Computer Virus

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
  • Help needed -- my port 110 is bound

    12 answers - 297 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg Add To My Reddit

    Cannot download e-mail. My ISP tech support guided me through some tests and
    concluded that my port 110 must be blocked/bound by some type of malware.
    I don't yet have an AV program installed. How can I at least unbind my port
    110 until I obtain an AV utility?
  • No.1 | | 384 bytes | |

    Knack wrote:
    Cannot download e-mail. My ISP tech support guided me through some tests and
    concluded that my port 110 must be blocked/bound by some type of malware.

    I don't yet have an AV program installed. How can I at least unbind my port
    110 until I obtain an AV utility?

    Start -accessories -Command Prompt

    netstat -an

    Post its output here.
  • No.2 | | 1859 bytes | |

    From: "Knack" <zymatikNSPAM@yahoo.com>

    | Cannot download e-mail. My ISP tech support guided me through some tests and
    | concluded that my port 110 must be blocked/bound by some type of malware.
    |
    | I don't yet have an AV program installed. How can I at least unbind my port
    | 110 until I obtain an AV utility?
    |

    Download MULTI_AV.EXE from the URL --

    To use this utility, perform the following
    Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
    Choose; Unzip
    Choose; Close

    Execute; C:\AV-CLS\StartMenu.BAT
    { or Double-click on 'Start Menu' in C:\AV-CLS }

    NTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
    FireWall to allow it to download the needed AV vendor related files.

    C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
    This will bring up the initial menu of choices and should be executed in Normal Mode.
    This way all the components can be downloaded from each AV vendor's web site.
    The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

    You can choose to go to each menu item and just download the needed files or you can
    download the files and perform a scan in Normal Mode. you have downloaded the files
    needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
    during boot] and re-run the menu again and choose which scanner you want to run in Safe
    Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

    When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
    file.

    Additional Instructions:
    http://pcdid.com/Multi_AV.htm

    * * * Please report back your results * * *
  • No.3 | | 530 bytes | |


    "David H. Lipman" <DLipman~nospanews:jB1ggm~@Verizon.Netwrote in message
    From: "Knack" <zymatikNSPAM@yahoo.com>

    | Cannot download e-mail. My ISP tech support guided me through some tests
    and
    snip

    Download MULTI_AV.EXE from the URL --

    snip
    When the menu is displayed hitting 'H' or 'h' will bring up a more
    comprehensive PDF help
    file.

    Additional Instructions:
    http://pcdid.com/Multi_AV.htm
    --
    * * * Please report back your results * * *
    --
  • No.4 | | 1323 bytes | |

    From: "Russg" <russgilb@MUNGEsbcyahoo.net>

    | Uhm I downloaded multi_av.exe and installed it and
    | ran the .bat file and selected Kapersky and off it went.
    | Now I might be referred to the help and pdf files, but
    | I'm asking here.
    | The batch file downloaded signatures and other stuff from
    | kapersky, then started about an hour and a half scan, I guess
    | of every file and file in an archive, maybe 287,000 of them.
    | It generated a scanresults.txt file, with, I think every one of
    | those files.
    | It reported at the end of the C: drive and D: drive that
    | there was one virus detected, which I think came from
    | my Norton, which I didn't disable.
    | My question. Where would the name of the virus it found
    | be? I believe it to be a false positive, but to sum up, there's
    | an awful lot of reporting and no indication of where the virus
    | was/is.
    | Thanks
    |

    The actual name of the Kaspersky LG file is; C:\AV-CLS\KAV\ScanReport.txt

    It will have lines such as

    C:\1\1048772.EXE infected: Trojan.Win32.Diamin.gen
    C:\1\1048772.EXE deleted: Trojan.Win32.Diamin.gen

    In NTEPAD.EXE search for "infected" and it will find the line where the file is infected
    and show what it is infected with as in the above example.
  • No.5 | | 825 bytes | |


