Some kind of virus I think (help)

General discussions not related to the Vibe, Matrix, or any other vehicle. (follow posting rules)
Post Reply
Whelan
Posts: 3980
Joined: Tue Jan 23, 2007 10:30 pm

Some kind of virus I think (help)

Post by Whelan »

So yesterday my computer fritzed on me. It suddenyl got a message where the time usually goes in the bottom left saying VIRUS ALERT, then I get a popup in that corner telling me to click here to cleanup, then popups for a spy search. On top of that my desktop is missing items. My Computer is now gone. When I click on the Windows button the All Programs is gone, every time I try to start up Norton to scan it tells me it cannot start up. And each time I restart the Adam folder pops up from the My Computer section which is my only way to access other files.So I tried Safeboot and tried to run Norton through the Admin, it gives me a warning box asking if I want a full system scan, I click yes, then nothing happens. I'm at the point of doing a System Restore (it's a Dell), but 1) I have no idea how to, and 2) what else can I do to fix this!
2012 GLI Autobahn 6MT
northvibe
Posts: 7641
Joined: Tue Jul 05, 2005 2:25 pm

Post by northvibe »

yeah you got malwared bad, those fake virus alerts are nasty buggers. Theres a thread here.....where I had a list of all the sweetest apps to use.I try to findEDIT:Here is a post from another threadQuote »Get the AVG free anti virus, you can try the spyware one. But Spyware Doctor was proven with tests done by my self and our tech shop and other places was found to find the most spyware and remove it. I run more than 1 app for spyware though as each one has its own little quirk. Just a side note, Symantec Corp. antivirus edition is awesome, the home user norton version is bloated. One of the better AV clients is nod32, panda or one that uses the kapersky engine.If you run windows, ALWAYS have on automatic OS updates so those exploits can be patched fast automatically. AV is on and updated, a scan once a week is good.Here are a list of apps that are good for the spyware side.free ones:Spyware TerminatorSpyware guurdspyware blasterA squared freeaimfix (removal of specific malware)spybotad-awareccleanerwindows defender (if you run xp or vista)advanced spyware removerPay one was just spyware doctor. For the free ones mix as many as you can. Most dont protect real time they just update and scan when you tell them too. Spyware terminator is realtime and free so it comes recommended to me from someone, but ive never used it. Hope this helps. once you know the name or type its easier to remove as you can google that and get a how to. I am sure you'll have to do some regedit and msconfig changes to stop start up crap.
Whelan
Posts: 3980
Joined: Tue Jan 23, 2007 10:30 pm

Re: (northvibe)

Post by Whelan »

It also has Military time on there now, I found this on Google, sounds pretty much like what I have, do the steps sound good?1. * Clean your Cache and Cookies in IE:Close all instances of Outlook Express and Internet Explorer Go to Control Panel > Internet Options > General tabUnder Browsing History, click Delete. Click Delete Files, Delete cookies and Delete historyClick Close below.* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):Go to Tools > Options.Click Privacy in the menu..Click the Clear now button below.. A new window will popup what to clear.Select all and click the Clear button again.Click OK to close the Options window* Clean other Temporary files + Recycle binGo to start > run and type: cleanmgr and click ok.Let it scan your system for files to remove.Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.Press OK to remove them.2. Please download Malwarebytes' Anti-Malware from Here or HereDoubleclick mbam-setup.exe to install the application.Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.If an update is found, it will download and install the latest version.Once the program has loaded, select "Perform Quick Scan", then click Scan.The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply along with a fresh HijackThis log.Extra Note:If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.3. Please visit this webpage for instructions for downloading and running ComboFix:http://www.bleepingcomputer.co...bofixPlease ensure you read this guide carefully and install the Recovery Console first (not for Windows Vista users !).The Windows Recovery Console will allow you to boot up into a special recovery mode, in case your computer has a problem after an attempted removal of malware. This allows us to help you. (WinXP SP3 users, please download the appropriate SP2 file, Home or Pro, to install the RC)In the event you already have Combofix, delete your current version and download the latest version as described in the tutorial.It must be saved directly to your desktop.Note: Make sure not to click ComboFix's window while it's running. That may cause it to stall or freeze.
2012 GLI Autobahn 6MT
northvibe
Posts: 7641
Joined: Tue Jul 05, 2005 2:25 pm

