SydLexia.com Forum Index
"Stay awhile. Stay... FOREVER!"

  [Edit Profile]  [Search]  [Memberlist]  [Usergroups]  [FAQ]  [Register]
[Who's Online]  [Log in to check your private messages]  [Log in]
Yet Another Computer Issue


Reply to topic
Author Message
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Mar 27 2011 06:43 am Reply with quote Back to top

Guess what? I have a virus on my computer. And it is proving hard to get rid of.

Also, here's some info on it:
-Blocks both my antivirus programs (Malwarebytes giving an error about something I don't understand and AVG not opening it's interface or updating)
-Before my antivirus programs were blocked, running a scan caused my computer to completely lock up (caps lock buttons not responding, etc.)
-Messages about startup programs being blocked, and system processes crashing.
-Safe Mode being blocked.
-Possibly some other issues I have not seen yet or mentioned.

Anyone know what I could do?


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Mar 27 2011 08:59 am Reply with quote Back to top

I would reimage the computer/reformat. That is just me. The alternative is hours worth of fighting.

The hardest part about fixing problems once you get to this point is that you can't use the computer you have because it is fucked.

So, you need a boot disk with utilities.

I would suggest WinPE with a full set of tools, but that is an extremely large amount of work. So...
My second suggestion would be to boot off of the Windows DVD and get to the command prompt. From there have a USB key plugged in that has portable ClamWin and SpyBot:
http://portableapps.com/apps/security

You should run the portable apps on another working computer to update them prior to using them on your own.



 
View user's profileSend private messageVisit poster's website
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Mar 27 2011 09:08 am Reply with quote Back to top

Okay, I shall try these tomorrow (it is 12am where I live). I really do not wish to reformat my disk, because I have not backed up my files since that Windows 7 malfunction, so I shall go the harder way.


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Mar 27 2011 09:22 am Reply with quote Back to top

Mr. Satire wrote:
Okay, I shall try these tomorrow (it is 12am where I live). I really do not wish to reformat my disk, because I have not backed up my files since that Windows 7 malfunction, so I shall go the harder way.

Remember, you could boot to any bootable OS and just backup your shit.



 
View user's profileSend private messageVisit poster's website
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Mar 27 2011 01:42 pm Reply with quote Back to top

What we do at the place I intern when we get a computer that matches what you said
1.) System restore to a week before the virus hit.
2.) Run a boot time scan and/or a full system scan with Avast
3.) verify the virus is gone.
View user's profileSend private message
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Mar 27 2011 04:51 pm Reply with quote Back to top

GPFontaine wrote:
Mr. Satire wrote:
Okay, I shall try these tomorrow (it is 12am where I live). I really do not wish to reformat my disk, because I have not backed up my files since that Windows 7 malfunction, so I shall go the harder way.

Remember, you could boot to any bootable OS and just backup your shit.

Well, I do have Ubuntu installed on disk and Live CDs of Ubuntu.


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Mar 27 2011 04:53 pm Reply with quote Back to top

Hacker wrote:
What we do at the place I intern when we get a computer that matches what you said
1.) System restore to a week before the virus hit.
2.) Run a boot time scan and/or a full system scan with Avast
3.) verify the virus is gone.

I don't have System Restore active, I think. I usually disable it to save disk space.


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
The Opponent
Title: Forum Battle WINNER
Joined: Feb 24 2010
Location: The Danger Zone
PostPosted: Mar 27 2011 05:04 pm Reply with quote Back to top

You can try getting the Dr. Web LiveCD. I use it when I need offline antivirus in a fix.


I'm not a bad enough dude, but I am an edgy little shit. I'll do what I can.
 
View user's profileSend private messageVisit poster's website
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Mar 27 2011 10:32 pm Reply with quote Back to top

Dr. Web? Who/What is that?



 
View user's profileSend private messageVisit poster's website
Knyte
2010 SLF Tag Champ*
Title: Curator Of The VGM
Joined: Nov 01 2006
Location: Here I am.
PostPosted: Mar 28 2011 12:12 am Reply with quote Back to top

Sounds like one of those "Windows Antivirus 2010" viruses.

