This just showed up in my task list as of a few days ago, and I've read that if you have XP then it is a virus. We are using McAfee(always updated) and are still managing to get trojans left and right! The last one was the "byteverify" and I used mcafee to delete it. There were no other traces of the virus but one file.. and the rundll32.exe continues to show up in the task list on restart. Why is mcafee not catching these until I manually do a scan..and how the he%$ do I get rid of this one. I did run adaware and found some disturbing spyware that I deleted.. it also showed back up on rescan, and I couldn't find anything in the registry. SO FRUSTRATING!
Welcome to the Dell Community Forum (DCF).
REMINDER - Even if you know the sender, never open attachments until you have scanned them with a virus checker
(1) RUN THIS VIRUS CHECKER
* Go here
http://housecall.antivirus.com
* Click "Scan Now. It's Free!"
* Choose your country, click Go
* Give it 5 or 10 minutes to build the first time
* Put checks by your hard disk drive, floppy, or zip disk letters
(whatever needs scanning)
* Click "Scan" and "Autoclean"
* Close all boxes when finished
* Click Start- Windows Updates
* Click Scan for Updates
* Load all Critical Updates
* When finished close all boxes
* If you have identified a virus, go here to find a remover:
http://www.sarc.com/avcenter/tools.list.html
(2) SPECIFIC VIRUS REMOVAL TOOLS
* Go here for cleaning tools:
http://www.beforeyoukillyourcomputer.com/virus.htm
* On the right, scroll down to Removal Tools
* Click your virus. Download the tool and follow it's instructions
(3) DOWNLOAD/INSTALL SPYBOT SEARCH & DESTROY
* Go here:
http://www.safer-networking.org/index.php?page=mirrors
* After Downloading and installing SpyBot Search & Destroy, first press Online, and search for, put a check mark at, and install all updates
* Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds
(4) DOWNLOAD/INSTALL HIJACK THIS
* Go here:
http://tomcoyote.com/hjt
* Unzip Hijackthis.zip into a new folder you create in the root (first) level of the C: drive
* Name this folder HJT (don't unzip it into a temp folder or run the file from a temp folder, or the Windows Desktop, etc...as it needs a safe folder to keep backup logs). Also when people post here and place it on the Desktop the log usually shows their full name since their Windows user profile is commonly named with their full name
* Go here to see graphical instructions:
http://russelltexas.com/spywareinfo/createhjtfolder.htm
* Run Hijackthis, click on the 'scan' button and then 'save log' button
* Copy and paste the contents of the text file you save into a reply to this message
* Do NOT fix anything in the Hijackthis log screen without assistance from the experts
* Go here to post your HiJack This log if the experts do not answer on the Dell Community Forum:
http://www.spywareinfo.com/forums/index.php?showforum=30
* Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system
Thank you for your response and help! Here is the log:
Logfile of HijackThis v1.97.7 Scan saved at 2:52:29 PM, on 6/14/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
/* Do not edit this file. * * If you make changes to this file while the browser is running, * the changes will be overwritten when the browser exits. * * To make a manual change to preferences, you can visit the URL about:config * For more information, see http://www.mozilla.org/unix/customizing.html#prefs */
Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.
Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.
Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.
Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.
I also like to run Windows Disk Cleanup after cleaning with those two tools. Make sure you reboot if any reboot cleanup functions of Spybot and Adaware are advised by these tools (this may happen at the end of their cleanup).
Run Disk Cleanup: type cleanmgr at Start/Run. Scan all hard drives and check all categories at the end and click OK.
If you have any problems with Disk Cleanup completing...XP users can fix it here:
Reboot and browse a bit and post a new Hijackthis log.
Special comments: I would also uninstall Kodak EasyShare and Wild Tangent in Control Panel/Add Remove Programs. Not allowed on my machines!
All the best,
Texruss www.russelltexas.com Spyware Fighter Wilders Forum Slyware Warrior Tom Coyote Forum Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.
DELL-Chris M
Community Manager
•
56891 Posts
•
232143 Points
683
0
Posted June 14th, 2004 17:00
Welcome to the Dell Community Forum (DCF).
REMINDER - Even if you know the sender, never open attachments until you have scanned them with a virus checker
(1) RUN THIS VIRUS CHECKER
* Go here
http://housecall.antivirus.com
* Click "Scan Now. It's Free!"
* Choose your country, click Go
* Give it 5 or 10 minutes to build the first time
* Put checks by your hard disk drive, floppy, or zip disk letters
(whatever needs scanning)
* Click "Scan" and "Autoclean"
* Close all boxes when finished
* Click Start- Windows Updates
* Click Scan for Updates
* Load all Critical Updates
* When finished close all boxes
* If you have identified a virus, go here to find a remover:
http://www.sarc.com/avcenter/tools.list.html
(2) SPECIFIC VIRUS REMOVAL TOOLS
* Go here for cleaning tools:
http://www.beforeyoukillyourcomputer.com/virus.htm
* On the right, scroll down to Removal Tools
* Click your virus. Download the tool and follow it's instructions
(3) DOWNLOAD/INSTALL SPYBOT SEARCH & DESTROY
* Go here:
http://www.safer-networking.org/index.php?page=mirrors
* After Downloading and installing SpyBot Search & Destroy, first press Online, and search for, put a check mark at, and install all updates
* Next, close all Internet Explorer windows, hit 'Check for Problems', and have SpyBot remove all it finds
(4) DOWNLOAD/INSTALL HIJACK THIS
* Go here:
http://tomcoyote.com/hjt
* Unzip Hijackthis.zip into a new folder you create in the root (first) level of the C: drive
* Name this folder HJT (don't unzip it into a temp folder or run the file from a temp folder, or the Windows Desktop, etc...as it needs a safe folder to keep backup logs). Also when people post here and place it on the Desktop the log usually shows their full name since their Windows user profile is commonly named with their full name
* Go here to see graphical instructions:
http://russelltexas.com/spywareinfo/createhjtfolder.htm
* Run Hijackthis, click on the 'scan' button and then 'save log' button
* Copy and paste the contents of the text file you save into a reply to this message
* Do NOT fix anything in the Hijackthis log screen without assistance from the experts
* Go here to post your HiJack This log if the experts do not answer on the Dell Community Forum:
http://www.spywareinfo.com/forums/index.php?showforum=30
* Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system
DELL-Chris M (old account)
#IWork4Dell