View Full Version : Possible Virus, please help


pietro
19-02-2005, 10:09
My desktop (running XP) was fine yesterday morning, logged on last night and some desktop icons would not colour in and will not open, the icons are followed by the letters .lnk

I cannot run any spyware or virus programs to check for any problems, they will not open. I have downloaded and ran Trend Micro but nothing found. I can only access system restore in safe mode. Restored to two previous dates but no change.

I did notice that Ad-Watch had noticed registry changes but this is another program I can no longer open.

Help!

wendy
19-02-2005, 11:29
That definately sounds like a virus to me. Never had that problem myself so donīt know what to suggest but it sounds like it has written itself into your registry. Martin S would be one of the best people to contact or JoeP . Sorry I canīt help but hope someone else can.

Strix
19-02-2005, 11:42
Look vidster up and click on cbttechs in his signature. It's a transatlantic techie forum. They're usually very helpful too.

max
19-02-2005, 11:43
Have you tried doing a restore back to a previous day?

Strix
19-02-2005, 11:59
Originally posted by pietro
....Restored to two previous dates but no change...

Help!

Cyclone
19-02-2005, 13:04
sounds more like the file associations have been screwed up than a virus.

Shortcuts are represented by files with a .lnk extension. if windows no longer understands that extension then it will just show the files.

Here (http://twinto.web1000.com/files/fileass/linkfile_fix.zip) is a fix, download it, extract it, right click and select import into registry. This will restore the .lnk file association.

pietro
19-02-2005, 13:58
Cyclone, tried the link , got various pages but I suspect not the one that you mean Or is it just me.

Nutronic
19-02-2005, 14:02
Originally posted by pietro
Cyclone, tried the link , got various pages but I suspect not the one that you mean Or is it just me.

Have you tried going to your av/spyway program directly....as in through my computer etc?

Also try microsofts malicious removal tool, if you have anything malicious, it will find it.....

here is where u'll get it (http://www.microsoft.com/downloads/details.aspx?FamilyID=ad724ae0-e72d-4f54-9ab3-75b8eb148356&displaylang=en)

pietro
19-02-2005, 14:54
In my first you will see that I mention Ad Watch. After searching all day, I have found out that there is a big problem with this program. See link:

http://www.lavasoftsupport.com/index.php?showtopic=56503

It seems this problem has been going on for a while now and I am one of this programs latest victims.

I have tried the various methods mentioned to restore my system but to no success. It looks like I will be re- installing the OS this weekend.

Adaware/Adwatch users take note.

JoeP
19-02-2005, 15:02
Hmmmm...

I've used Adaware for yonks on two or three PCs here at The Towers and haven't had any real problems.

However, I've not been using it on XP....

Joe

vidster
19-02-2005, 15:04
My first action (after ruling out viruses etc) would be to try running sfc scannow.

START> RUN> type: sfc scannow (Note the space)> ENTER

You will need your xp disk.

If that didn't work i would then consider performing a repair install of the Operating System by following the instructions HERE (http://www.cbttechs.com/forums/showthread.php?t=455).

This will re-install XP and you shouldn't loose anything.

Hope this helps ;)

JoeP
19-02-2005, 15:05
Hmmmm...

I've used Adaware for yonks on two or three PCs here at The Towers and haven't had any real problems.

However, I've not been using it on XP....

At the risk of sounding dim, have you tried renaming the .lnk files by simply taking the .lnk off the end?

I know it's a pain in the bum but it might be easier than reinstalling everything.

Joe

Cyclone
19-02-2005, 15:25
you're right, that's not what the link was supposed to take you too.

Renaming the .lnk files won't solve anything, .lnk is the correct extension for a windows shortcut file, the problem is that windows has lost the association so it doesn't know what the .lnk extension means anymore.

Do a search on google for "restore .lnk shortcut association" maybe you can find one that is genuine (unlike the one I posted originally).

Draggletail
19-02-2005, 15:50
Originally posted by JoeP
Hmmmm...

I've used Adaware for yonks on two or three PCs here at The Towers and haven't had any real problems.

However, I've not been using it on XP....

Joe

I have used Adaware on XP for six months or so, no problems (so far)...

Strix
19-02-2005, 21:20
Does this (http://securityresponse.symantec.com/avcenter/venc/data/w32.derdero.b@mm.html) look like your symptoms?

pietro
20-02-2005, 07:57
strix ays: Does this look like your symptoms?

No nothing like them. Also I've managed to do an online scan with Trend Micro, nothing found. Would it have picked it up?

cgksheff
20-02-2005, 09:52
I think you answered your own question, pietro, and that Ad-Watch is the most likely culprit. As mentioned in your other thread, this software has the ability to caused massive corruption when running at the same time as other system software.