Search for the exact name the pop ups give you. You can find detailed instructions of what files you need to get rid of.

You usually have to load into safe made. Kill the related processes, then hunt down and delete the files. (Which are usually hiding in the %appdata% folder somewhere.
View user's profileSend private messageVisit poster's website
Doddsino
Joined: Oct 01 2009
PostPosted: Mar 28 2011 01:18 am Reply with quote Back to top

All I have to say is..

YOUR'RE IN DANGER! YOUR COMPUTER IS INFECTED WITH SPYWARE!

ALL YOU DO WITH COMPUTER IS STORED FOREVER IN YOUR HARD DISK. WHEN YOU VISIT SITES, SEND E-MAILS... ALL YOUR ACTIONS ARE LOGGED. AND IT IS IMPOSSIBLE TO REMOVE THEM WITH STANDARD TOOLS. YOUR DATA IS STILL AVAILABLE FOR FORENSICS. AND IN SOME CASES

FOR YOUR BOSS, YOUR FRIENDS, YOUR WIFE, YOUR CHILDREN. Every site you or somebody or even something, like spyware, opened in your browsers, with all the images, and all the downloaded and maybe later removed movies or mp3 songs - ARE STILL THERE and could break your life!

SECURE YOURSELF RIGHT NOW! REMOVE ALL SPYWARE FROM YOUR PC!
View user's profileSend private message
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Mar 28 2011 04:27 am Reply with quote Back to top

Knyte wrote:
Sounds like one of those "Windows Antivirus 2010" viruses.

Search for the exact name the pop ups give you. You can find detailed instructions of what files you need to get rid of.

You usually have to load into safe made. Kill the related processes, then hunt down and delete the files. (Which are usually hiding in the %appdata% folder somewhere.

I know it's not one of those fake antiviruses, since it doesn't seem to install anything that looks like a fake antivirus.

The popups look like typical Windows Vista/7 "this program is not responding/has stopped working" dialogs, and they claim that a program that sounds like a system process (I forgot the name, but it begins with 'Host'). Also, I have seen Windows Data Execution Prevention warnings, and warnings that some startup programs have been blocked.

Like I said, I can't access safe mode, however, I can use Ubuntu to do some stuff relating to files.


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Apr 03 2011 03:09 am Reply with quote Back to top

UPDATE-ME-DO: I now have a screenshot of one of the errors I have been getting presumably due to the virus. Also, when I booted windows today, my antivirus (AVG Free 2011) said it had succeded in removing a malware, and after that, both my antivirus programs worked again. However, I am still getting some errors, and some websites randomly redirect.

Oh, and here is the screenshot:
Image


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
Blackout
Title: Captain Oblivious
Joined: Sep 01 2007
Location: That Rainy State
PostPosted: Apr 03 2011 03:12 am Reply with quote Back to top

I'm no expert but don't windows error msgs like that always ask you if you want to notify Microsft or not? It looks phony and weird with the whole Don't call us we'll call you jazz going on in there... Confused



 
View user's profileSend private messageAIM AddressYahoo MessengerMSN Messenger
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Apr 03 2011 10:41 am Reply with quote Back to top

Blackout, that error is not suspect. It is a notice and there is no option when it comes up.

Satire,

  1. Get Super Anti Spyware & Malware Bytes. Run them. http://ninite.com/malwarebytes-super/
  2. Update your video driver
  3. Update the rest of your drivers
  4. Run the manual fix for BITS, do not run the automated portion - http://support.microsoft.com/kb/940520
  5. Unplug all unnecessary USB devices (Keep the Mouse and Keyboard Laughing)
  6. Eject all media (CD's, floppy disks?)
  7. Run: C:\Windows\system32\MdSched.exe



 
View user's profileSend private messageVisit poster's website
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Apr 03 2011 12:58 pm Reply with quote Back to top

Not trying to be a smart ass but why're you having him run a memory test for the last step?

Is there some association between viruses and dead RAM?
View user's profileSend private message
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Apr 03 2011 05:39 pm Reply with quote Back to top

The chances of this being a memory error are limited, so it is a last test due to its duration.

