Home General Discussion

Virus/Trojan help?

polycounter lvl 20
Offline / Send Message
Kevin Johnstone polycounter lvl 20
Hey folks,

I'm in a bind here, somehow something nasty got into my home pc and it won't go past
the desktop anymore. It freezes after displaying the clock in the right hand corner, doesn't
get as far as loading the program icons so something reall stopped it in its tracks
as theres nothing i can do there.

I'm wondering if any of you have recommendations for programs that could fix this, I'm pretty
sure its spyware as I was tired and I clicked a pop up by accident that then popped up a 'good luck' message and then I started having problems.

Windows reported that I was under attack and started running some realtime spyware 2008 XP protector that discovered a bunch of trojans and worms and I had to go online and register it
before it would delete them, which I did and now regret as im paranoid enough now that I'm
questioning whether that was a real program as it didnt stop the computer freezing up
later.

Any advice would be appreciated, is there something I can buy and run on the computer from the boot menu or something ?

Replies

  • Pedro Amorim
    try running the computer in safe mode and see what happens. maybe you can install a spyware detector by then.
  • IronHawk
    Offline / Send Message
    IronHawk polycounter lvl 10
    Give this a shot http://www.ultimatebootcd.com/

    Otherwise if you have another PC slave the drive and then scan it from there or drop it in a usb drive housing and scan it through usb so the bugger wont load on boot.

    Good luck ;)
  • Japhir
    Offline / Send Message
    Japhir polycounter lvl 17
    the first thing i'd try is to go ctrl+alt+delete and then to the processes tab, then add a new process called "explorer.exe" and see if it will start. But i don't know shit about computerstuff so i'll shut up now.
  • PolyHertz
    Offline / Send Message
    PolyHertz polycount lvl 666
    Hey folks,
    realtime spyware 2008 XP protector that discovered a bunch of trojans and worms and I had to go online and register it
    before it would delete them, which I did

    Bad move. XP has no built in anti-virus/anti-spyware software, you were tricked.

    Ironhawks suggestion is good to scan it as a slave drive, but in a few cases can result in infecting the master drive too.
  • Target_Renegade
    Offline / Send Message
    Target_Renegade polycounter lvl 11
    If you haven't already googled and tried to find the cure then I would suggest the following.

    1) Run in safe mode and dload and run a program called HijackThis. There are usually some forums where they'll take a look at the log created and give suggestions.

    2) What I'd do would be to re-install windows on top of the existing windows. What should happen is that the registries will be back to normal. This would only be so that I can get at the files I want to keep and back those up. Once done, you'll have to go through the tedious bs of formatting the HDD, then re-installing everything, but once you do it'll feel like having a shower after sweating for 2 months.

    Thats what I've done in the past and it worked for me.
  • Gmanx
    Offline / Send Message
    Gmanx polycounter lvl 19
    Try googling 'majorgeeks'. Their site has an established procedure you can follow to analyse the problem - and the guys in the forums love a challenge, so they'll do their best to help. They've got me out of trojan scrapes a couple of times.
  • bluekangaroo
    Offline / Send Message
    bluekangaroo polycounter lvl 13
    If you haven't already googled and tried to find the cure then I would suggest the following.

    1) Run in safe mode and dload and run a program called HijackThis. There are usually some forums where they'll take a look at the log created and give suggestions.

    2) What I'd do would be to re-install windows on top of the existing windows. What should happen is that the registries will be back to normal. This would only be so that I can get at the files I want to keep and back those up. Once done, you'll have to go through the tedious bs of formatting the HDD, then re-installing everything, but once you do it'll feel like having a shower after sweating for 2 months.

    Thats what I've done in the past and it worked for me.

    That is good advice....

    I recently had a similar problem and I'd also suggest to go into System Restore and set up a manual save/checkpoint right after installing all your main apps and programs.... and then If you ever get any more trojans or spyware in the future you can just reset back to your save point without having to go thru any more reinstalls ever again
  • PfhorRunner
    Offline / Send Message
    PfhorRunner polycounter lvl 18
    Hiren's boot CD has some good removal tools, and is very handy for any technician to have. There are also Linux boot disks that allow you to boot off the disk into (omg) linux, and run windows virus removals on the drives.

    You don't want to try to remove the viruses in normal mode, safemode is helpful because it has net access to download the latest definitions for certain Anti-viruses.

    There are also tools made for people that do this for a living, they tend to drive around black and white VW bugs, and work for a major corporation. You might check in to what tools they use.
  • IronHawk
    Offline / Send Message
    IronHawk polycounter lvl 10
    that ultimate boot cd has 3 apps 2 for virus and one for malware can boot it from cd or thumbdrive. it's also free.
  • Kevin Johnstone
    Offline / Send Message
    Kevin Johnstone polycounter lvl 20
    thanks for the help folks, i'll let you know how it goes
  • Geezus
    Offline / Send Message
    Geezus mod
    Snag a copy of Adaware, Spybot, and HijackThis! from your work PC/friend's PC. Get those on a CD (with the definition updates).

    Hit F8 on boot, get into safe mode
    Run HijackThis! and check anything that's obvious (or check the online forums for recommendations.)
    Reboot back into Safe mode, Start > Cmd > MSconfig > Startup remove anything obvious, or check online for recommendations.
    Reboot back into Safe mode, Run SpyBot (whatever the deepest/longest scan is) remove all crap.
    Reboot back into Safe mode, Run Adaware (deepest/longest scan). remove all crap.


    Both Adaware and Spybot may ask you to reboot to finish removal.

    However, In the long run, it's best to try to backup any data you can, and just fdisk the drive and reinstall the OS.
    Hope it works out for ya.....and I hope the midget porn was worth it! :)

    [edit]
    I just read some previous recommendations in this thread...and I would save the "Dirty Install" of windows that Target recommends for a very last resort. If you can get into Safe Mode, it's always best to try and work from there to solve your problems enough to backup your data before you fdisk/format/reinstall.

    I've heard good things about the Geek Squad at the Crossroads Best Buy, if you don't have a "computer buddy" to help ya out. Something like this should cost $25-$40 with a Geek Squad.
    [/edit]
  • Robert Headley
    Offline / Send Message
    Robert Headley polycounter lvl 18
    another thing you can do, since it is loading up the desktop.

    Hold down shift while booting and it should prevent all non-windows stuff for booting.

    I recommend you get a program collection called Hitman Pro
    It is actually a combination of programs that run automagically.

    http://www.hitmanpro.nl/hitmanpro/

    That is if the holding shift, or safe mode thing works.

    Good Luck.
  • Marine
    Offline / Send Message
    Marine polycounter lvl 19
    sounds like the same one my mum had, it even added a bsod screen saver and changed the background to a warning about being infected. that one was calling itself "antivirus xp 2008" got rid of it with spybot s&d in safe mode
  • Target_Renegade
    Offline / Send Message
    Target_Renegade polycounter lvl 11
    i know of someone who had the BSOD background, funnily enough if you scrolled to the top, there was an option to close the window/background. Best best is to run in safe mode and take it from there and make sure when you're using spyware removal software, to turn off your internet connection.
  • PfhorRunner
    Offline / Send Message
    PfhorRunner polycounter lvl 18
    Geezus wrote: »
    I've heard good things about the Geek Squad at the Crossroads Best Buy, if you don't have a "computer buddy" to help ya out. Something like this should cost $25-$40 with a Geek Squad.
    [/edit]

    $199.99 for virus removal.

    Snagging a copy of their tools is much cheaper. They're supposedly set up to be completely automatic, and run from the windows PE, with net access to download the latest updates. something like 7 or 8 removal tools.
  • Rob Galanakis
    http://icrontic.com/forum/

    I don't know why people would go to PC for virus help- I wouldn't go to Icrontic for art help :) They are really experts in virus/spyware and are extremely helpful.
  • Geezus
    Offline / Send Message
    Geezus mod
    $199.99 for virus removal.

    Snagging a copy of their tools is much cheaper. They're supposedly set up to be completely automatic, and run from the windows PE, with net access to download the latest updates. something like 7 or 8 removal tools.


