Annoying virus - Please help !

Author
Discussion

Sheets Tabuer

19,167 posts

217 months

Saturday 28th August 2010
quotequote all
Ok it is not a virus because it doesn't self replicate, it is malware.

If you are scanning your pc without killing the process you are pissing in the wind, get rkill and run it, you may have to run it a few times before it kills it then run malwarebytes, then download ad-aware and update it and run it, that should clear it.

you should be able to get in safe mode you probably are not catching the 2 second window.

Anyhow this malware is written by a 4 year old so the above steps should remove it.

TheEnd

15,370 posts

190 months

Saturday 28th August 2010
quotequote all
I had to "fix" something similar a few weeks ago, pop ups that look like the MS warning from the taskbar, taskmanager locked out, and the guy who owned the laptop wasn't about either, so on a guest account.

he got a recovery console format instead!

combofix is pretty good at removing the awkward ones



Edited by TheEnd on Saturday 28th August 01:51

lestag

4,614 posts

278 months

Saturday 28th August 2010
quotequote all
try Hirens boot CD
http://www.hirensbootcd.net/download.html
http://www.hirensbootcd.net/download/Hirens.BootCD...

download it , unpack it (on another PC) and burn it onto a CD using the executable in the zip file.
Then put it in your CD drive and turn the PC on it should boot from the CD
Choose to run mini windows XP
and in the system tray will be hirenscd tools app select what you want off there
it has malware bytes , super anti spyware etc.

the advantage of using the boot CD is that your hard drive is effectively inert and there is no malware running, so it is easier for the AV tools to clean the hard disk

bigdods

7,174 posts

229 months

Saturday 28th August 2010
quotequote all
Egg Chaser said:
Sheets Tabuer said:
Which version of windows do you have?

how old is your pc, is it a usb keyboard?
Windows XP and a wireless usb keyboard
on my microsoft wireless keyboard I have to press flock first if windows hasnt booted. The function keys then work correctly and I can F8. Worth a try.

Vespula

2,993 posts

178 months

Saturday 28th August 2010
quotequote all
Sheets Tabuer said:
I now run IE if I have to use it in a programme called sandibox, that isolates the IE process and won't let things that run in IE run on your PC.
Interesting, but it is actually called Sandboxie.

Link: http://www.sandboxie.com/

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
bigdods said:
Egg Chaser said:
Sheets Tabuer said:
Which version of windows do you have?

how old is your pc, is it a usb keyboard?
Windows XP and a wireless usb keyboard
on my microsoft wireless keyboard I have to press flock first if windows hasnt booted. The function keys then work correctly and I can F8. Worth a try.
flock? confused

va1o

16,040 posts

209 months

Saturday 28th August 2010
quotequote all
I think he means F lock

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
va1o said:
I think he means F lock
My keyboard doesn't have an F-lock key...

MH

1,267 posts

268 months

Saturday 28th August 2010
quotequote all
Aye, this one's a pain in the arse. I had it the other week. It puts something in your registry controlset settings or Windows\CurrentVersion\Run to start itself up when you start windows. You can fix it yourself if you can remove that when in safe mode.
After that it sets IE to use a proxy (which is the malware app) which is why you can't access the internet.
Once you've fixed your registry in safe mode, remove the file that it pointed to while in safe mode, startup normally, sort out the proxy setting in IE then download a suitable anti malware app and do a full scan.
Mike

va1o

16,040 posts

209 months

Saturday 28th August 2010
quotequote all
Have you got an old PS/2 keyboard you could use? Just as a way of booting into safe mode.

This connector:

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
Thanks everyone, sorted it now thumbup

Although I didn't need to go into safe mode

philthy

4,689 posts

242 months

Saturday 28th August 2010
quotequote all
Egg Chaser said:
Thanks everyone, sorted it now thumbup

Although I didn't need to go into safe mode
What worked for you?

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
philthy said:
Egg Chaser said:
Thanks everyone, sorted it now thumbup

Although I didn't need to go into safe mode
What worked for you?
Just ran rkill then Malwarebytes, then changed the proxy settings.

philthy

4,689 posts

242 months

Saturday 28th August 2010
quotequote all
Egg Chaser said:
Just ran rkill then Malwarebytes, then changed the proxy settings.
There isn't much that malwarebytes doesn't catch, eventually.
Glad you're sorted.

Egg Chaser

Original Poster:

4,954 posts

169 months

Saturday 28th August 2010
quotequote all
philthy said:
Egg Chaser said:
Just ran rkill then Malwarebytes, then changed the proxy settings.
There isn't much that malwarebytes doesn't catch, eventually.
Glad you're sorted.
Yep, had to use it a couple of times before and it hasn't let me down yet.

Thanks smile

Raverbaby

896 posts

188 months

Saturday 28th August 2010
quotequote all
Is it AV Security suite?

http://www.bleepingcomputer.com/virus-removal/remo...

It was a PITA for me to remove but got there with above guide.

As above I'm sure you will need to plug an older keyboard(ps/2?) in to pc in order for it to be recognized straight away to hit F8

Egg Chaser

Original Poster:

4,954 posts

169 months

Tuesday 7th September 2010
quotequote all
Since I've got rid of this crap, I keep getting 3 error messages at startup:








Anybody got any ideas what these mean? And if its not important, how do I stop these from popping up everytime? (they're starting to get annoying!)

va1o

16,040 posts

209 months

Tuesday 7th September 2010
quotequote all
Erm not sure exactly, have you looked in MSCONFIG to see if they are on the startup list? Bit drunk at the moment so unable to give any intelligent advice sorry tongue out

FourWheelDrift

88,822 posts

286 months

Tuesday 7th September 2010
quotequote all
Try this time to get into safe mode and run Malwarebytes.

That might fix it.

TheEnd

15,370 posts

190 months

Tuesday 7th September 2010
quotequote all
I think that means the Run DMC has a few virus entries left in it, and is trying to start them, although the main bit has gone.

msconfig might show the bits.