Also, at that point the problem would coincidentally be timed alongside of malware. The Host Process failing can be linked to memory issues... so thats that.



 
View user's profileSend private messageVisit poster's website
Hacker
Banned
Joined: Sep 13 2008
PostPosted: Apr 04 2011 12:56 am Reply with quote Back to top

Ah well cool, I'll have to remember that in the future
View user's profileSend private message
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Apr 04 2011 03:29 am Reply with quote Back to top

GPFontaine wrote:
Blackout, that error is not suspect. It is a notice and there is no option when it comes up.

Satire,

  1. Get Super Anti Spyware & Malware Bytes. Run them. http://ninite.com/malwarebytes-super/
  2. Update your video driver
  3. Update the rest of your drivers
  4. Run the manual fix for BITS, do not run the automated portion - http://support.microsoft.com/kb/940520
  5. Unplug all unnecessary USB devices (Keep the Mouse and Keyboard Laughing)
  6. Eject all media (CD's, floppy disks?)
  7. Run: C:\Windows\system32\MdSched.exe

I already have Malwarebytes, but when I downloaded SuperAntiSpyware, running the installer gave me this message:
Image
(and, no, my window borders are not set to purple, that was the background, also, Malwarebytes gives the same error when I launch

I think I have the latest drivers for everything, but I'll check later.

I can't see to get that BITS fix for Windows, since I have to run a Windows Validation thingy, which does not work due to the virus.

I can easily remove my USB mouse (I use a laptop Razz )

I shall try the last step later.

I am screwed, aren't I?


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Apr 04 2011 04:55 am Reply with quote Back to top

Oh, and here is some other things I have noticed.

Sometimes Firefox looks like this until I restart:
Image
Note the classic-style scrollbars, and glitched top.

Also, I have noticed suspicious-looking processes running, trying to kill these gives an 'access is denied' error. I then tried using RKill (http://www.bleepingcomputer.com/download/anti-virus/rkill), but that was blocked too.

My verdict:
I AM SCREWED!


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Apr 04 2011 07:48 am Reply with quote Back to top

GPFontaine wrote:
I would reimage the computer/reformat. That is just me. The alternative is hours worth of fighting.



 
View user's profileSend private messageVisit poster's website
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Apr 04 2011 08:10 am Reply with quote Back to top

GPFontaine wrote:
GPFontaine wrote:
I would reimage the computer/reformat. That is just me. The alternative is hours worth of fighting.

I was being sarcastic about being screwed.

Also, I wish to keep going and only reformatting as a last resort, as I haven't backed up my stuff since that Windows 7 fail.


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
GPFontaine
Joined: Dec 06 2007
Location: Connecticut
PostPosted: Apr 04 2011 09:48 am Reply with quote Back to top

You still haven't booted off of a portable media and done a backup?



 
View user's profileSend private messageVisit poster's website
Mr. Satire
Joined: Jun 08 2010
Location: Termina Field
PostPosted: Apr 04 2011 05:35 pm Reply with quote Back to top

GPFontaine wrote:
You still haven't booted off of a portable media and done a backup?

Nope.

Remember, I am still willing to try and remove the virus without formatting my Windows Vista partition.


Image
Signature by Hacker (RIP)
 
View user's profileSend private messageSend e-mailVisit poster's website
Atma
Title: Dragoon
Joined: Apr 29 2010
Location: Cincinnati, OH
PostPosted: Apr 04 2011 05:42 pm Reply with quote Back to top

I know reformatting sucks. But seriously, Fuck the insane amount of hours of trying to outsmart this for an issue you don't know where it is at.

I would be backing my stuff up and reformatting at this point.

FUN FACT: My latest purchase of a laptop did NOT include Windows 7 Discs. It only came pre-installed. I pray I don't have to reformat anytime soon. I know there are "Ways around it" but I'd still like to get Windows Updates. Especially after I paid for the fucking system.
View user's profileSend private message
Display posts from previous:      
Reply to topic

 
 Jump to: