Help! I have a virus ...........  |
|
It came through MSN messenger and I can't get rid of it! I was in the middle of a conversation with someone when it looked as if the other person asked "is this really you?" and it had what looked like a link to an image attached to it. So I stupidly clicked the link and it was an .exe file which is causing havoc with my pc! It keeps shutting down, my desktop disappears, there are some websites I just can't open (Facebook for example) and my browser keeps switching to dating and gambling sites! Tried everything to get rid of it - I know exactly the files that are infected but I can't quarantine or delete them because I get a message that other programs are using them (they're all system32 files). AVG and Trend Micro identify them but can't quarantine them and Norton can't deal with it either apparently! I've tried Unlocker and Killbox too but neither works. I also can't do a system restore. Tried it and it fails every time. Having searched for possible solutions online (and not being able to find one that works!) I now know that this "messenger" virus has been around for about 3 or 4 years so I wondered if anyone on here has had to deal with it, and if so how did you get rid of it? I really, really don't want to have to wipe my hard drive but at the moment it's looking like the only solution!
| |
| |
|
|
| | Los Angeles Tattoo Removal As seen on LA Ink& Dr. 90210! Schedule a Free Consultation Today. www.DrTATTOFF.com
| Fix Safe Mode Easily Spotmau PowerSuite 2007, Fix any PC& Windows Porblems. www.spotmau.com
| Hijackthis.Exe Free Download: Hijackthis.exe Repair Tool. 100% Safe& Guaranteed. Hijackthisexe.FreshPCFix.com
|
|
|
|
|
|
|
|
| 1. Cherokee_Rose (80) | 7 months ago | Oh No....i haven't never heard of it...i would try to go to bleeping computer.com they are really helpful there with these kind of things.I know they will tell you to download Ad-Aware,this is a good program you get it here Go to lavasoftusa.com to get it....Good Luck
| |
| |
|
|
Stiletto (3125) | 7 months ago | I haven't looked at that site yet so I'll try it - thanks!
| |
|
|
| Cherokee_Rose (80) | 7 months ago | you are very welcome..that is what they told me to do and it got rid of whatever it was....it is safe
| |
|
|
| Cherokee_Rose (80) | 7 months ago | Its called Ad-Aware 2007 its at the top of the page...click on free version
| |
|
|
sconibear (1168) | 7 months ago | sorry, i didn't see you mentioned "bleeping computer" Cherokee_Rose, another good site...a lot of the same people from "the elder geek".
| |
|
|
|
Los Angeles Tattoo Removal As seen on LA Ink & Dr. 90210! Schedule a Free Consultation Today. www.DrTATTOFF.com | add comment |
|
|
|
2. sconibear (1168) | 7 months ago | go to "The Elder Geek.com" they can fix anything. just sign up (it's a free forum) and post your problem. they'll walk you through it step by step. it might take a few minutes for someone to reply, so just be patient. they'll probably tell you to download "hijack this" which is a scan that will give you a report that they'll want to see. hope it works out for you. these guys know computers and have got me out of a couple messes.
| |
| |
|
|
Stiletto (3125) | 7 months ago | I've had a look at that site too - it's full of useful information for someone like me who doesn't know much about these things! I've tried a few things so far and it does seem to be working better but there's definitely still something on here so going to do the "hijack this" thing. Thanks!
| |
|
|
sconibear (1168) | 7 months ago | no problem. i've had similar problems to what you mention (pages and pop ups that come up and drive you nuts) there's something out there called "combo fix" that pretty much will knock anything out, and i have ran it on my own with no problems (it changes minor settings that you can fix) but it comes with a warning that you should only use it with a pro. walking you through it, but like i said, iv'e used it with no ill effects. anyways, just thought i'd mention it.
| |
|
|
Stiletto (3125) | 7 months ago | well - I have downloaded Combo fix but haven't used it yet. Was a bit nervous of using it because it sounds pretty powerful! However, it's good to know you've used it and your pc survived lol!
