home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Security and Privacy Issues
Ask a Tech Support Question (free)!

Boss's computer infected, help me oh god :(

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1584
Discussions: 200,906, Posts: 2,378,902, Members: 246,276
Old July 8th, 2004, 02:08 PM   Digg it!   #1 (permalink)
Junior Member
 
Join Date: Jun 2004
Posts: 7
Boss's computer infected, help me oh god :(

Okay, hopefully someone here can help me. If not, I think we're in deep crap

On my boss's computer, we have a cable connection. Using Mcafee Firewall + Virusscan.

The other day, got a virus alert for the life of me I can't remember what it was, but Mcafee said it got rid of it okay. Soon after, the CPU usage shot up to 100% and slowed down the computer massively. It stopped after a while, but today, I can't open Mcafee, every time I try to run virus scan or turn on the firewall it shuts down. I tried to go to the Mcafee.com site, but it says page can't be accessed. I somehow doubt their pag went down and this whatever is causing all this isn't letting me get to the Mcafee site. A process tried to access the internet when I rebooted earlier, winxtc.exe which I denied access to, but is still running and I can't end it. Firewall says it's connected to a remote IP when I can get it to stay open long enough to check. I tried to do a search for the winxtc.exe file, but I discovered I can no longer get into the search for files and folders through the start menu. I also tried to go into my Windows folder to look but alas, I can't see any of my files! It's the same in program files, it says they are there (x amount of folder and size) but I can't see anything. If anyone has any idea if I can fix this, or what to do, I would appreciate a reply as soon as possible! Thanks.
Descent is offline   Reply With Quote
Old July 8th, 2004, 02:14 PM     #2 (permalink)
Ultimate Member
 
osprey4's Avatar
 
Join Date: Oct 2001
Location: South Jersey
Posts: 8,729
He's the boss, right? Tell him he's in great shape, the CPU is running at 100%!!

Seriously, though, sounds like a case for Hijackthis:
http://www.snapfiles.com/get/hijackthis.html

The term "winxtc.exe" is showing up all over the Hijackthis forums.
osprey4 is offline   Reply With Quote
Old July 8th, 2004, 02:14 PM     #3 (permalink)
:slack: strong
 
Detritus's Avatar
 
Join Date: Jan 2002
Location: MI
Posts: 17,372
Blog Entries: 4
Send a message via MSN to Detritus Send a message via Yahoo to Detritus
First try seeing if you can complete a scan here http://housecall.trendmicro.com/hous...start_corp.asp

Also try this virus scanner http://www.grisoft.com/us/us_dwnl7.php

Try this as well http://www.spychecker.com/program/hijackthis.html
Detritus is offline   Reply With Quote
Old July 8th, 2004, 02:32 PM     #4 (permalink)
Junior Member
 
Join Date: Jun 2004
Posts: 7
The term "winxtc.exe" is showing up all over the Hijackthis forums.

Can you give me a link to the specific forums? I can't seem to find anything. And I downloaded hijackthis, and it keep shutting down on me to!
Descent is offline   Reply With Quote
Old July 8th, 2004, 02:47 PM     #5 (permalink)
Junior Member
 
Join Date: Jun 2004
Posts: 7
Okay, I just rebooted and Mcafee grabbed it this time. All better now. Watch out for that damn winxtc.exe crap :|
Descent is offline   Reply With Quote
Old July 9th, 2004, 02:53 PM     #6 (permalink)
Ultimate Member
 
osprey4's Avatar
 
Join Date: Oct 2001
Location: South Jersey
Posts: 8,729
Quote:
Originally Posted by Descent
Okay, I just rebooted and Mcafee grabbed it this time. All better now. Watch out for that damn winxtc.exe crap :|

I'll mention it to my boss.
osprey4 is offline   Reply With Quote
Old July 9th, 2004, 03:05 PM     #7 (permalink)
Leader of the Crab People
 
Redwolf's Avatar
 
Join Date: Oct 2001
Location: NCSU
Posts: 4,381
Send a message via ICQ to Redwolf Send a message via AIM to Redwolf Send a message via Yahoo to Redwolf
It has a name:

WORM_AGOBOT.WD
http://www.trendmicro.com/vinfo/viru...WORM_AGOBOT.WD

Quote:

This worm has backdoor capabilities. It executes commands sent in via Internet Relay Chat (IRC) and can be used to launch as denial of service attack against specified target sites.

It terminates certain antivirus processes and files dropped by other malware. It steals the CD keys of popular game applications.

It modifies the HOST file so that any access to specific antivirus Web sites is redirected to the local machine.

Redwolf is offline   Reply With Quote
Old July 9th, 2004, 03:09 PM     #8 (permalink)
Ultimate Member
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 1,199
We have a poster in our office that says something like this,

Quote:
We have the most up to date Anti-spyware and Anti-virus software, but we forgot about Ruth in accounting!

nomaxim is offline   Reply With Quote
Old July 9th, 2004, 03:11 PM     #9 (permalink)
Newbie
 
filipino's Avatar
 
Join Date: May 2004
Location: Philippines
Posts: 3,894
do housecall over at trendmicro since only trendmicro doing the job right
http://www.trendmicro.com/vinfo/viru...WORM_AGOBOT.WD
filipino is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search

Similar Threads
Thread Thread Starter Forum Replies Last Post
The Pope is a jerk OuTpaTienT IMO Community 194 July 4th, 2004 02:53 PM
My HD got totally wiped by virus..... jagnorm Security and Privacy Issues 9 January 11th, 2004 09:15 PM
HELP!!virus found on my system robin801 General Tech Discussion 31 October 14th, 2002 03:55 AM
N[ort]on AntiVirus dunbar Applications and Operating Systems 7 September 11th, 2002 02:27 PM
Magistr Virus Edoras Applications and Operating Systems 13 January 16th, 2002 05:34 PM


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (2809)
Is the PSU I received dead? (10)
California Passes Anti-Flat-HDTV Le.. (38)
Install XP pro and a Vista laptop ?.. (8)
Fox uses old news clips to inflate .. (33)
A good PSU? (10)
HIS HD5770 graphic card question (14)
Foreign voltage (6)
New Computer wont recognize XP disc (7)
Dept. of HS: NSA 'Helped' Develop V.. (12)
Ideal cheap graph card for PC-Gamin.. (15)
Print spooler problem (5)
EVGA 9800 gtx help with finding a g.. (6)
Mysterious Boot manager (9)
Recent Discussions
Boot Problem? (0)
Logitech G9 laser gaming mouse $59.95.. (2)
$5 off any item with the purchase of .. (1)
Foreign voltage (6)
Ideal cheap graph card for PC-Gaming? (15)
What OS for a home server? (other tha.. (0)
HIS HD5770 graphic card question (14)
Install XP pro and a Vista laptop ?? (8)
Need hard disk drivers (3)
Cloning old drive to new drive (6)
Asus P4G8X Mobo (0)
Amptron monitor G17FP-Black (0)
windows vista security holes (0)
EVGA 9800 gtx help with finding a goo.. (6)
A good PSU? (10)
Is the PSU I received dead? (10)
HP Pavillion Laptop ze4220 won't turn.. (7)
Dept. of HS: NSA 'Helped' Develop Vis.. (12)
Convert 5 pin Keyboard to USB (11)
Print spooler problem (5)
hybernate option (2)
Steam ID's, Gamertags etc... (1)
New Computer wont recognize XP disc (7)
World's largest Monopoly Game using G.. (328)
Modern Warfare 2: Who Bought It? (60)


All times are GMT -4. The time now is 07:36 AM.
TechIMO Copyright 2009 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28