    Hrm, rates have gone up since I ran my Geek Squad several years back. Usually Malware/Spyware was part of a "System Tuneup" which was $25. Some other things would pop up, but $199? really? Is that for In-Home or store work? That seems ridiculously overpriced.
  • PfhorRunner
    Offline / Send Message
    PfhorRunner polycounter lvl 18
    Geezus wrote: »
    Hrm, rates have gone up since I ran my Geek Squad several years back. Usually Malware/Spyware was part of a "System Tuneup" which was $25. Some other things would pop up, but $199? really? Is that for In-Home or store work? That seems ridiculously overpriced.

    In store price. This does not include a data backup, or re-installation of Anti-Virus software. System Tune-ups run you $99.99. Data backups are another $99.99, but only for 9.4GB, for more than that it is $159.99.

    The only thing below $29.99 on their price sheet is a $19.99 physical cleaning, or a $19.99 T-shirt...

    "Optimizations" are $29.99

    This is all in store, for in-home service its normally at least $99.99 more.

    Prices got jacked WAY up, but its only because people don't know how to do it, and since GeekSquad is such a known name now, they can get away with it. They're "trusted" which means even if the prices were jacked up higher, I doubt they would have a problem maintaining a ludicrous amount of business.
  • PolyHertz
    Offline / Send Message
    PolyHertz polycount lvl 666
    Yep, $200 for 'adv diag and repair' as it's called, which means they test the hardware for defects and scan/clean spyware/viruses (95% of which is done automaticaly by the MRI disc). About 2 years ago they decided to cram most of their services into that package to force people to pay huge sums. And that's in store, can't remember the in-home price but its alot worse (Used to work for GeekSquad).

    'Optimizations' are a joke btw, all the techs are required to do is do windows updates and run a registry tweak program. I made it my mission to do a 'real' optimization whenever possible back then, but most the time they'll only do the minimum.

    Oh, and the prices didn't detract from buisness at all. The one I was at was swamped from open till close every day (wasn't uncommon to stay till 2am just to keep the backlog managable).
  • J Randall
    Offline / Send Message
    J Randall polycounter lvl 15
    Thanks for the pointers doin the same thing, whats with these viruses that advertize an antivirus?
  • Ged
    Offline / Send Message
    Ged interpolator
    PolyHertz wrote: »
    Bad move. XP has no built in anti-virus/anti-spyware software, you were tricked.

    Ironhawks suggestion is good to scan it as a slave drive, but in a few cases can result in infecting the master drive too.

    my virus protection(AVG) just came up with a warning it had found a trojan so I told it to fix it but after that I just had this xp virus protection 2008 thing pop up on me too! so I quickly end tasked it.

    luckly I had read this thread so I never clicked any "I agree" button or anything I just end tasked it. Do you think I may still be at risk? Im running a virus check on my whole PC now.

    I just checked and I seem to have lost my screensaver options under display properties, damnit! this isnt good :(
  • bearkub
    Offline / Send Message
    bearkub polycounter lvl 20
    Yah, there are a bunch of those that change your background to a big "WARNING" or whatever. I had to wipe a ton of them out at work. Basically, from what I gathered searching for info on them, the spyware gets on your machine which actually comes from, you guessed it, the people that make the AntiSpyware that is being advertised. The "removal tool" you buy only removes the stuff that generated the ads in the first place. Wish I could find the links again to back that up...

    Another one to look out for is AntiSpySpider. Man, that was a nasty bastard to get rid of. Same stuff, changes your wallpaper, your screensaver, jacks up your browser. It took a bit of manhandling and a little anti-spyware cocktail to get rid of that thing. :P

    Fun times!
  • Ged
    Offline / Send Message
    Ged interpolator
    well I read up on it and was recommended to use http://www.malwarebytes.org/ and it found 10 files/entries so I fixed all of them and I think Im all ok now, but that was scary! these are really nasty things! cant believe a website could access my registry and change the entries for screensaver properties to not show. Thats really deep dangerous territory and I didnt even click on a banner or agree to anything, no downloads, no information at all, I was just browsing as usual and it popped up.
Sign In or Register to comment.