| |
|
|
santuccie (1795) | 7 months ago | By the way, just in case you (or someone with physical access to your computer) fall for a similar trick in the future, you might be interested in knowing how to lock the kernel. In order to start with Windows, malware must be able to install/modify a system service or driver, write to the registry, or both. Disabling write-access to these regions foils the attack. Here is one method that works on all versions of Windows 2000, XP, and Vista: http://invincible-windows.blogsplot.com/
| |
|
|
|
Fix Safe Mode Easily Spotmau PowerSuite 2007, Fix any PC & Windows Porblems. www.spotmau.com | add comment |
|
|
|
3. gabs8513 (17534) | 7 months ago | I have not had to deal with it Sweetie but it has popped up on my Messenger and I just ignored it as I know the Person I was talking to had not sent it I am sorry this happened to you and I think the only way that you can sort this is by totally reformatting the Computer Have you tried the free Anti Virus Antivir? I have had that one on my Computer for 5 years and it is great But if that one does not work you will have to reformat
| |
| |
|
|
Stiletto (3125) | 7 months ago | Hi Gabs - I haven't tried that anti-virus although in the last day or so I've downloaded that much stuff to try and fix this that I'm not sure what I've all got on this pc now lol! Will try that one too though xxx
| |
|
|
gabs8513 (17534) | 7 months ago | Just type Antivir into your Browser but do get rid of the others you downloaded because if you have to many on the Computer they will not work as good believe it or not, once you are on the Site just follow download Instructions if you need to know anything shout ok
| |
|
|
theprogamer (7373) | 7 months ago | Not so fast. Did you try my response Stilleto?
| |
|
|
Stiletto (3125) | 7 months ago | I'm going to get rid of this flipping thing first (even if it kills me - or my pc!) but will look at Antivir when my pc is back to normal. I've used AVG for ages and have always found it very good but it can't cope with this one! Although to be fair having read about the infection it seems most anti-virus programs can't deal with it anyway but I'm disappointed AVG let it through without even warning me.
| |
|
|
theprogamer (7373) | 7 months ago | Well the malware got through and did this due to your clicking it (many people do this). Many bad programs sliver in like this and they go right to work blocking antiviruses and attaching themselves to prevent removal under normal conditions. If you need some safety programs for consideration heres a list of 15 items you could use. Of course you'll have to pick and choose, but many of the programs are quite handy. Did I mention most of these are free to use... http://www.pcworld.com/ar...
| |
|
|
|
Stiletto (3125) | 7 months ago | That's another really useful link - thanks progamer!
| |
|
|
|
Hijackthis.Exe Free Download: Hijackthis.exe Repair Tool. 100% Safe & Guaranteed. Hijackthisexe.FreshPCFix.com | add comment |
|
|
|
4. theprogamer (7373) | 7 months ago | Try to restart your computer in safe mode to see what that does. It should be the F8 key in order to get to safe mode option when starting up. If you restart in safe mode there's a better chance the .exe won't start up(since safe mode cancels all non-essential startups). You can manually start your AVG, Trend and Norton in safemode. When in safe mode start up your anti-virus and run a scan. The scanner might be able to detect and deal with the program when its not running. Another option is to try to repair your operating system by getting the operating software or recovery disc and loading that in. You'll want to hit install and it'll check for previous installations of the OS. It should detect it and give you an option to repair the installation. http://www.michaelstevens...
| |
| |
|
|
Stiletto (3125) | 7 months ago | I've done so much stuff to it in the last couple of days and it is working better so I've obviously got rid of some things but it's still not ok so there is definitely something still on it. I'll try scanning in safe mode first to see if that works but if not I'll try to repair it. Thanks for the link!
| |
|
|
sconibear (1168) | 7 months ago | if you're going to go to the extreme of reformating or wiping clean your hard drive, i'd go ahead and try the combo fix you downloaded. just don't mess with it...let it run till it reboots your computer and gives you a report.
| |
|
|
Stiletto (3125) | 7 months ago | Well I've tried scanning in safe mode and unfortunately it didn't work. It detects the infected files but can't quarantine them and I can't delete them. The combo fix thing scared me a bit when it came up with the stat about 1 in 100 pc's don't survive the procedure - or something like that anyway! I so don't want to reformat though. I'm going to try the combo fix now and if that doesn't work then it's the repair.
| |
|
|
theprogamer (7373) | 7 months ago | There is AVG rootkit as another option and I left the link for it in a response above. If you don't want to do that, then its understandable. The only other thing I can think of trying is a system restore.
| |
|
|
Stiletto (3125) | 7 months ago | I was looking at AVG Rootkit actually when I followed your link. Hmm, I don't know ... I can't do a system restore because it won't let me. I've tried a few times but it keeps failing, which is apparently something that this particular virus does. I swear if I could get hold of the person responsible for this I would cause them physical harm lol!! I shall never again click on a link that comes through IM - no matter how genuine it looks.
| |
|
|
theprogamer (7373) | 7 months ago | I found this website which has removal tactics for a certain MSN messenger virus. Did yours come with a toolbar? Either way, should be worth a look. See if you have anything this website describes Stilleto http://www.technibble.com...
| |
|
|
|
Stiletto (3125) | 7 months ago | Thanks so much for those links - have had a look at them and the first one sounds a lot like what I have although I don't have a toolbar. Will try it in the morning. Its now 2am here and I've spent almost the whole day trying to get rid of this thing!! Will let you know how it goes!
| |
|
|
Stiletto (3125) | 7 months ago | Well it's finally gone I hope! Can't believe I've spent 2 or 3 days on this. I will never again click a link that comes through IM anyway - I've learned my lesson. I ended up using Combo Fix which seemed to more or less fix it completely but I also used AVG anti-spyware which seems really effective. Anyway, thank you so much for your help with this progamer - I now intend to make my pc like a fortress, not going through all this again!
| |
|
|
theprogamer (7373) | 7 months ago | Okay, great to hear! Glad to help Stilleto... hopefully you know that. And about AVG antivirus... For a real time scanner shield after AVG-Antivirus "full" expires, you should look into Spyware Terminator. That has a realtime shield.
| |
|
|
Stiletto (3125) | 7 months ago | You're always so smart and helpful, to be honest I was really hoping you would come into this discussion. We've discussed this before but you would have an 11 star if it was up to me xx Anyway I will be very, very careful in future and am going to check out all the info that's been left on this discussion so there will hopefully be no repeat disasters in the future!
| |
|
|
|
|
|
5. itsmepinky (1146) | 7 months ago | I am not a computer genius, but i have experienced this several times. I got a virus from other sites & i had to format my pc many times. Maybe u can call u computer vendor & ask him to sort out the issue. All d best ~pinks~
| |
| |
|
|
Stiletto (3125) | 7 months ago | I'm trying to avoid having to pay someone to sort it out but I may well end up having to do that lol! Thanks for responding itsmepinky.
| |
|
|
|
|
|
6. santuccie (1795)  | 7 months ago | When your scanners identify the files, take note of the names of these files and the paths to them. Since they can't be disinfected or quarantined in normal mode, you'll have to do battle with these parasites in safe mode. I see another poster has already recommended this. Before you try deleting files, I recommend you download and run AVG Anti-Spyware (formerly Ewido): http://www.ewido.net/en/ If some of your preexisting system services or drivers were modified by this malware, AVGAS would be one of your best bets at identifying and removing the infection without crippling your system. Run Norton again, and see what's left. Still in safe mode, navigate to the folder and delete the files named. Run HijackThis (I believe you mentioned in another comment that you've tried this already, or were about to), then save a log file. Post your log file in a forum like this one: http://www.whatthetech.com/hijackthis/ I'd just as soon tell you to post the log file here, but I'm not sure myLot would approve. If registry keys were left behind (most likely), it's possible the infection may come back. You may have to go through this process a second time in safe mode, using information gathered from your HJT logfile to remove the registry keys as well as the installed files to take this bugger down. If all else fails, do a repair install. Did you say you have a copy of a Microsoft Windows CD? You can restore your operating system without losing your applications, settings, or data: http://www.michaelstevens... Good luck!
| |
| |
|
|
sconibear (1168) | 7 months ago | just run the "combo fix" you already downloaded There's a 99.9999999% percent chance this will fix your problem. it's kinda scary, but i've used it on my own like 3 times now and never had any problems with it, and it knocked out the same kind of viruses you describe. if you're going to resort to restoring your operating system anyways, then no harm, no foul...
| |
|
|
santuccie (1795) | 7 months ago | I understand. But really, it's ideal to reserve the repair installation as a last resort. Ewido was always the best at removing a process-injecting Trojan without crashing Windows, even before it surpassed Trojan Hunter in sheer detection rate, and TDS-3 dropped out of the race. We don't know yet whether this is what the OP has, but unless she has a rootkit (which her AV scanners likely wouldn't see at all), Ewido is a solid first choice. Be it a process-injecting Trojan or a polymorphic Trojan, this product is most likely to find and fix the problem without giving the user the runaround. I believe you when you say you've used Combo Fix without any problems, but I see a lot of cries for help from people who weren't so lucky.
| |
|
|
Stiletto (3125) | 7 months ago | Well I've spent all day on it but finally it's gone (I hope!). I scanned in safe mode and it got some but not all of the infected files. I also downloaded AVG Anti-Spyware which removed a whole load of stuff but still not the files I wanted. No matter what I did it wouldn't let me do a repair install. In desperation I ran Combo Fix and it deleted a whole load of stuff. It was pretty scary though but at least my pc survived! So after another scan I managed to delete everything that was infected. Apparently what I had was something that Trend call cryp_tap_2 some sort of worm thing I think! It looks like it's gone now anyway. I'm not sure if everything is working perfectly but it seems to be ok so far. Thank you so much both of you for your help, I really appreciate it. I'm hopeless when it comes to stuff like this - I'm not technically minded at all.
