Google Answers Logo
View Question
 
Q: computer virus ( Answered,   1 Comment )
Question  
Subject: computer virus
Category: Miscellaneous
Asked by: allguts-ga
List Price: $10.00
Posted: 29 Apr 2004 09:57 PDT
Expires: 29 May 2004 09:57 PDT
Question ID: 338284
how can I  remove  Bloodhound.Packed  virus C:\windows\system32\jadll
Answer  
Subject: Re: computer virus
Answered By: tlspiegel-ga on 29 Apr 2004 10:16 PDT
 
Hi allguts,

Bloodhound is not the name of a virus, but a message displayed by
Symantec's Norton Anti-Virus when it thinks it may have found a new
virus.

Bloodhound.Packed   
http://securityresponse.symantec.com/avcenter/venc/data/bloodhound.packed.html?Open
Discovered on: January 19, 2004  
Last Updated on: April 26, 2004 03:06:30 PM 
  

"Symantec antivirus products exclusively use the virus name
Bloodhound.Packed when a potentially unknown virus is found using
Symantec Bloodhound technology. Bloodhound technology consists of
heuristic algorithms used to detect unknown viruses. The actual file
detected under Bloodhound.Packed is likely to be infected with a new,
packed, 32-bit Windows virus.

Bloodhound.Packed is detected only in Portable Executable (PE) files.
Bloodhound.Packed can detect any threat within a packed file.

Type:  Trojan Horse, Virus, Worm 
Infection Length:  various   
 
Systems Affected:  Windows 2000, Windows 95, Windows 98, Windows Me,
Windows NT, Windows Server 2003, Windows XP
Systems Not Affected:  DOS, Linux, Macintosh, OS/2, UNIX"

[edit]

"The following instructions pertain to all current and recent Symantec
antivirus products, including the Symantec AntiVirus and Norton
AntiVirus product lines.

1. Disable System Restore (Windows Me/XP). 
2. Update the virus definitions. 
3. Restart the computer in Safe mode or VGA mode. 
4. Run a full system scan and delete all the files detected as Bloodhound.Packed. 
5. Clear the Temporary Internet Files folder, if required.

1. Disabling System Restore (Windows Me/XP)
If you are running Windows Me or Windows XP, we recommend that you
temporarily turn off System Restore. Windows Me/XP uses this feature,
which is enabled by default, to restore the files on your computer in
case they become damaged. If a virus, worm, or Trojan infects a
computer, System Restore may back up the virus, worm, or Trojan on the
computer.

Windows prevents outside programs, including antivirus programs, from
modifying System Restore. Therefore, antivirus programs or tools
cannot remove threats in the System Restore folder. As a result,
System Restore has the potential of restoring an infected file on your
computer, even after you have cleaned the infected files from all the
other locations.

Also, a virus scan may detect a threat in the System Restore folder
even though you have removed the threat.

For instructions on how to turn off System Restore, read your Windows
documentation, or one of the following articles:

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDocument&src=sec_doc_nam

http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam

Note: When you are completely finished with the removal procedure and
are satisfied that the threat has been removed, re-enable System
Restore by following the instructions in the aforementioned documents.

[edit]

"Additional information: 

What are Portable Executable (PE) files?
Portable Executable (PE) files are files that are portable across all
the Microsoft 32-bit operating systems. The same PE-format executable
can be executed on any version of Windows 95, 98, Me, NT, 2000, and
XP. All the PE files are executable, but not all the executable files
are portable.

A common example of a PE file is a screen saver (.scr) file."



Best regards,
tlspiegel

Clarification of Answer by tlspiegel-ga on 02 May 2004 19:33 PDT
Hi allguts,

I searched for more information other than what I originally found for
you.  I located one more suggestion you might try.

FAQfarm.com

Question: 
How do you eliminate a 'Bloodhound.Packed' virus from
WINDOWS\System32\ia.dll, when Norton is not able to do it?
http://www.faqfarm.com/Computer/Virus/22090

Answer:
Try CWShredder. It worked for me. No more annoying Searchpage browser
hijack trash (fingers crossed).
Also try downloading Spybot, it's good and it's free!


CWShredder
http://www.totalpcparts.com/downloads/cwshredder.exe

Spybot
http://spybot.eon.net.au/
Click on Download on the left side of page


Best regards,
tlspiegel
Comments  
Subject: Re: computer virus
From: skcva-ga on 02 May 2004 16:50 PDT
 
I did everything suggested. However, when I tried to delete the
temporary files, IE became unresponsive. So, I still have the file on
my hard drive.

Also, starting up in safe mode is not as straighht forward as indicated.

Important Disclaimer: Answers and comments provided on Google Answers are general information, and are not intended to substitute for informed professional medical, psychiatric, psychological, tax, legal, investment, accounting, or other professional advice. Google does not endorse, and expressly disclaims liability for any product, manufacturer, distributor, service or service provider mentioned or any opinion expressed in answers or comments. Please read carefully the Google Answers Terms of Service.

If you feel that you have found inappropriate content, please let us know by emailing us at answers-support@google.com with the question ID listed above. Thank you.
Search Google Answers for
Google Answers  


Google Home - Answers FAQ - Terms of Service - Privacy Policy