1. Log in now to remove adverts - no adverts at all to registered members!

Virus

Discussion in 'General Chat' started by stopmeandslapme, Jan 31, 2012.

  1. stopmeandslapme

    stopmeandslapme Well-Known Member

    Joined:
    Mar 24, 2011
    Messages:
    20,321
    Likes Received:
    10,268
    My mate has managed to get his comp infected with a brand new virus and I'm trying to sort it out.

    Even booted in Safe Mode, it has made so many changes: can't see programs on start menu, can't see any files or folders even in DOS, can run System Restore but it doesn't do anything, wouldn't let me install Java (needed for online scan) logged in as Administrator. Absolutely ****ed. Have left it running House Call full system scan, have to walk the dogs now.

    Any suggestions on how to proceed would be gratefully received.

    PS: If you get an email from Fedex containing a shipping document, don't open it!
     
    #1
  2. biggerbossman

    biggerbossman New Member

    Joined:
    Jan 30, 2012
    Messages:
    494
    Likes Received:
    0
    HN51? Everyone get vaccinated.......Do you like WWF?
     
    #2
  3. eddieveeee

    eddieveeee New Member

    Joined:
    Jun 2, 2011
    Messages:
    3,535
    Likes Received:
    2
    what os?
     
    #3
  4. Go G YellowScreen

    Go G YellowScreen Well-Known Member

    Joined:
    Dec 16, 2011
    Messages:
    6,610
    Likes Received:
    58
    please log in to view this image
     
    #4
  5. Vilsmeier-Haack Reaction

    Vilsmeier-Haack Reaction Well-Known Member

    Joined:
    Jan 27, 2011
    Messages:
    11,691
    Likes Received:
    1,014
    Sounds like windows. Also I make a point of not clicking links which say "brand new virus" <laugh>
     
    #5
  6. Vilsmeier-Haack Reaction

    Vilsmeier-Haack Reaction Well-Known Member

    Joined:
    Jan 27, 2011
    Messages:
    11,691
    Likes Received:
    1,014
    Have you tried rebooting the ****er, you will lose everything but should get rid of virus
     
    #6
  7. stopmeandslapme

    stopmeandslapme Well-Known Member

    Joined:
    Mar 24, 2011
    Messages:
    20,321
    Likes Received:
    10,268
    You mean reinstalling Windows? Probably will have to but need to rescue stuff from comp first, it's his business computer with several years of accounts, etc on it.

    It's Windows XP.
     
    #7
  8. biggerbossman

    biggerbossman New Member

    Joined:
    Jan 30, 2012
    Messages:
    494
    Likes Received:
    0
    Take the battery out and put in once more
     
    #8
  9. eddieveeee

    eddieveeee New Member

    Joined:
    Jun 2, 2011
    Messages:
    3,535
    Likes Received:
    2
    Sounds like system restore virus, it hides files in start menu and everywhere

    when u run system restore does it ask for activation key?
     
    #9
  10. biggerbossman

    biggerbossman New Member

    Joined:
    Jan 30, 2012
    Messages:
    494
    Likes Received:
    0
    <coin-tel> ,,,,,,,,
     
    #10

  11. eddieveeee

    eddieveeee New Member

    Joined:
    Jun 2, 2011
    Messages:
    3,535
    Likes Received:
    2
    Delete System Restore files:

    %LocalAppData%\
    %LocalAppData%\.exe
    %LocalAppData%\~
    %LocalAppData%\~
    %StartMenu%\Programs\System Restore\
    %StartMenu%\Programs\System Restore\System Restore.lnk
    %StartMenu%\Programs\System Restore\Uninstall System Restore.lnk
    %Temp%\smtmp\
    %Temp%\smtmp\1
    %Temp%\smtmp\1
    %Temp%\smtmp\2
    %Temp%\smtmp\3
    %Temp%\smtmp\4
    %UserProfile%\Desktop\System Restore.lnk


    Delete System Restore registry entries:

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main "Use FormSuggest" = 'Yes'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "CertificateRevocation" = '0'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings "WarnonBadCertRecving" = '0'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop "NoChangingWallPaper" = '1'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations "LowRiskFileTypes" =
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments "SaveZoneInformation" = '1'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoDesktop" = '1'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System "DisableTaskMgr" = '1'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ".exe"
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run ""
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system "DisableTaskMgr" = '1'
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = 'no'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "Hidden" = '0'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced "ShowSuperHidden" = '0'
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU "MRUList"
     
    #11
  12. RAVENBLACK

    RAVENBLACK Well-Known Member

    Joined:
    Jan 21, 2010
    Messages:
    24,877
    Likes Received:
    265
    sounds to me like you have a gltch with the di-lithium crstals.

