PDA

View Full Version : Stupid Newbie AV Question(s) (W98)



Tess_Trueheart
10-09-2002, 09:21 PM
Ok, here goes the stupid question(s) of the year, I'm sure:

Running Win 98, NAV 2000. Also AVG. Have had two different 'bugs' quarantined in the Q-vault for quite a while, one described by NAV as 'JS.Exception.Exploit' (or by Trend as 'JS_Seeker.Z1', based upon the detail of the url foisted upon me in the changed Registry), the other as 'VBS.Seeker.Family' that came packed in a globesearch.com bomb.

Now, I've never had to delete a virus from Quarantine before, things have almost always repaired themselves via the NAV in the past. So I've been a bit leery of acting on my own here, but I've talked the ear off of all my techie friends on what to do next, and they all throw up their hands in despair and advise me to just lose everything to a wipe and full restore. Arrrrgh, nooooo!

The 'VBS.Seeker.Family' is said to have originated in C:\WINDOWS; the 'JS.Exception.Exploit' says it came from C:\Program Files\Netscape\Users\{me}\cache

So -- if I were to attempt to delete these (then do any appropriate repairs in the Registry thereafter - that will be another question later on, on how I need to do that), would it be deleting ONLY the 'VBS' and/or the 'JS' file(s), or will it delete the file/file folder it is said to be captured from in the original location(s)???

I could live without the Netscape (I also use IE of course), but to delete Windows itself and having only a funky factory QuickRestore disk to work from is not my idea of fun ...

Please tell me it is safe to delete these from the Quarantine vault and I will not lose the use of anything if I do!

Another downside to these infections is that apparently a few .dll's or something must have been affected finally, because my CD-burner software suddenly won't function, so I can't backup any more files off of the system as I had started to do. And of course, the burner software is also restorable only from the stupid factory QR disk ... :(

Another oddity -- I supposedly had all updates/patches in place and yet the JS Exploit still got past them!

"Help me Obe Wan Kenobi, you're my only hope!"

TonyKlein
10-10-2002, 11:15 AM
If you select items in quarantine and hit 'remove' they will be destroyed, and that's the end of them, so relax! :)

The JS exploits didn't actually get past your protection, as your antivirus detected them in your temporary internet files, and quarantined them to stop them from actually doing any mischief.

Cheers, Tony

Tess_Trueheart
10-10-2002, 06:54 PM
Thanks, Tony!

So, ok, this means I WON'T be deleting the C:\Windows, right? Just the VBS.Seeker.Family, right? Cool!

Now, may I ask is there something (a program) recommended for the rank beginner to assist them in doing registry edits? I believe in looking over info at Trend (NAV didn't post anything really) I will have to delete any reference to the offender URL showing up in search tasks or bars.

Boy, crossing my fingers it works, once I actually do this!

Hally
10-19-2002, 03:06 AM
Tess Registry Editing is a very dangerous procedure & not reccommended for beginers even a person comfortable with pc's would have trouble in the registry, I've seen a few people stuff up their whole system with two minutes of half hearted editing.

What exactly did you want to edit or change??


<font color=blue>&gt;&gt;Hally&lt;&lt;
&gt;&gt;&gt;/images/forums/icons/laugh.gif&lt;&lt;&lt;</font color=blue>

Nana
10-19-2002, 08:11 AM
Tess,

As for a tutorial, we have the <a target="_blank" href=http://www.winguides.com/article.php?id=1&guide=registry>Windows Registry Tutorial</a> right here at WinGuides.

Hally is absolutely correct about editing your registry, you can muck up your computer so bad you won't be able to get into Windows. Before you do anything, make sure to back it up.

Also, as Tony mentioned, if the viruses are in quarantine, it means that they didn't get past your AV software. When a virus is found, NAV, for example, gives you information about where it is in your system right then. When they quarantine it, it gets moved. I think you may find that you won't have anything to delete.

Good luck.
Nana /images/forums/icons/smile.gif

BTW: Tess, NO newbie is stupid when she/he asks questions. It's those who don't ask that are stupid!<P ID="edit"><FONT class="small">Edited by Nana on 10/19/02 07:22.</FONT></P>