|  RSS

PC World Forums: Suspicious behavior - PC World Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Suspicious behavior

#1 User is offline   stewox Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 129
  • Joined: 18-May 07
  • Location:Slovenia - MB

Posted 15 May 2009 - 02:04 PM

My IE icon was renamed by it self , Internet Explorer was renamed to "yo" , while i was gone


Is this a known event that a virus does or do i have a breach , ...



Not to mention i had open ports for about in these 2 days while wamp server was on but it was only for about 2 hours in one day.



And IE is being used for pron mostly and that time a few windows were open when it renamed itself (i was afk at that moment so didn't saw renaming in action)



Ad aware finds nothing , maken a complete scan with nod32 days ago , one was found and removed , now I'll try what you guys suggested last time ... I just need to know if this YO is a joke or what it really is.
0

#2 User is offline   coastie65 Icon

  • Moderator
  • PipPipPipPipPipPipPipPip
  • Group: Moderators
  • Posts: 10,338
  • Joined: 02-April 07
  • Location:Richmond Va.

Posted 15 May 2009 - 02:37 PM

That is the first time I've heard of that. I don't what was suggested, But I would recommend running www.SUPERantispyware.com & www.malwarebytes.org . coastie.
0

#3 User is offline   Grr8008 Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 436
  • Joined: 11-August 08

Posted 15 May 2009 - 03:40 PM

I agree with Coastie. Malwarebytes.org is great. Also, what Anti Virus do you have?
0

#4 User is offline   tek101 Icon

  • Senior Member
  • PipPipPipPipPip
  • Group: Members
  • Posts: 527
  • Joined: 05-April 09
  • Location:UCF

Posted 15 May 2009 - 03:43 PM

Sounds like your IE has been Hijacked ......:(

Follow coastie's suggestion to remove it .....
0

#5 User is offline   stewox Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 129
  • Joined: 18-May 07
  • Location:Slovenia - MB

Posted 16 May 2009 - 03:41 AM

Okay



I have nod32 btw , didn't i said about it before?
0

#6 User is offline   tek101 Icon

  • Senior Member
  • PipPipPipPipPip
  • Group: Members
  • Posts: 527
  • Joined: 05-April 09
  • Location:UCF

Posted 16 May 2009 - 05:12 AM

Yes ...You did .....Clearly .....

If it worked ....You should NOT be in this position ......

I'm not saying its bad either ,,,, One AV or one malware program will NOT save you from all kind of nasty stuff out there .....

Its an opinon ..we just want to help......You don't have to get offended .......
0

#7 User is offline   mjd420nova Icon

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,519
  • Joined: 05-August 06
  • Location:Fremont, California

Posted 16 May 2009 - 09:37 AM

I've had some similar occurrances of this happen to a few users. It wasn't a virus, worm or Trojan. It turned out to be a faulty click on the icon when trying to open it and it went into the rename icon mode. The users didn't catch it right off and attempted to log on and caught it when they looked up after entering a few characters. Not all that common but not unusual either.
0

#8 User is offline   Grr8008 Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 436
  • Joined: 11-August 08

Posted 16 May 2009 - 01:02 PM

Sorry about that, I have never heard of Nod32 before and neglected to read your post carefully enough to realize it was AV. Well then I recommend updating it, running it as well as Malwarebytes. You could also try Windows Defender. Oh and to all you people who might jump on me for recommending that, please don't. After all you never know what might work.
0

#9 User is offline   stewox Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 129
  • Joined: 18-May 07
  • Location:Slovenia - MB

Posted 17 May 2009 - 05:06 AM

I didn't mean like that , I'm not angry lol ( I'm not english , maybe my tone of writing looks upset?)



Ok then I suppose I don't need to worry about this so much... I will scan with everything suggested anyway.
0

#10 User is offline   tek101 Icon

  • Senior Member
  • PipPipPipPipPip
  • Group: Members
  • Posts: 527
  • Joined: 05-April 09
  • Location:UCF

Posted 17 May 2009 - 05:13 AM

Hey ....Its cool ...

Set it "Read only" in General .....after you rename it ...click ..apply ..OK....

Posted Image
0

#11 User is offline   stewox Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 129
  • Joined: 18-May 07
  • Location:Slovenia - MB

Posted 17 May 2009 - 06:07 AM

On the other hand why this looks suspicious , is that , the word yo , means like , hello or hi , so if some hacker got in , probably did that , everbody would say like hi"



Not only that , windows open or close by them self, but i saw only 2 times... this only happening about 3 days.





But the accidentialy renaming still proves to be a possibility that it could happen , no panic
0

#12 User is offline   stewox Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 129
  • Joined: 18-May 07
  • Location:Slovenia - MB

Posted 18 May 2009 - 02:53 AM

Now I am having frequent mouse stops , the mouse just stops at seemingly determined time but actually on random , it never stoped when i moved it , but it stopped from working just when i paused my actions for a moment


This is getting on my freaking nerves , cause i know this only happening when the windows started to close or open by them slefs and that YO renaming , ... I have no idea what the heck whatsoever could have caused that ,but I know I always found worms if my windows were closing/opening by them self, done a full NOD32 scan and nothing found.



