/trojan creator to appear as a valid msdos file. If the files were not detected from F-Prot, then it is possible you did not download the updated signature and definiton file? If you did also download those updated files, then you may wish you send a report to the creators of f-prot so they can examine and include those files into the next def file release. I am not aware of the current abilites of any A/V program, as I am not in a habbit of even running a/v apps. I can honestly say in a 10 year span of messing with computer, and not running anti-virus apps, I have only been infect 4 times. And I've been using computers for a much longer time than that. Maybe you can try the additional DOS program mentioned - Bit-Defender, they also do offer a windows version also. If your wanting a free windows a/v app, check in the pinned here http://www.oldversion.com/talk/index.php?a...t=ST&f=2&t=1405 scroll to the bottom of the page and click on the anti-virus link, myself & others have posted links to several free A/V apps. |
|
|
|
![]() |
| Thread Tools | |
|
|
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| The Computer Company Game | jake | General Discussion | 2 | 01-12-2009 01:30 PM |
| Acer Computer Explorer [Win 3.x] | expert01 | Requests | 2 | 12-28-2006 10:40 PM |
| Does Anyone Know How To Format The Computer | steve_majora | General Discussion | 7 | 09-06-2004 10:34 PM |
| Outfiting An Old Computer | Yozuki | General Discussion | 19 | 04-26-2004 07:28 PM |
| Corrupted Ie 6 File On Computer | Linda Hatchett | Programs / Support | 1 | 03-25-2003 08:24 PM |