    "David H. Lipman" <DLipman~nospam~@Verizon.Netwrote in message
    From: "Russg" <russgilb@MUNGEsbcyahoo.net>

    | Uhm I downloaded multi_av.exe and installed it and

    snip

    The actual name of the Kaspersky LG file is;
    C:\AV-CLS\KAV\ScanReport.txt

    It will have lines such as

    C:\1\1048772.EXE infected: Trojan.Win32.Diamin.gen
    C:\1\1048772.EXE deleted: Trojan.Win32.Diamin.gen

    In NTEPAD.EXE search for "infected" and it will find the line where the
    file is infected
    and show what it is infected with as in the above example.

    I got it. The line in question:

    c:\DCUME~WNER\DESKTP\XFTSP~1.EXE/data0013 infected:

    all line wrapped.

    It is in xoftspy installation program, which I haven't installed,
    I use spy sweeper.

  • No.6 | | 1003 bytes | |

    Sat, 03 Jun 2006 03:35:44 GMT, "Russg" <russgilb@MUNGEsbcyahoo.net>
    wrote:

    >I got it. The line in question:
    >
    >c:\DCUME~WNER\DESKTP\XFTSP~1.EXE/data0013 infected:
    >
    >
    >all line wrapped.
    >
    >It is in xoftspy installation program, which I haven't installed,
    >I use spy sweeper.


    Indeed Kaspersky produces that alert on the install file of XFTSPY.
    I downloaded XFTSPY to check. The alert means "potentially dangerous
    software", but I dunno what risks are involved in using the program.
    Apparently, it's not a highly regarded program:

    ,aid,118362,pg,4,00.asp

    If you're interested in researching it, do a Google on rouge
    antispyware to see where XFTSPY resides nowdays in the long lists of
    rouge and questionable antispyware products. I seem to recall that it
    was once on the list of rouge products.

    Art
    http://home.epix.net/~artnpeg

  • No.7 | | 1276 bytes | |

    Art wrote:
    Sat, 03 Jun 2006 03:35:44 GMT, "Russg" <russgilb@MUNGEsbcyahoo.net>
    wrote:
    >
    >I got it. The line in question:
    >>

    >c:\DCUME~WNER\DESKTP\XFTSP~1.EXE/data0013 infected:
    >
    >>

    >all line wrapped.
    >>

    >It is in xoftspy installation program, which I haven't installed,
    >I use spy sweeper.
    >

    Indeed Kaspersky produces that alert on the install file of XFTSPY.
    I downloaded XFTSPY to check. The alert means "potentially dangerous
    software", but I dunno what risks are involved in using the program.
    Apparently, it's not a highly regarded program:

    ,aid,118362,pg,4,00.asp

    If you're interested in researching it, do a Google on rouge
    antispyware to see where XFTSPY resides nowdays in the long lists of
    rouge and questionable antispyware products. I seem to recall that it
    was once on the list of rouge products.

    Hi Art. My pov is that once a source is proven untrustworthy, it never can
    be trusted again. So so much for being removed from the Rogue/Suspect list.
    indeed the Rouge on! :-)

    Shane

  • No.8 | | 1356 bytes | |


    "Art" <null@zilch.comwrote in message
    Sat, 03 Jun 2006 03:35:44 GMT, "Russg"

    >>I got it. The line in question:
    >>
    >>c:\DCUME~WNER\DESKTP\XFTSP~1.EXE/data0013 infected:
    >>
    >>It is in xoftspy installation program, which I haven't installed,
    >>I use spy sweeper.

    >

    Indeed Kaspersky produces that alert on the install file of XFTSPY.
    I downloaded XFTSPY to check. The alert means "potentially dangerous
    software", but I dunno what risks are involved in using the program.
    Apparently, it's not a highly regarded program:

    ,aid,118362,pg,4,00.asp

    If you're interested in researching it, do a Google on rouge
    antispyware to see where XFTSPY resides nowdays in the long lists of
    rouge and questionable antispyware products. I seem to recall that it
    was once on the list of rouge products.