Post by northvibe »

yeah thats a basic guide to getting that stupid fake virus software off. Last I tried it it worked on a work machine. It may of come back though....ccleaner will also do temp files etc. asquared will get a bunch of stuffmalwarebytes is okay but its like a trial version or somethinghijack this log is almost a must these days, if you post that up its easier to get help.
bull77
Posts: 1976
Joined: Wed Mar 08, 2006 2:27 am
Location: Ottawa

Re: Some kind of virus I think (Whelan)

Post by bull77 »

Quote, originally posted by Whelan »SI'm at the point of doing a System Restore (it's a Dell), but 1) I have no idea how to, and 2) what else can I do to fix this!whats with all the spyware issues? Are you guys searching for nude Palin pics??? anyways try some of the tools in this thread:http://forums.genvibe.com/zerothread?id=35181and if you want to revert back to factory defaults on a dell --- do this:reboot -- at the dell logo, press ctrl + f11 -- you "should" go into a PC Restore screen -- follow the steps -- easy stuff.if you're running vista -- reboot and press F9, at the dell logo, to get to the advanced startup menu --- from here there should be an option to repair your pc and then follow the steps to do a restore.
User avatar
808 Vibes
Posts: 3923
Joined: Fri May 12, 2006 2:53 pm

Re: Some kind of virus I think (bull77)

Post by 808 Vibes »

Quote, originally posted by bull77 »whats with all the spyware issues? Are you guys searching for nude Palin pics??? HAHAHAAA Would a system restore of a few days ago help?
~ ALIS VOLAT PROPRIIS ~
ou.grizzly
Posts: 2660
Joined: Sat Mar 01, 2008 5:26 pm

Re: Some kind of virus I think (Whelan)

Post by ou.grizzly »

You need to use Tylenol, drink plenty of clear fluids, and get rest. Make sure to wash your hands, get a new cup every time you gargle, and dispose of your toothbrush daily. Also, make sure to use tissue and discard them right away. To alleviate congestion (engorgement of blood), use a decongestant, an antihistamine, and avoid pornography websites from now on. Keep us posted.
2009 Jet Black 2.4L Auto / Fogs / 17" Alum / Clear Bra / Camry Leather Shift Knob / GT Rear Spoiler
2013 Polished Metallic Honda CR-V EX-L Navi
jimincalif
Posts: 622
Joined: Sat Jul 12, 2003 1:59 am

Post by jimincalif »

My son recently got a nasty one that did much of this and disabled Task Manager. Spybot killed it enough that I could run Task Manager, but it would still come back, it also replaced the desktop background. I think it was called "webhancer". Very bad.I ran spybot, Lavasoft and then I went into msconfig and looked at the processes on the startup tab, you can google them to see what they are, disable ones that are not supposed to be there. Google your symtoms to try to find out the name of the one you have. If you can get a name you can google it and find instructions to kill it for good.For webhancer I also opened the registry with regedit and searched for webhancer and deleted those entries. I found the program and folder names in my google searching and renamed those (then later deleted).Finally, another message board pointed me to Stopzilla (which you have to pay for), I ran this and it also found a few traces and cleaned them up. Been 4 weeks now and still good.Whoever releases this stuff should be shot.
"We contend that for a nation to tax itself into prosperity is like a man standing in a bucket and trying to lift himself up by the handle." - Winston Churchill---------------------------------Who is John Galt?2 Vibes, 03GT & 07 base (kids drive)1993 Lexus LS4001980 Fiat Spider
Whelan
Posts: 3980
Joined: Tue Jan 23, 2007 10:30 pm

Re: (jimincalif)

Post by Whelan »

Well its fixed!I got the Malware, it found 50 items infected with trojan and hijacker stuff. Once that cleaned up a few items were deleted from the registry that could not be fixed. Upon rebooting I updated my Norton to 2009 and ran my Adaware. That found 20 items that I cleaned up.Right now Norton is doing a full system scan just to make sure. But all my icons came back, time is normal no longer military, and the computer is running very well actually.
2012 GLI Autobahn 6MT
Post Reply