| |
|
|
theprogamer (7373) | 7 months ago | Hopefully the thing really is gone, but there can be self-replication. Just for security sake I would recommend rechecking the other "anti-Messenger virus" links I had posted, just in case the processes/files listed come up on task manager or in msconfig. Anything's possible with viruses.
| |
|
|
Stiletto (3125) | 7 months ago | I'll do that progamer because the last thing I want is it reappearing! Actually those forums have lots of useful information anyway for someone who is as clueless as I am about these things. I've bookmarked them all. I suppose the positive is that I've found out about a whole lot of things I never even knew existed! Thanks again for all your help
| |
|
|
|
Stiletto (3125) | 7 months ago | Thanks for the link santuccie. I notice it's your blog so I'm going to add it again here because the link you posted didn't work (it had an extra l in blogspot!) just in case others reading this discussion want to look at it http://invincible-windows.blogspot.com/ I've bookmarked it anyway so I can look through the info on it. Also I've no doubt I'll have another disaster at some point so at least I'll know where to look next time!! Thanks again for all your help
| |
|
|
|
santuccie (1795) | 7 months ago | Oh yeah, one more thing. Once you're fairly certain everything is okay, you might want to install a drive imaging program that can restore your entire operating system, even if a virus hits it so hard that it can no longer boot. The undisputed leader of this industry is Acronis True Image, and they just so happen to be having a promo right now. Register now for a free copy of True Image version 8, so you'll never have to reinstall Windows again: http://www.acronis.co.uk/mag/pcpro/ati8pe If you have any more questions, or if you need assistance, feel free to add me as a friend.
| |
|
|
Stiletto (3125) | 7 months ago | Thanks - I'm sending you a friends request anyway.
| |
|
|
|
|
|
7. Asylum (3236) | 7 months ago | I was going to suggest System Restore, which is an easy way to "get out of jail" so to speak, but then I read that you had already tried this. It is not uncommon nowadays for a virus to disable System Restore. I do not know which virus you have and never use instant messenger programs myself, which makes it rather difficult for me to advise. If you have a floppy drive then you could try booting up onto a floppy boot disk and deleting the file through DOS, because the file will not be in use then. If the worst happens and you have to reformat, then consider making a complete backup of the system once you have reconfigured everything. With an external backup of a good installation it would be easier in the future to turn the clock back even without System Restore.
| |
| |
|
|
Stiletto (3125) | 7 months ago | Thanks for responding Asylum - I've finally got rid of it but it's taken days!! Never again will I click a link that comes through messenger! Not being able to do a System Restore was a big worry and then when I couldn't even reinstall XP I was REALLY panicking lol!! However, it's finally fixed and to be honest I did so much to it I'm not really sure what it was that worked in the end.
| |
|
|
|
|
|
8. TheSpy (3383) | 6 months ago | Go to www.avg.com Download their free virus protector. Run it once and everything will be cleaned up for you. Every morning they download new protection for you computer. Have a great evening. Ivor:)
| |
| |
|
|
Stiletto (3125) | 6 months ago | Hi Ivor - I've done that with AVG and I do usually find it really good, plus it's free of course which is even better! It was just really stupid of me to click on the darned link but I've learned my lesson now - will never do it again on msn messenger anyway. Thanks for responding
| |
|
|
TheSpy (3383) | 6 months ago | I'm glad you use AVG I hope you had a nice Mothers Day.
| |
|
|
TheSpy (3383) | 5 months ago | Where are you I miss you?
| |
|
|
|
|
|
9. tigerdragon (2589) | 6 months ago | since you are going to wipe your drive out then i would suggest that you store your files to another hard drive. if you are using as desktop pc then i would suggest that you get another hard drive and enslave it so the only one that would be infected if you get a virus again would be your drive c and not your drive d.
| |
| |
|
|
|
|
|
| 10. tmmrocks (1) | 2 months ago | hi plz help me my dad got rid of the virus but then it came back the thing we use said sorry a virus has been found now deleting all programes lucly i stoped it be for it deleted all my saved work and i saved internet explorer my dad said i did this to our pc i told my dad 2 fix it but he said i broke is my problem but i didn't can some one plz plz help me i am really worred i have nooooooooo money to my stuff 2 get rid of it and by the way i can not download or do any thing to help and i do not have all programes or word or any thing else plz help
| |
| |
|
|
|
|
|
|
|
|
|