Plateforme Level Extreme
Abonnement
Profil corporatif
Produits & Services
Support
Légal
English
April Fools Day Conflicker C Virus Warning
Message
De
31/03/2009 12:19:34
 
 
À
31/03/2009 12:16:48
Information générale
Forum:
Visual FoxPro
Catégorie:
Problèmes
Versions des environnements
Visual FoxPro:
VFP 9 SP1
OS:
Windows XP SP2
Network:
Windows 2003 Server
Database:
MS SQL Server
Application:
Desktop
Divers
Thread ID:
01392337
Message ID:
01392420
Vues:
52
>>>>>>>>>The program could delete all of the files on a person's computer, use zombie PCs -- those controlled by a master -- to overwhelm and shut down Web sites or monitor a person's keyboard strokes to collect private information like passwords or bank account information, experts said.
>>>>>>>>>
>>>>>>>>>http://www.cnn.com/2009/TECH/03/24/conficker.computer.worm/
>>>>>>>>>
>>>>>>>>>It was on the local news again today. Supposedly, if you can navigate to the most popular anti-virus sites, then you are not infected. One of the things it does is block those sites.
>>>>>>>>
>>>>>>>>The symptoms described are very similar to teh problems I had a few weeks ago. Windows and AVG auto. updates were disabled, any attempt to manually go to their sites and download - I was getting "Cannot access page" type messages.
>>>>>>>>
>>>>>>>>I had a hell of a time immunizing agin it and now my pc is thrashing the disk constantly, and everything takes forever (eg you can wait 5+ minutes for Firefox to load up, closing or minimising a window you see it happen in slow motion)
>>>>>>>>
>>>>>>>>I haven't a clue what's thrashing the disk all the time. There are several AVG????.??? processes on the go now since, but I can't ID what's what.
>>>>>>>>
>>>>>>>>In short my pc is practically unusable co0s it takes an age to do anything.
>>>>>>>>
>>>>>>>>BTW if anyone has any insight to this I'd appreciate it. I'm, of course, not on my home m/c at the mo.
>>>>>>>>
>>>>>>>>AFAIK I've not got any of teh other tools I used to get rid of the malware (eg PC Doctor et al) set as running (and clashing with AVG) but there seems to be some fishy looking anti-virus resident processes going on.
>>>>>>>
>>>>>>>Have you applied the security patches?
>>>>>>>http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
>>>>>>>
>>>>>>>Considered settings (don't know if Conflicker.C same as Conflicker.B):
>>>>>>>http://support.microsoft.com/kb/962007
>>>>>>>
>>>>>>>And run the malware removal tool?
>>>>>>>http://www.microsoft.com/security/malwareremove/default.mspx
>>>>>>>
>>>>>>>And definitely read this:
>>>>>>>http://forums.mcafeehelp.com/showthread.php?p=540778
>>>>>>
>>>>>>Thanks for that, Tracy, but, as I said, I threw everything that I could/had been recommended/etc at the problem and now I get my Windows and AVG updates and all is up-to-date protection-wise. At the end of "chemotherapy" I gave the m/c it did a MARATHON Windows security update, lasting hours - feasting on all the updates it had missed during the illness. I don't see how the above can explain the thrashing.
>>>>>>

UPDATE

Tonight I removed PC Doctor. It was taking an age to start up and using huge resources. CPU usage was peaking 70-80 % sometimes, after idling at 2-3. Disk thrashing all the time. Now after reboot disk quite quiet. I guess it had done its job in curing the pc but no room anymore to compete with AVG. Looks promising.

Windows Firewall BTW. Hadn't been disabled this reboot, so I'm hopeful.

Took disk compression and file indexing off C: and as I closed the dialogue I had to laugh as another popped up saying that the process was to take 4 days 11 hours LOL. I cancelled it but, after the reboot, props says these options are off.

Just ran the Windows mal s/w rem tool. Pretty sure I had already but I couldn't find the installer exe on my hd so ran anyway. No bad found so I feel pretty good at the mo :-)

END UPDATE

>>>>>>The point is that it seems to have come out of all this slow and useless. It's like it could have turned absolutely paranoid and EVERYTHING is being constantly checked, as if, say, more than one virus checker is going all the time. But I only have AVG active. Again, there seems to be a proliferation of AVG background processes going on (whereas there used to be just the resident shield and temporarily teh AVG updater)
>>>>>
>>>>>Is Windows Defender running as well? I noticed a serious performance lag when SpySweeper, AVAST anti-virus, and Windows Defender are all running (but only with some versions).
>>>>
>>>>Yes but none of the rest (but AVG of course).
>>>>
>>>>I do notice that SOMETHING keeps switching off my firewall. Each time I turn on I get the security warning and have to go back through the "recommendations" route and switch it back on. Would love to know what switches it off and why (even when not online) :-(
>>>
>>>Recommendations (you've probably done them all):
>>>
>>>What firewall are you using? I use Commodo. Check the event viewer for firewall entries.
>>>
>>>Run AdAware in failsafe mode with networking, download the latest definitions, then do a full scan.
>>>
>>>Run SpywareBlaster or SpySweeper (immunize and scan to remove).
>>>
>>>Post your issue in the SysInternals.com forum.
>>>
>>>Do a boot-time scan with your anti-virus.
>>>
>>>Run malwarebyte's anti-malware to remove all malware.
>>>
>>>Run avast antirootkit or Trend Micro RootkitBuster.
>>
>>Thanks Tracy
>>
>>I've done several of the malware removal sweeps with different products. I think I have a problem with not enough RAM or disk space left. I'm gonna try taking indexing off and disk compression - see if that helps in the first instance. Some of your recog's above I have not tried. May get round to running them too.
>
>The 'firewall shutting down' is the issue that most concerns me. It looks like a trojan.

Sorry can't remember which one I use now - I've had so many products on the m/c of late.
- Whoever said that women are the weaker sex never tried to wrest the bedclothes off one in the middle of the night
- Worry is the interest you pay, in advance, for a loan that you may never need to take out.
Précédent
Répondre
Fil
Voir

Click here to load this message in the networking platform