Yesterday the mose just stopped , i had to disconnect it from USB then back again , then after a while , EVERYTHING STOPPED , keyboard too , and the last time i pluged in the mouse , the windows plug-in hardware tray appears as normal but should disappear normally for this addons, but it didn't it froze and it stayed there , so when I unplugged and pluged the mouse didn't want to work NO WAY with no win-plug-in sound effect, the keyboard didn't work aswell ., tried to plug the mouse into the PS/2 adaptor and then into , but didn't work as well , nothing worked this PAIN in the ... freaking small problem turned I had to hard reset the PC , nothing valuable was lost but anyways i don't like to hard reset most of the BIG problems in many games , apps , ... I manage to somehow get to the proper shutdown command.
0

#13 User is offline   tek101 Icon

  • Senior Member
  • PipPipPipPipPip
  • Group: Members
  • Posts: 527
  • Joined: 05-April 09
  • Location:UCF

Posted 18 May 2009 - 05:53 AM

Time for another AV ......

Try Avast ....; download.cnet.com/Avast-Home-Edition/3000-2239_4-10019223.html
0

#14 User is offline   coastie65 Icon

  • Moderator
  • PipPipPipPipPipPipPipPip
  • Group: Moderators
  • Posts: 10,338
  • Joined: 02-April 07
  • Location:Richmond Va.

Posted 18 May 2009 - 06:07 AM

Have you downloaded and run Malwarebytes ( www.malwarebytes.org ). & SUPERantispyware ( www.SUPERantispyware.com ). ? If not, do so, and than get back with us. coastie
0

#15 User is offline   stewox Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 129
  • Joined: 18-May 07
  • Location:Slovenia - MB

Posted 18 May 2009 - 06:31 AM

I did it cleaned 9 trojans


And , is AVAST true antivirus? , cause i already have nod32

I installed it and didn't reboot , what can happen if I reboot? can I remove it now?
0

#16 User is offline   coastie65 Icon

  • Moderator
  • PipPipPipPipPipPipPipPip
  • Group: Moderators
  • Posts: 10,338
  • Joined: 02-April 07
  • Location:Richmond Va.

Posted 18 May 2009 - 09:12 AM

Hi, Yes. I am running Avast! in here and also installed it on my Mothers new Vista Laptop. I am using Webroot's Spysweeper on here for the antispyware as it is free from my service ( MSN Premium through Verizon ). A good antispyware app coupled with Avast! should be fine. coastie
0

#17 User is offline   SpiritWind Icon

  • Expert
  • PipPipPipPipPipPip
  • Group: Members
  • Posts: 1,922
  • Joined: 19-August 06

Posted 18 May 2009 - 09:14 AM

Posted Image Hi :
NOD32 is an antiVIRUS program, as is Avast . However, NOD32 is considered superior

to Avast ( and I sometimes provide Advice on the Avast Support Forums ), so I do NOT

recommend "switching" antiVIRUS programs . However, antiVIRUS programs do NOT

Detect all the different "Kinds" of malware coming over the internet, which is WHY is it

Best to "complement" an antiVIRUS program with 1 or 2 antiSPYWARE/antiTROJAN

programs, which is sometimes called the "Layered Approach", as I spoke about at

forums.pcworld.com/docs/DOC-1141|d-1141 .

The "Detections" you mentioned are considerd "Rogue" Programs by the malware-

fighting "community", which Malwarebytes' Anti-Malware is designed to "detect", where

antiVIRUS programs are NOT designed to "detect" .

NOTE : Ad-Aware has NOT been considered a top antiSPYWARE program the last

couple of yrs; nowadays, "SUPERAntiSpyware" from [http://www.superantispyware.com]

is considered much superior by the vast majority of the malware-fighting "community" .
0

#18 User is offline   coastie65 Icon

  • Moderator
  • PipPipPipPipPipPipPipPip
  • Group: Moderators
  • Posts: 10,338
  • Joined: 02-April 07
  • Location:Richmond Va.

Posted 18 May 2009 - 10:16 AM

Hey SW, Thanks for adding that clarification. I tend to miss that fact everytime I post, in that you need a good antispyware app to catch that stuff. Avast! is very good at alerting you to nasty sites though. I went to a legitimate site the other other day, that had appartly been hijacked, or at least attempted to navigate to it. Avast! immediately nixed that and put up it's yellow message with red lettering.
0

#19 User is offline   stewox Icon

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 129
  • Joined: 18-May 07
  • Location:Slovenia - MB

Posted 19 May 2009 - 02:16 PM

Yes thanks for the clarification too, malwarebytes indeed removed several trojans and hijacks and seems now my system is ok again (these were really some strong ones , as nothing detected them with what i used usually)
0

#20 User is offline   coastie65 Icon

  • Moderator
  • PipPipPipPipPipPipPipPip
  • Group: Moderators
  • Posts: 10,338
  • Joined: 02-April 07
  • Location:Richmond Va.

Posted 19 May 2009 - 03:01 PM

Hi, Malwarebytes is a good tool. I have it installed in here, just in case. I try to watch where I go, but these days, you can stumle upon stuff antwhere as they like to hijack legitimate sites. What I don't do is download anything, but leave the site, once Avast! has red flagged it. In some cases where I couldn't navigate away from the site, I pulled up the Task Manager and did a restart. I could have broken the Internet connection by pulling the ethernet cable as well. The thing is, with some of those things, they require you to download in order to leave the site and that is what you don't want to do. Anyway, glad to hear things are better. You might want to download ATF Cleaner or CCleaner and clean any residual junk that may be on there. coastie
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users