PDA

View Full Version : Virus


amietron
09-21-2002, 10:05 PM
i don't know what to do to fix it. bigwong directed me to a site to DL norton's anti-virus cus i didn't know where my CD was, but that didn't detect it. i know i've got something on my comp for sure. kasia and bigwong can both tell ya. wow, free porn. cool, free porn. the link it's directed to is my IP followed by 8180. friend said somebody could be hacking into my computer. what do i do to just fix everything so it's back to normal? and lose nothing..

somebody HELLLLLLP, please.

should i attempt to solve this problem myself, or get it fixed by either a friend, computer guy at school, comp shop?
:(

amietron
09-21-2002, 10:07 PM
that's my IP. :(

SunWuKong
09-21-2002, 10:08 PM
you said earlier that one of your instant messengers is sending out IMs all on its own. which one is it and have you tried uninstalling it?

ren28
09-22-2002, 12:42 AM
I need more info about the problem.

amietron
09-22-2002, 01:07 AM
havent tried to re-install. happens on AIM and AOL.

SunWuKong
09-22-2002, 09:01 AM
Originally posted by amietron@Sep 22 2002, 04:07 AM
havent tried to re-install. happens on AIM and AOL.
do you use AOL as your ISP?

amietron
09-23-2002, 08:22 PM
yes

SunWuKong
09-23-2002, 08:38 PM
ok it sounds like this is what you have

http://vil.nai.com/vil/content/v_99437.htm


this is what i suggest:

1) uninstall AIM

2) remove all the files that the above page lists under "Symptoms"

3) edit the registry to get rid of the entry that was added by the worm (the page above lists the entry)... this might not be intuitive for someone who has never done this. you need to be very careful. go to "Start" -> "Run..." -> type in "regedit" and press enter. there should be a directory of registry entries. you need to find the one that was added by the worm and delete it. again, be careful not to delete something that was actually useful.

4) restart the computer

any problems send me a PM with your hotmail address (for MSN messenger) or ICQ #.

ren28
09-27-2002, 04:42 AM
Be careful with the registry... if you jack that up, the OS may not start again. :blink:

BaiginLong
12-02-2002, 10:30 AM
very very careful indeed
you mess that up and it'd take a freak like me to get it working again without formatting and the whole enchilada
:nerd:
I have about 11 years (been fixing computers ever since I laid hands on them as a 7 year old. been fixing computers for my schools since 5th grade) of experience honey and I know that Windows registry editing is a bizznach sometimes

himura-dono
12-03-2002, 03:06 AM
unless she has xp pro....^_^ in which case, dial back the way back machine, lol and chill in the xp pro goodness...

editing registry isn't THAT hard...i'm a software moron and i can do it. if you have a hardware problem, i can handle that ^_^

Azn Retribution
12-03-2002, 12:22 PM
that url followed by a 8180 or anything similar directs you to a server that takes advantage of a security hole in windows and installs a backdoor similar to subseven. it is not a virus per se..
more of a program that allows people to connect your computer(providing you are not behind a firewall) and take control.

It is most commonly encountered in IRC but occasionally pops up from IMbots.
mostly just lil script kiddy wannabe hackers use it.
very few real hackers actually exist now...
just more of script kiddies getting all the media attention.

Download Norton or some similar virus scanner will get rid of it for you.
a backdoor does not do anything on its own as compared to a real virus
a virus follows a set of instructions usually bent on messing up your computer.