PDA

View Full Version : Yet Another Virus (please help)



TheThunderBringer
12-14-2010, 09:15 PM
I got another one....but it wasn't my fault this time, 'twas my brother's.

Anyway, same drill as last time, the virus won't let me access the internet or ANY applications if I'm not in Safe Mode (I have a PC that runs on XP, if that helps), which means I cannot look for a solution on it. I ran Malwarebytes...3 times, in fact. On the 3rd try, it said nothing was infected, yet the assault on my computer continues D:

Anyone know how to get rid of this? I would really reeeeally appreciate it!

Token Black Guy
12-14-2010, 11:48 PM
Did you run the scan in safe mode? If not then do it. I had a similar virus on my laptop, except my OS is Windows 7. Ok i want you to get your hands on a different pc that isn't infected and download this iso image file (http://www.freedrweb.com/livecd/?lng=en) and burn it to a cd. (There are instructions on the site on how to use it.) Once you burned the image to a cd, put the cd in your pc and boot it by tapping the ESC key(it might be a different key on your pc) upon start-up. Hopefully this helps you.

Videogamer555
12-15-2010, 01:12 AM
Boot to "safemode with networking". Get on the net, and download the free versions of Super Antispyware, AVG, Avira, Avast, Malware Bytes, and any other free ones you can get your hands on. Install, Run (update virus defs, and then perform scan), and Uninstall each of them (not all at the same time of course). At least ONE of these should destroy your virus.

If that doesn't get doesn't get it. I'll tell you how to manually find it in the registry. And yes there are other ways to boot a virus than the normal "HKLM\software\windows\current version\run" and "HKCU\software\windows\current version\run" methods. I have downloaded a number of RATs (Remote Admin Tools) used to control a victim's comp, but only to legally test on my own computer (hack myself, LOL). I can tell you I've discovered some less conventional ways of autostarting malware from the registry. If the above virus scans don't work, but regedit will run (if nothing else it should run in safe mode), I'll tell you how to find and remove the registry entries used for autostarting the malware at Windows bootup.

Ashminigun
12-15-2010, 08:08 AM
I don't want to discredit anyone idea because they are many way to skin a cat. Every method could work but it's matter how serious is the problem and how long will it take to fix it. Not to mention the affect of a method on your OS stability and data integrity after the clean up.

If I'm in your shoe, I would take out the hard disk where the affected system partition located, make it slave/mount on external hard disk device and plug it on unaffected computer and run an anti virus scan on the affected disk. After the scan find and clean the malware, plug it back and boot it. If your OS able to function normally (in you case, able to access the Internet and run application), that means the scan has detect and safely remove the bug.

You can go an extra mile by clean up your system registry using third party software. You can also use Regedit but you need to know what needs to delete and what needs to be modify. You cannot go through the registry blindly and delete/modify the string that you think is the problem. Regedit is only reserve for those really know what they are doing.

If the anti virus scan has completed and its unable to detect the problem, I would advise you to back up your important data then perform any one of these options:
Run your OS in Safe Mode and try restore the last working setting using System Restore.
If the 1st option fail, insert your OS installation CD and choose Repair.
If both method fail, you need to do a clean installation of your OS (Make sure you have back up your important data. Once you reformat the partition, it's hard to retrieve the lost data from that partition.

Alias-Revolution
12-15-2010, 12:09 PM
I'd re-format my hard drive, but that's just because I'm lazy.

TheThunderBringer
12-15-2010, 02:25 PM
I DID run Malwarrebytes in safe mode, but again, it said it couldn't find anything =/

Thanks for all the info/options, everyone ^^ I'll try those out as soon as I can and get back to you. This is a big help

Lily Rock
12-15-2010, 02:42 PM
I had a very hard-to-delete hack/trojan on my comp once... It was cause of my curiosity about CS(Yes, I don't own it, and never had played it, tbh, it sucks BIGTIME), so it wasn't removed at any ways... So my father found "SuperAntiSpyware", it's probably the best solution I've used, as it removed it INSTANTLY, other threats too, try it, get a USB wire for your cell, w/e or get a cheap USB that can carry it, it should work.

Token Black Guy
12-15-2010, 07:53 PM
I had a very hard-to-delete hack/trojan on my comp once... It was cause of my curiosity about CS(Yes, I don't own it, and never had played it, tbh, it sucks BIGTIME), so it wasn't removed at any ways... So my father found "SuperAntiSpyware", it's probably the best solution I've used, as it removed it INSTANTLY, other threats too, try it, get a USB wire for your cell, w/e or get a cheap USB that can carry it, it should work. Forgot about that one. Dr. Web (http://www.freedrweb.com/cureit/) and Trend Micro (http://housecall.trendmicro.com/) has a tool like that also.