//flex table opened by JP

Click to See Complete Forum and Search --> : virus


tksanchez
01-06-2003, 10:34 PM
I dont know if this is in the right area, but here goes. I think I have unknowingly downloaded a virus or worm on my computer. The name of the file is cheeseburger.exe and is running in my taskmanager using 3404k of memory. I ran Trends Housecall virus scanner and it showed a worm by the name of supernova? or something like that. I didnt write it down. I deleted the folder that contained it but my taskmanager shows it running. Any ideas on how to get rid of it? xp professional

embj
01-06-2003, 10:52 PM
This is what you have.

Supova---Here is a link to Norton's Site that gives some info about it (http://securityresponse.symantec.com/avcenter/venc/data/w32.supova.worm.html).

I reccomend doing a free online scan from TrendMicro. It will clean it, too. Here is the link. (http://housecall.trendmicro.com/housecall/start_corp.asp) :cool:

Had six virii to infect my puter in November!!! Had to format 3 times. 4 of them were the backdoor.trojan. Ever since I got Norton Internet Security 2003, I haven't had any!!! Yay!!!
After I downloaded some things off the web that had virii in them it automatically deleted them so they couldn't infect my puter.

Best of Luck!!!

rmanet
01-06-2003, 11:09 PM
Originally posted by embj
I recommend doing a free online scan from TrendMicro. It will clean it, too. Here is the link. (http://housecall.trendmicro.com/housecall/start_corp.asp) :cool:

Isn't that how he found it? and how come it didn't delete it then - I still use AVG, then TrendMicro and Symantec online every so often but I'm not a big time internet cruiser so I've only had a few nasty experiences with trojans, viruses, etc.

omendata
01-06-2003, 11:41 PM
Sorry to say it guys but no network computer professional should ever get a virus infection - Ive been in the game 20 years and never had an infection on my main machine.

They are all easy to kill as long as you know the basics - Your armament should include a good process killer , memory monitor , antivirus package - AVG is great and its free , knowledge of all registry run points and win.ini,system.ini load points , startup folder - With that a format should never be necessary unless its a highly destructive virus which is unusual these days as most are stealth worms designed to steal info rather than make themselves visible.

You should always be running a firewall , router - Personally I run my own Gnatbox on a floppy only old pentium 100 as my main gateway/router and its the cheapest and by far the most secure on the market - fantastic package - check em out - www.gta.com - we also run it at work - It can also teach you how to become rather adept at internet security - thats how I got a foothold on the market and its booming - Wages are spiralling out of control in the contract security game - hell even Zonealarm can teach you a thing or two.

omendata
01-06-2003, 11:43 PM
Sorry to say it guys but no network computer professional should ever get a virus infection - Ive been in the game 20 years and never had an infection on my main machine.

They are all easy to kill as long as you know the basics - Your armament should include a good process killer , memory monitor , antivirus package - AVG is great and its free , knowledge of all registry run points and win.ini,system.ini load points , startup folder - With that a format should never be necessary unless its a highly destructive virus which is unusual these days as most are stealth worms designed to steal info rather than make themselves visible.

You should always be running a firewall , router - Personally I run my own Gnatbox on a floppy only old pentium 100 as my main gateway/router and its the cheapest and by far the most secure on the market - fantastic package - check em out - http://www.gta.com/products/main-gbpro.php - we also run it at work - It can also teach you how to become rather adept at internet security - thats how I got a foothold on the market and its booming - Wages are spiralling out of control in the contract security game - hell even Zonealarm can teach you a thing or two.

tksanchez
01-07-2003, 12:05 AM
I ran trends housecall and it say to just delete the folder, I did but it still shows in the task manager. So how would I get rid of this. Thanks

What is AVG and how do i get it.

omendata
01-07-2003, 12:16 AM
Some viruses prevent you from installing a new virus checker.
Try it anyway:

WWW.GRISOFT.COM

Try and kill the process first from task manager - doesnt always work - you are better off with a dedicated process/thread killer but give that a go first.

Also check these registry keys.
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

Or run msconfig.exe - look for any errant applications or put the results on here and we'll tell you which to delete.

tksanchez
01-07-2003, 01:05 AM
This is system configuration utility:
Startup:

SysTray
dpps2
Cheese-Burger
msmsgs
Zone Alarm
msmsgs
NvCpl
nwiz
Hello-Killy
Microsoft Office
I unchecked Cheese-Burger and it keeps coming back, and Hellow Kitty has something to do with it also, showed up at the same time

omendata
01-07-2003, 01:26 AM
Kill them both in the tasklist - then remove them from the registry - should do it in safe mode but try normally first.
If that doesnt work also check your startup folder - look in system.ini - run sysedit.exe.
Look for shell = or load =
Remove kitty first then cheeseburger.

If running xp/2000 check services - some install as a non-stoppable service - havent had time to look the details of this one up - dealing mostly with Yak infections at the mo - nasty.

tksanchez
01-07-2003, 01:59 AM
omendata I ran the AVG and after I got it set up on my computer, I asked to check for viruses, and It found two. cheeseburger and kitty, it then asked to remove them. I think it worked! how can I check for sure?

Before all of this I did try to disable it in the tasklist, I would disappear but it would reappear later on. For future reference how do I find the registry? I know what safe mode is and how to get there.

omendata
01-07-2003, 02:24 AM
There are two registry editors.
Best one to use has the find command - use it by clicking start , run type regedit and hit enter - be aware that changing values in the registry without knowing what you are doing can completely snafu your machine - its easy to backup the registry in win9x but win2k.xp take a bit more work - easiest way in xp/2000 is to install a second copy of xp/2000 and backup the config folder - having a second os on the hard disk has always been an IT Professionals way of quick disaster recovery especially with NTFS - There are other ways like using NTFSDOS PRO , Command console etc but its a case of choose yer own bag.

embj
01-07-2003, 03:27 PM
My bad. Sorry I just read over it.:)

And cheesburger and kitty are the same thing. Kitty is just a nickname. :cool:

Oops, forgot about AVG.

tranka32
01-14-2003, 10:35 PM
I didn't see any reference to it in the above posts but did you turn off the system restore option in win xp.... I think it's a good idea???????