Help needed again from computer experts

Posted by: oldie on 04 July 2004

Once again I'm in the nasty brown stuff, and hope that all of you computer experts can rescue this poor old computer illiterate sod from further doldrums.[OP SYSTEM XP PRO]
Dispite having McAfie antivirus, XP firewall, Mailwasher, Spybot and Ad-aware running on my computer plus several strands of razor wire a few anti personal mines and a burgular alarm this weekend two viruses managed to infect the computer,fortunately for me this coincided with a visit of some friends and their family for a BQ ,so their Daugthers boyfriend had to earn his meal. I never open unknown e-mails or attachments [ever]and only view attachments through the mailwasher pre view, but still I'm told somthing called netsky ?? had managed to get in and it proved to be very difficult to remove as It kept replicating it self as every time that he tried to delete the quarantine file it reappeared. He finaly managed to remove it by going into safe mode and doing something that I couldn't see as his fingers were flying all over the key board.My question is , he has advised me to instal another anti virus program such as AVG to run at the same time as McAfie [he said this is what he does where he works as a NHS IT Technician]but I have read somewhere, possibly on this forum that these anti virus programs can be unstable and sometimes can affect other programs, so running two of them together might be inviting even more problems. Has anyone out there had similar experiences or has run two anti virus programs together .Any advice would be appreciated, apart from "get a Mac or another operating system" as I have [or I thought I had] only just got to grips with this Bl--dy M/c Thanks in advance, from a very confused and frustrated
oldie
PS The Mcafie anti virus program did not either identify the problem or start the virus alert warning window So both the Netsky worms had managed to evade everthing that I have had installed.

[This message was edited by oldie on Sun 04 July 2004 at 13:09.]
Posted on: 04 July 2004 by bjorne
Oldie, the sad truth seems to be that your pc can get infected even if you use antivirus programmes, firewalls etc. My pc got infected few weeks ago even though I´m careful and keep the programmes upgraded....
Posted on: 04 July 2004 by Chris Brandon
Oldie,

For a home domestic user,you seem to have most conventional bases covered.
It is unfortunate that these things sometimes do happen.
Besides making sure that your o/s is fully upto date patch-wise. Try using an alternative Browser and email client.

My personal favourites are two from Mozilla.org

"Firefox" for the internet browser ( current version = 0.9.1)
"Thunderbird" for the email side of things ( current version 0.7.1).

Both seem to be inherantly more secure than their Microsoft equivelants ( Internet Explorer & outlook express).

Regards

Chris
Posted on: 05 July 2004 by oldie
Chris / Bjorn,
Thanks for your comments and advice
it's reassuring to know that at least I'm doing something correct[ which makes a change]
as we [better half and myself] are off to Sunny Scotland for three weeks in a couple of days I will look up Mozilla when we get back
Thanks again,
oldie.
Posted on: 05 July 2004 by Mike Hughes
Oldie,

All of the above is good advice but I would have expected your current anti-virus software to have detected Netsky, which has been around for some time in different variants. This raises several thoughts.

1) Your av software is not having it's virus definitions updated.

2) Your av settings are incorrect and not doing basic checks.

3) Safe software practices are not happening e.g. someone inserts a CD or floppy disk and it never occurs to them that the first thing to do is virus check it before they open anything on it.

Mike
Posted on: 05 July 2004 by oldie
Mike,
Thanks for the info.To answer your points as best I can, the McAfie anti virus program is set to scan every time on start up and I do a full scan with spybot, Adaware and McAfie on a regular basis, all e-mails come in through Mailwasher.The McAfie is set to automatically download any up dates and I'm told that it does this stealthily as I have only ever seen it open a information window and down load once, as a bit of an old luddite I must admit that I would be happier if it did it the same way that Windows does it's updates so I could see that it was done. All of the Internet security options are set to medium which I think is the XP recommendation.
As far as I know ,no CD's or other "things" have been used to import any information into the computer [ I only use the Cd option for the occasional "burn"]
Have you any experiance or thoughts on the advice I was given to run two antivirus programs at the same time, Im sure that,from information I have read here that a single program can be unstable so I guess two running together could be disastrous. The only other thing that I can think of to protect myself, is to disconnect the computer and fill it with concrete but I think that might be counter productivebut it might come to that yet Wink
oldie.

[This message was edited by oldie on Mon 05 July 2004 at 15:25.]
Posted on: 05 July 2004 by David Stewart
I'd suspect that two antivirus packages running on the same machine could be problematical. They'd probably trip over each other and use enormous amounts of system resources.

It might be worth checking the ID number of the latest virus signature file on the McAfee website and comparing it with that on your system, just to make double sure it is being properly updated.

McAfee should recognise and remove most (if not all) Netsky variants providing its sig file is up to date. However when I was using McAfee, I found they sometimes took a long time to update sig files after new variants were found in the wild. This could leave you vulnerable for several days.

You could always remove McAfee and try another program like AVG (it's Freeware).

David
Posted on: 05 July 2004 by oldie
Hi Lewis,
Yes I had done all that you advise, but still the little Bas- -rds managed to find away in. I'm not by any stretch of imagination a computer wizz, in fact I barely know how to switch it on but even I thought that running two AV programs would likely cause me more problems than it would cure. As they said it was experts that designed the titanic, But he did get rid of the Netsky's and advise me in good faith so I just thought that I would check things out with the worlds best experts
I still think that the concrete option is the best bet WinkThanks again for all of your help I'm now off to find a seven year old to show me how it's done Big Grin
oldie.
Posted on: 05 July 2004 by dave simpson
Oldie,

Your reinfection is likely due to System Restore if it's not disabled prior to removing the worm. System Restore is simply backing up a copy of the worm (along with everything else)for reinfection.

To disable/enable System Restore On Win XP:

Click Here

Just an idea...

dave
Posted on: 06 July 2004 by oldie
MANY THANKS TO YOU ALL.
With the help of my former Computer Technician
from the Uni [before I was helped out of the door]who knows what a dumbo I am when it comes to computers Confused, we or I should say she has talked me through things and every thing is up todate and running, it would appear that I was just unlucky and the Netsky thing managed to get in. As far as I know, it has now been well and truly killed R.I.P and all the AV systems
working so no need now for the concrete problem sorter solution Big Grin
So Thanks again Folks
oldie.
Posted on: 06 July 2004 by garyi
Get a mac.

Byeeee
Posted on: 06 July 2004 by oldie
Garyi,
I don't eat burgers Wink
oldie.