    Art
    http://home.epix.net/~artnpeg
    Thanks.
    I'm satisfied that I don't want xoftspy, spy sweeper is doing
    well. I was thinking of changing spy detector/remover, as
    xoftspy was/is free, I thought. Like Scotty the watchdog
    program, spy sweeper detects and asks about programs that
    are trying to install in the startups, like qtask for quick time.

  • No.9 | | 2550 bytes | |

    Sat, 3 Jun 2006 15:25:18 +0100, "Shane" <shanebeatson@gmail.com>
    wrote:

    >Art wrote:
    >Sat, 03 Jun 2006 03:35:44 GMT, "Russg" <russgilb@MUNGEsbcyahoo.net>
    >wrote:
    >>

    I got it. The line in question:

    c:\DCUME~WNER\DESKTP\XFTSP~1.EXE/data0013 infected:

    all line wrapped.

    It is in xoftspy installation program, which I haven't installed,
    I use spy sweeper.
    >>

    >Indeed Kaspersky produces that alert on the install file of XFTSPY.
    >I downloaded XFTSPY to check. The alert means "potentially dangerous
    >software", but I dunno what risks are involved in using the program.
    >Apparently, it's not a highly regarded program:
    >>

    >,aid,118362,pg,4,00.asp
    >>

    >If you're interested in researching it, do a Google on rouge
    >antispyware to see where XFTSPY resides nowdays in the long lists of
    >rouge and questionable antispyware products. I seem to recall that it
    >was once on the list of rouge products.
    >>

    >
    >
    >
    >Hi Art. My pov is that once a source is proven untrustworthy, it never can
    >be trusted again. So so much for being removed from the Rogue/Suspect list.

    indeed the Rouge on! :-)

    Hi Shane. Too bad there isn't a truly super antispyware that finds
    them all or 99.9% anyway. People seem to be loading up on multiple
    AS programs in the fear that what one misses another might find. That,
    to me, would be too much of a hassle, especially since I'm not prone
    to taking hits. I rely to a large extent on doing generic checks once
    in awhile to see if anything abnormal seems to be going on. That plus
    good 'ol Kaspersky :)

    BTW, have you checked out my K-BT util? I spent some time tailoring
    that boot diskette to get high speed scanning out of KAVDS32. I found
    that it requires a lot of "elbow room" in the RAM drive in which it
    resides, and, of course, smartdrv is required as well. Anyway, the
    scan speeds are quite good and I much prefer using this formal scan
    method when I want to check my main drive (or at least Windows).
    Those who don't have diskette drives can create a bootable CD
    using the diskette K-BT creates.

    Art
    http://home.epix.net/~artnpeg

  • No.10 | | 2946 bytes | |

    Art wrote:
    Sat, 3 Jun 2006 15:25:18 +0100, "Shane" <shanebeatson@gmail.com>
    wrote:
    >
    >Art wrote:

    Sat, 03 Jun 2006 03:35:44 GMT, "Russg"
    <russgilb@MUNGEsbcyahoo.netwrote:

    I got it. The line in question:

    c:\DCUME~WNER\DESKTP\XFTSP~1.EXE/data0013 infected:

    all line wrapped.

    It is in xoftspy installation program, which I haven't installed,
    I use spy sweeper.

    Indeed Kaspersky produces that alert on the install file of XFTSPY.
    I downloaded XFTSPY to check. The alert means "potentially
    dangerous software", but I dunno what risks are involved in using
    the program. Apparently, it's not a highly regarded program:

    ,aid,118362,pg,4,00.asp

    If you're interested in researching it, do a Google on rouge
    antispyware to see where XFTSPY resides nowdays in the long lists
    of rouge and questionable antispyware products. I seem to recall
    that it was once on the list of rouge products.

