Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Possible infection

Status
Not open for further replies.

mhaff

Technical User
Jan 31, 2003
55
US
We have the small business edition with a 10 user license. My boss purchased a new laptop in July while I was out of the office and didn't bother to install AV softare. I realized this today and installed Symantec. About 90% thru the process, I got a couple of error messages saying the realtime protection could not load. I went ahead and finished the installation. When I restarted the computer I got several symantec error messages saying that it couldn't load the following files. NAVOPTRF.DLL, NAVAPW32.DLL, DFALERT.DLL, CCIMSCAN.DLL, STATUSHP.DLL. But, the realtime protecion icon in the taskbar is on, as in enabled. Of course at this point I suspect infection. I then ran Stinger. It found nothing. I then tried to install AVG(free version) in Windows safe mode. The system locked up. What else can I try? I imagine I need to run something in dos mode or pre-boot.
The OS is Win2k. Thanks
 
Heres a couple of programs you can run. Solo antivirus isnt free but has a 30 day trial and can be ran in dos.

(solo antivirus)

also if your able to do an online scan use this.

Let me know what you find.

Also when you installed the programs were any registry monitors running like adaware pros adwatch or anything of the like? If so try closing them and reinstalling for they can stop things.
 
Thank you for the response. Unfortunately I am out of the office for the next couple of weeks. Unless I have a chance to look at it sunday, it will be a while until I get to it. I will let you know.
 
Oh, I forgot. After I posted my first message here, I did some more investigating. I know that porn has a tendancy to install malicious software using media center drm. So I opened media player and opened the most recent file in the history and it was a porn clip named "Trapezistas(1).mpeg". So I decided to delete the file. Problem is, it can't be found. It's as if it is hiding. Any suggestions on that one?
 
Be sure to check the FAQ's for this forum, including faq760-3862. If you can find out what it is, there might be some manual removal instructions. Also, some virii won't be enabled when running in safe mode, so make sure that your efforts include some scanning, cleaning & installing in safe mode - some things you'll be able to do there, some you won't.

As for that file, it could be a direct link on the internet or it might be in the Temporary Interent Files. When searching the hard drive, be sure to include system & hidden files in the search.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top