From: David H. Lipman on
From: "Xray" <pl(a)yer.com>



| I'll give that a try, thanks.

| I finally managed to uninstall Avast, so I could install Kaspersky.
| It found 3 viruses and 2 trojans, including 2 in memory.
| One is rootkit.win32.agent.bdzt
| Another located at c/windows/system32/drivers/bqglkgov.sys

| It calls for a restart to be removed, but upon restarting, Kaspersky
| crashes.

Please describe what were 3 viruses were found.
File name and paths as well as what Kaspersky called it.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: gufus on
From: gufus
Subj: Re: bad virusSat, 20 Mar 2010 19:59:02 -0600

From: David H. Lipman---? To: Xray
Subj: Re: bad virusSat, 20 Mar 2010 18:26:10 -0400

Hello, David!

You wrote on Sat, 20 Mar 2010 18:26:10 -0400:

??|> "Beauregard T. Shagnasty" <a.nony.mous(a)example.invalid> wrote in
??|> news:ho21t0$bi7$1(a)news.eternal-september.org:

??>>> Xray wrote:

??>>>> "Beauregard T. Shagnasty" wrote:
??>>>>> Xray wrote:
??>>>>>> Ok heres what happened, I feel like quite an idiot.

??>>>>>> In a panic I reactivated the anti virus, but it was too late.

DHL> In certain circles I am well known for investgating Usenet binaries.

Vcool..

--
With best regards, gufus. E-mail: stop.nospam.gbbsg(a)shaw.ca


From: Xray on
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in
news:ho3sfd010hp(a)news3.newsguy.com:

> From: "Xray" <pl(a)yer.com>
>
>
>
>| I'll give that a try, thanks.
>
>| I finally managed to uninstall Avast, so I could install Kaspersky.
>| It found 3 viruses and 2 trojans, including 2 in memory.
>| One is rootkit.win32.agent.bdzt
>| Another located at c/windows/system32/drivers/bqglkgov.sys
>
>| It calls for a restart to be removed, but upon restarting, Kaspersky
>| crashes.
>
> Please describe what were 3 viruses were found.
> File name and paths as well as what Kaspersky called it.


Well, the rootkit listed above is a virus I believe.
Also have Rootkit.Win32.TDSS.d

Since Kaspersky wasn't doing anything, I unistalled it and installed Avast.
Got multiple blue screen page faults on startup after that, apparently my
system has become highly unstable.
Finally managed to boot normally.
Avast doesn't work at all, its there but corrupted, won't do a thing.

Looks like I'm looking at a fresh OS reinstall about now, this thing is
insidious and is always one step ahead.

From: David H. Lipman on
From: "Xray" <pl(a)yer.com>

| Well, the rootkit listed above is a virus I believe.
| Also have Rootkit.Win32.TDSS.d

| Since Kaspersky wasn't doing anything, I unistalled it and installed Avast.
| Got multiple blue screen page faults on startup after that, apparently my
| system has become highly unstable.
| Finally managed to boot normally.
| Avast doesn't work at all, its there but corrupted, won't do a thing.

| Looks like I'm looking at a fresh OS reinstall about now, this thing is
| insidious and is always one step ahead.

RootKits are trojans not viruses.

Viruses self replicate. That means once infected it will auto-infect other files (by
appending, inserting or prepending code ), boot sectors and/or systems. Trojans may
infect another file by appending, inserting or prepending code but that subsequent file
doe not speread the infection. It is simply becoames "trojanized".

You can't uninstall, replace and re-install fully installed antio virus applications like
you've been doing.

** At this point, my advice is now to WIPE and RE-INSTALL the OS.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: Xray on
"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in
news:ho403m014ge(a)news3.newsguy.com:

> From: "Xray" <pl(a)yer.com>
>
>| Well, the rootkit listed above is a virus I believe.
>| Also have Rootkit.Win32.TDSS.d
>
>| Since Kaspersky wasn't doing anything, I unistalled it and installed
>| Avast. Got multiple blue screen page faults on startup after that,
>| apparently my system has become highly unstable.
>| Finally managed to boot normally.
>| Avast doesn't work at all, its there but corrupted, won't do a thing.
>
>| Looks like I'm looking at a fresh OS reinstall about now, this thing is
>| insidious and is always one step ahead.
>
> RootKits are trojans not viruses.
>
> Viruses self replicate. That means once infected it will auto-infect
> other files (by appending, inserting or prepending code ), boot sectors
> and/or systems. Trojans may infect another file by appending, inserting
> or prepending code but that subsequent file doe not speread the
> infection. It is simply becoames "trojanized".
>
> You can't uninstall, replace and re-install fully installed antio virus
> applications like you've been doing.

Well, the virus hosed Avast, seemed like an option worth trying, since the
alternative is basically to reinstall the OS.
Kaspersky detected the problem, was unable for whatever reason to do anything
about it, so I moved on.
At this point, since I've nothing left to lose, I'm going to unistall Avast
[again] and try AVG.