1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

PC appears to be corrupted with an unknown virus?

Discussion in 'Virus & Other Malware Removal' started by Chris31279, Sep 1, 2004.

Thread Status:
Not open for further replies.
Advertisement
  1. Chris31279

    Chris31279 Thread Starter

    Joined:
    Sep 1, 2004
    Messages:
    1
    While trying to run FormFlow (16bit Appl) I keep getting an error stating that "AUTOEXEC.NT" was invalid. In fact it was missing. I restored the file from the REPAIR directory, but each time the PC was RE-booted, the file would be deleted. SymantecAV (list date 8/25/2004) didn't find any virus. Symantec Web site has no references for this file deletion or the Windupdates program. I found a utility (Windupdates.exe) running, so I de-installed the program through the ControlPanel+AddRemovePrograms. The "AUTOEXEC.NT" file is no longer being deleted, BUT there is still a reference in the REGISTRY. The entry in the REGISTRY references a Web site (public.windupdates.com/get_filelong name) and downloads [bridge-c5.cab] a file. I ran SpyBot and there was no reference to this Web site.

    Please advise

    Thanks
     
  2. KrashedKris

    KrashedKris

    Joined:
    Dec 23, 2003
    Messages:
    262
  3. KrashedKris

    KrashedKris

    Joined:
    Dec 23, 2003
    Messages:
    262
    Hi Chris31279, I just saw your PM about what "Windupdates" is - well I'll try to answer as best I can but I should say I'm not by any means a security expert so I don't have all the answers. AFAIK Windupdates is some kind of malicious application which falls into the general category of spyware/adware and isn't a virus as such although the distinctions between all these baddies seem to be increasingly blurred. I had a quick google around and found a discussion about it and related nasties in this thread at Broadband Reports security forum, although I'm sure there are other sources out there -

    http://www.dslreports.com/forum/remark,10868910~mode=flat~days=9999

    I think the bottom line is you want to make sure it's been completely removed from your pc. What I'd suggest is that if you don't already have these, get both of these excellent free anti-spyware/adware apps, Spybot Search & Destroy and AdAware S.E. as linked here -

    http://www.safer-networking.org/

    http://www.lavasoftusa.com/software/adaware/

    Install the latest definition files as directed on the sites and configure them to scan all files on your system, boot to safe mode, run them and have them remove anything that they find. This is a safe option as both apps create backups of any removed malware by default.

    Then download the free "Hijack This" application from here -

    http://www.aumha.org/downloads/hijackthis.exe

    Create a new folder for it suitably named (e.g. HJT), double-click it to run it (in normal mode) and select to save the scan results in notepad or wordpad etc - then post back to this thread with the log pasted into your post. DO NOT FIX ANYTHING WITH HIJACK THIS unless advised to do so by a mod or knowledgeable responder in this forum - most of the items detected in the scan are required system or application files.

    hth (y)
     
  4. cybertech

    cybertech Retired Moderator

    Joined:
    Apr 16, 2002
    Messages:
    72,115
    Hi Chris31279, Welcome to TSG!!


    Create a folder on your hard drive for Hijackthis, like My Documents\HJT
    Click on this link: http://www.thespykiller.co.uk/
    Go to the downloads section and get hijackthis. Save the file into the folder you have created.
    Unzip the file to the folder.
    Scan your machine, then click on Save Log.

    Post a copy back here and someone will be happy to review it.

    Don't make any changes until instructed to do so.
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - appears corrupted unknown
  1. Harisz
    Replies:
    8
    Views:
    614
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/268941

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice