View Full Version : I think I've got a NEW VIRUS - 2 Threads Merged....
squeaks14
08-15-2005, 07:13 PM
whenever i log on to my pc, (my brothers and i have 5 different log-ins combined) i have about one minute to click on the desktop before it locks up and becomes unusable. if i do manage to click an icon, the program will either never open or i will get an error message that says it has encountered an error and must shut down. If i move my mouse to the start button, it will turn into the hourglass, no matter how long i wait. so basically, the desktop is useless, even if i go to task manager, end explorer.exe, and re run it. speaking of the task manager, the files kerpolcy.exe and oddasrad.exe continuously pop-up as many as 30 times each, even if i start deleting all of them. I've searched for both of these files online, both with and without the .exe, and i got no matches. When i looked at the applications under task manager on one of the log-ins that had never been used since the virus, i found the application INSTAL~1. I searched for this online and also found nothing. If i ever try to run a program using task manager(since i cant use the desktop), my pc freezes until the below paragraph happens.
Randomly, sometimes after 1 or 2 minutes, sometimes after 10, the screen will turn blue with a whole bunch of text that i can't read at all before it disappears and my pc restarts.
The only think that i can think of that caused this (and it probably did) is my brother downloaded Morpheus (The music swapping program) about a week ago.
What is going on with my pc? Any help would be greatly appreciated. :D Thanks
squeaks14
08-15-2005, 07:16 PM
whenever i log on to my pc, (my brothers and i have 5 different log-ins combined) i have about one minute to click on the desktop before it locks up and becomes unusable. if i do manage to click an icon, the program will either never open or i will get an error message that says it has encountered an error and must shut down. If i move my mouse to the start button, it will turn into the hourglass, no matter how long i wait. so basically, the desktop is useless, even if i go to task manager, end explorer.exe, and re run it. speaking of the task manager, the files kerpolcy.exe and oddasrad.exe continuously pop-up as many as 30 times each, even if i start deleting all of them. I've searched for both of these files online, both with and without the .exe, and i got no matches. When i looked at the applications under task manager on one of the log-ins that had never been used since the virus, i found the application INSTAL~1. I searched for this online and also found nothing. If i ever try to run a program using task manager(since i cant use the desktop), my pc freezes until the below paragraph happens.
Randomly, sometimes after 1 or 2 minutes, sometimes after 10, the screen will turn blue with a whole bunch of text that i can't read at all before it disappears and my pc restarts.
The only think that i can think of that caused this (and it probably did) is my brother downloaded Morpheus (The music swapping program) about a week ago.
What is going on with my pc? Any help would be greatly appreciated. :D Thanks
pop pop
08-15-2005, 08:26 PM
Welcome to PCGuide. Looks like you may have had a rude introduction to the wonderful world of file swapping.
The HJT experts will help you. They'll need to know what OS you're using, do you have any resident antispyware apps (Spybot S&D, AdAware, SpywareBlaster), and can you boot into safe mode. Post back and let them know.
Budfred
08-15-2005, 08:26 PM
Welcome to http://www.pcguide.com/ubb/pcgubb.gif
Please read the descriptions of the forums before posting and post only one thread per topic... I merged your 2 threads and moved them to a more appropriate forum...
You appear to have forgotten to include the paragraph you refer to...
If you can, it would be a good idea to run an online virus scan... I suggest Housecall from my signature... Then try to download and run Spybot, Ad-Aware SE and Ewido (if you have Win2000 or WinXP)... Update them before running them... If you can't do it in Normal Mode, boot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option) and run them from there... Download and run HijackThis and post a log... To run HJT, extract it to a permanent folder such as one
you create like C:\HJT. Close all open windows and
browsers and make sure that all programs are enabled if
you use msconfig. Run it and Scan, then Save the log.
When the log window appears, Right click to Copy it, open
your browser and come here to Paste the entire log. Do
not make any changes until it is checked since most items
are either benign or essential to the computer.
http://www.downloads.subratam.org/hijackthis.zip
Here is the link to Ewido with instructions for running it....
Please download, install, and update the NEW free version of Ewido trojan scanner (http://www.ewido.net/en/download/):
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
From the main ewido screen, click on update in the left menu, then click the Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
If ewido finds anything, it will pop up a notification. We have been finding some cases of false positives with the new version of Ewido, so we need to step through the fixes one-by-one. If Ewido finds something that you KNOW is legitimate (for example, parts of AVG Antivirus, pcAnywhere and the game "Risk" have been flagged), select "none" as the action. DO NOT check "Perform action with all infections". If you are unsure of an entry, select "none" for the time being. I'll see that in the log you will post later and let you know if ewido needs to be run again.
When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.
vBulletin v3.6.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.