    What to do is disenfranchise the regulator and perform a multilateral sweep of the coabis files and then reinstate the nebulus using the multifunctional tricoder.

    Any problems give me a shout.
     
    #12
  13. stopmeandslapme

    stopmeandslapme Well-Known Member

    Joined:
    Mar 24, 2011
    Messages:
    20,321
    Likes Received:
    10,268
    No it doesn't ask for key, it let's me select a restore point then when I click "Next", nothing happens.

    Cheers for the registry entries, I'll have a look at those when I'm back there.
     
    #13
  14. eddieveeee

    eddieveeee New Member

    Joined:
    Jun 2, 2011
    Messages:
    3,535
    Likes Received:
    2
    If this is the system restore you are seeing then that is the problem, you can use malwarebytes to remove it if u dont want to do it manually, if its none of these then i dont know.

    please log in to view this image


    please log in to view this image
     
    #14
  15. Sam Axe

    Sam Axe Active Member

    Joined:
    Jan 31, 2011
    Messages:
    7,355
    Likes Received:
    7
    Delete the System32 folder and reboot. Problem solved.
     
    #15
  16. biggerbossman

    biggerbossman New Member

    Joined:
    Jan 30, 2012
    Messages:
    494
    Likes Received:
    0
    They tried that Sam....
     
    #16
  17. stopmeandslapme

    stopmeandslapme Well-Known Member

    Joined:
    Mar 24, 2011
    Messages:
    20,321
    Likes Received:
    10,268
    Eddie, it's not a fake system restore virus, it's a virus that has disabled system restore as well as pretty much everything else.

    Check the link in the OP, it's brand new, most AV software doesn't recognise it, that's why I'm asking you guys because there is zero information out there about how to undo the damage.
     
    #17
  18. biggerbossman

    biggerbossman New Member

    Joined:
    Jan 30, 2012
    Messages:
    494
    Likes Received:
    0
    Take it to PC World with the octopus sex images and do porridge for Aquariality or bin your computer like that Ginge off News of the World done...
     
    #18
  19. eddieveeee

    eddieveeee New Member

    Joined:
    Jun 2, 2011
    Messages:
    3,535
    Likes Received:
    2
    i dunno then m8 sounds like its doing pretty much the same damage as the system restore virus
     
    #19
  20. Gambol

    Gambol George Clooney's wee brother

    Joined:
    Jan 22, 2010
    Messages:
    60,564
    Likes Received:
    18,215
    Kick the daft **** in the baws for opening attachments on an unsolicited email.

    If it's a virus that has infected and continues to infect executable files on your disk then you either have to find a virus scanner that can detect it, or re-install the OS.

    If it's a trojan you'll have to track it down the hard way.

    Go through your processes in task manager and isolate the trojan's process(es) by googling the names of each process. This will leave you a list of processes you consider dangerous.

    Locate where each process on your list is stored on the hard drive and write a batch file to delete them. Don't execute it yet. Do a registry search to locate all keys/data that mention the process names on your list. Write a regedit file that will delete those keys/data. Don't execute it yet. Add any files pointed at by the keys you will delete to your batch file for deletion.

    Boot into safe mode. Using task manager end all the processes on your list. Execute your batch file. Execute your regedit file. Reboot.

    If the trojan is back upon normal reboot, you missed something. Either a process and/or registry entry or data file used by the trojan. Repeat the whole thing until the trojan is gone when you reboot, then run system restore.

    It's may be simpler to just re-install the OS.

    In short, boot him in the baws and re-install the OS. Boot him in the baws again when he tells you he hasn't backed up his own data. Boot him in the baws and re-install the OS anyway. That will teach the dumb ****.
     
    #20

Share This Page