Announcement

Collapse
No announcement yet.

I know this isnt the right forum but...

Collapse
This topic is closed.
X
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • I know this isnt the right forum but...

    Ok here is the thing. I had one main user on Windows XP Pro. Well the passed day or so it would not let me open up ANY EXE flies nothing, it wouldnt let me open up a .TXT flie. I started in safe mode and let it scan my PC and here is what it found.
    Attached Files

    You think you're the best, but there is always someone better.

  • #2
    oi..one of those is msn messenger it looks like..i hope i dont catch one of those :dead: :sweat:
    (ノ ゜Д゜)ノ ====【†】 BIBLE FIGHT !
    sigpic

    Comment


    • #3
      this is what it says ANYTIME i try to run an EXE on my admin user.
      Restrictions
      "This operation has been cancelled due to Restrictions in effect on this computer. Please contact your system administrator."

      You think you're the best, but there is always someone better.

      Comment


      • #4
        Come on you all with almost 40 ppl looking at this post I know someone has something to say bout it..... Or can help me on this.

        You think you're the best, but there is always someone better.

        Comment


        • #5
          Originally posted by Zynk
          Come on you all with almost 40 ppl looking at this post I know someone has something to say bout it..... Or can help me on this.
          As ruffry said, one of the files is MSN Messenger, not sure about the other.

          Allow the program to quarantine the files, reboot and then try running stuff in standard mode. If it still does stuff, the only thing I can think of is to reformat and reinstall.

          Here's what that particular virus does:

          Worm/Randex

          The exact description is not available.

          This type of virus spreads across local networks or through internet via shares disks. The virus searches for computers in its "neighborhood" with shared network drives and then copies itself on them.

          For prevention as far as possible do not share whole disks, but only selected folders. It is also advisable to use passwords on shared folders.

          We recommend you remove binding to "File and printer sharing" in Bindings Tab under TCP/IP Properties for all TCP/IP protocols (the TCP/IP protocol is usually defined for every LAN or Dial-Up adapter).


          Peer-to-peer networks

          Next most common method of spreading is by "peer-to-peer" networks (like KaZaA), the virus creates a few copies of itself in folders within the P2P shared system. If these files have got alluring names then there is a good chance somebody will download these files and execute them.
          And Norton/Symantec's site has this to say about it.

          Common characteristics of the W32.Randex family include:


          Spreading through network shares
          Attacking randomly generated IP addresses
          Using default credentials or weak username/password pairs to connect to a remote target system
          Opening backdoor ports
          Opening connections to predetermined IRC servers and waiting for commands from an attacker
          Performing Denial of Service (DoS) attacks
          Sounds pretty nasty, but doesn't seem to be the root of your problem. The screenshot you posted says that there are 3files that are infected - I can see two at the bottom but is there any chance you can get another grab of what the other infected file was (the one that was cleaned)?

          Comment


          • #6
            I dont know what to do. There is a lot of odd things going on. Like when I try to open any kinda EXE flie like when I try to click on the "E" for Internet Explorer it will say.

            Restrictions
            "This operation has been cancelled due to restrictions in effect on this computer. Please contact your system administrator."

            something else I cant understand is that. If I go to Favorites and click on all the shortcuts I have got saved they ALL work fine, and I have a keyb that lets you hit one key to go to your email or go to the web/home and it works just fine. It's just when I try to run any type of EXE file like PhotoShop or something like that. It will say the same thing like above. It also does this on MP3 flies and any type of video files.

            You think you're the best, but there is always someone better.

            Comment


            • #7
              This is a tough one. What you have is a BAD case of spyware. They're not considered viruses although they can sometimes certainly act that way. Here's what I would try...

              Create another user account. The reason being is that sometimes spyware isn't transfered from acct to acct. Go to www.download.com and get a program called Spybot Search and Destroy. Even from another acct it should find the registry key's associated with the spyware and you should be able to get rid of your problems that way.

              Another option is to hit Start->Run->Type in regedit

              Do a search for MemWatcher and delete anything and everything associated with MemWatcher.

              The other option is an unfortunate one. Format and reinstall. I'm not sure where you purchased your system, I built mine, but either way you'll either insert a disc titled "System Recovery Disk" or "Win XP" install disc. You'll lose everything but that, as far as I can see, is your only other option. Do a complete install. Let the disk format your HD. Do not do a repair or simple recovery.
              I don't know half of you half as well as I should like, and I like less than half of you half as well as you deserve. -JRR Tolkein

              Better to keep your mouth shut and appear stupid than open it and remove all doubt. - Mark Twain

              Comment


              • #8
                Well I have been useing them SpyBot S&D, Ad-Ware and Norton, it seems like Norton wont fix anything or delete it. Do you all know of any other good AntiVirus software? I have made the new acct it seems to be working and I deleted the old acct.

                You think you're the best, but there is always someone better.

                Comment


                • #9
                  AVG. It's good and it's free.
                  I don't know half of you half as well as I should like, and I like less than half of you half as well as you deserve. -JRR Tolkein

                  Better to keep your mouth shut and appear stupid than open it and remove all doubt. - Mark Twain

                  Comment


                  • #10
                    Where can I find it at?

                    You think you're the best, but there is always someone better.

                    Comment


                    • #11
                      I used this new piece of technology we call a "search engine" to find it.

                      http://www.grisoft.com/

                      Comment


                      • #12
                        www.download.com is always good. The oft forgoten www.tucows.net is a good one too.
                        I don't know half of you half as well as I should like, and I like less than half of you half as well as you deserve. -JRR Tolkein

                        Better to keep your mouth shut and appear stupid than open it and remove all doubt. - Mark Twain

                        Comment

                        Working...
                        X