    >>

    >
    >>

    >Hi Art. My pov is that once a source is proven untrustworthy, it
    >never can be trusted again. So so much for being removed from the
    >Rogue/Suspect list. indeed the Rouge on! :-)
    >

    Hi Shane. Too bad there isn't a truly super antispyware that finds
    them all or 99.9% anyway. People seem to be loading up on multiple
    AS programs in the fear that what one misses another might find. That,

    I spend much of my time these days (it seems, anyhow!) trying to defuse the
    state of paranoia many users seem to be in as they strive to keep all those
    programs updated! Just like you, and just like with viruses, I never get
    spyware.

    to me, would be too much of a hassle, especially since I'm not prone
    to taking hits. I rely to a large extent on doing generic checks once
    in awhile to see if anything abnormal seems to be going on.

    Indeed. And like with the AV scans, aren't you bored with never finding
    anything?

    That plus
    good 'ol Kaspersky :)

    Good ol' Kaspersky! Are you still using the current (Windows) version? I
    seem to recall you were pleased enough with it.

    BTW, have you checked out my K-BT util? I spent some time tailoring
    that boot diskette to get high speed scanning out of KAVDS32. I found
    that it requires a lot of "elbow room" in the RAM drive in which it
    resides, and, of course, smartdrv is required as well. Anyway, the
    scan speeds are quite good and I much prefer using this formal scan
    method when I want to check my main drive (or at least Windows).
    Those who don't have diskette drives can create a bootable CD
    using the diskette K-BT creates.

    Just downloaded it, Art. I'll get back to you.

    Shane

  • No.11 | | 1009 bytes | |

    From: "Russg" <russgilb@MUNGEsbcyahoo.net>

    |
    | "Art" <null@zilch.comwrote in message
    >Sat, 03 Jun 2006 03:35:44 GMT, "Russg"

    |
    I got it. The line in question:

    c:\DCUME~WNER\DESKTP\XFTSP~1.EXE/data0013 infected:

    It is in xoftspy installation program, which I haven't installed,
    I use spy sweeper.

    < snip >

    | Thanks.
    | I'm satisfied that I don't want xoftspy, spy sweeper is doing
    | well. I was thinking of changing spy detector/remover, as
    | xoftspy was/is free, I thought. Like Scotty the watchdog
    | program, spy sweeper detects and asks about programs that
    | are trying to install in the startups, like qtask for quick time.
    |

    This is NT malware. This is indicating a Process Killing utility that may be used
    maliciously. In this case it is used to help this "once considered a Rogue" anti spyware
    application kill malware that may be running to help it remove it.
  • No.12 | | 1373 bytes | |

    Sat, 3 Jun 2006 18:29:17 +0100, "Shane" <shanebeatson@gmail.com>
    wrote:

    >Indeed. And like with the AV scans, aren't you bored with never finding
    >anything?


    Soytenly! :)

    >That plus
    >good 'ol Kaspersky :)


    >Good ol' Kaspersky! Are you still using the current (Windows) version? I
    >seem to recall you were pleased enough with it.


    KAV 6.0 is very impressive, IM Have you taken a look at it?

    >BTW, have you checked out my K-BT util? I spent some time tailoring
    >that boot diskette to get high speed scanning out of KAVDS32. I found
    >that it requires a lot of "elbow room" in the RAM drive in which it
    >resides, and, of course, smartdrv is required as well. Anyway, the
    >scan speeds are quite good and I much prefer using this formal scan
    >method when I want to check my main drive (or at least Windows).
    >Those who don't have diskette drives can create a bootable CD
    >using the diskette K-BT creates.
    >>

    >
    >Just downloaded it, Art. I'll get back to you.


    Good. I'd appreciate hearing your comments on it.

    Art
    http://home.epix.net/~artnpeg

Re: Help needed -- my port 110 is bound


max 4000 letters.
Your nickname that display:
In order to stop the spam: 3 + 2 =
QUESTION ON "Computer Virus"

EMSDN.COM