Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | PC completely virus-ridden!


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

PC completely virus-ridden!
Reply
 
Thread Tools
Old 10-04-2008, 09:52   #1
That damn leprechaun!!
 
Nugget's Avatar
 
Join Date: Sep 2003
Location: I'm behind you...
Age: 33
Services: Will provides gags for cash
Posts: 8,424
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
PC completely virus-ridden!

Hi Guys (and Gals!),

Having had Norton go completely mad last week and tell me that my PC had both the Downloader and Metajuan trojans, I ran a full scan and (I thought) cleared them.

Unfortunately, having switched on again last night, it again went mad, saying that those two were still there, and there was also one called Trojan.Vundo...

I turned off Sysetm Restore, put it into Safe Mode, and ran the scan again - 6 hours later, it told me that there were 13 (13!) viruses detected. Norton claims to have repaired them all, but I have to say I'm not 100% convinced. Before I either kick it around the room, or re-format it (which I also don't know how to do (), can anyone suggest anything else that I can do, seeing as I'm rapidly losing the will to live...

TIA
__________________
The doctor told me that BOTH my eyes were lazy! And that's why it was the best summer ever.
Nugget is offline   Reply With Quote
Old 10-04-2008, 09:59   #2
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 30
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 7,467
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Re: PC completely virus-ridden!

Nugg,

I've got bad news I'm afraid.

The industry standard advice after any scale of viral infection is to 'rebuild from known good media'.

I've only ever had one viral problem (caused by my anti-virus failing to detect one virus which then shut it down and invited all its mates to the party). I can't begin to tell you the time I saved just rebuilding the whole machine, compared to what I would have spent trying (and failing) to get rid of the little buggers.

The other problem (of course) is that you can never be sure that you've got them ALL unless you rebuild.
__________________
Formerly known as 'Raistlin'
For Clarity: Bold = Moderating Decision/Comment :: Normal = My Opinion/Comment
Rob M is online now   Reply With Quote
Old 10-04-2008, 09:59   #3
Cable Forum Team
 
Graham M's Avatar
 
Join Date: Jul 2003
Location: Poole, Dorset
Age: 23
Services: Sky+ V-Box VM 10MBit
Posts: 9,323
Graham M is a king among kingsGraham M is a king among kingsGraham M is a king among kings
Graham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kingsGraham M is a king among kings
Send a message via ICQ to Graham M
Re: PC completely virus-ridden!

Sorry it's not very helpful (then nor is Norton normally) but I think one of the freebies such as AVG, AVAST is more likely to shed light on the situation and clear said virii out. But generally with that number, they get rooted in so deep, a reformat is almost inevitable. Don't use Norton!
__________________
Used to be Zeph - I'm still me though
Peter: Oh my god, Brian, there's a message in my Alphabits. It says, 'Oooooo.'
Brian: Peter, those are Cheerios.
www.elitehealthdistribution.co.uk - www.loonyasylum.net
Graham M is online now   Reply With Quote
Old 10-04-2008, 10:02   #4
That damn leprechaun!!
 
Nugget's Avatar
 
Join Date: Sep 2003
Location: I'm behind you...
Age: 33
Services: Will provides gags for cash
Posts: 8,424
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Re: PC completely virus-ridden!

Quote:
Originally Posted by Raistlin View Post
Nugg,

I've got bad news I'm afraid.

The industry standard advice after any scale of viral infection is to 'rebuild from known good media'.

I've only ever had one viral problem (caused by my anti-virus failing to detect one virus which then shut it down and invited all its mates to the party). I can't begin to tell you the time I saved just rebuilding the whole machine, compared to what I would have spent trying (and failing) to get rid of the little buggers.

The other problem (of course) is that you can never be sure that you've got them ALL unless you rebuild.
Quote:
Originally Posted by Zeph View Post
Sorry it's not very helpful (then nor is Norton normally) but I think one of the freebies such as AVG, AVAST is more likely to shed light on the situation and clear said virii out. But generally with that number, they get rooted in so deep, a reformat is almost inevitable. Don't use Norton!
Thanks for that guys - I was fairly sure that that would be the answer, but I thought it would be better to ask first

Right, next question - how the hell do I re-format then

Oh, and I hate Norton anywaqy, but BT provide it free with whichever option we're on. Mind you, I'm not going to be using it anymore
__________________
The doctor told me that BOTH my eyes were lazy! And that's why it was the best summer ever.
Nugget is offline   Reply With Quote
Old 10-04-2008, 10:03   #5
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 30
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 7,467
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Re: PC completely virus-ridden!

Do you have any system restore discs that came with the computer?
__________________
Formerly known as 'Raistlin'
For Clarity: Bold = Moderating Decision/Comment :: Normal = My Opinion/Comment
Rob M is online now   Reply With Quote
Old 10-04-2008, 10:08   #6
That damn leprechaun!!
 
Nugget's Avatar
 
Join Date: Sep 2003
Location: I'm behind you...
Age: 33
Services: Will provides gags for cash
Posts: 8,424
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Re: PC completely virus-ridden!

Quote:
Originally Posted by Raistlin View Post
Do you have any system restore discs that came with the computer?
I believe so - it's all in Mrs Nugs name, so she'll have to dig them out
__________________
The doctor told me that BOTH my eyes were lazy! And that's why it was the best summer ever.
Nugget is offline   Reply With Quote
Old 10-04-2008, 10:12   #7
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 30
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 7,467
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Re: PC completely virus-ridden!

You should find that if you restart the PC with one of those discs in it will take you through the process of restoring it all to exactly how it was when you first bought it.

Remember though that this will delete all files and software from the drive. Make sure you copy any files that you need to CD first and that you have copys of any software/licence keys that you need.

You'll also need to get out any email addresses, web page bookmarks, or other information that you need to keep - this includes the settings for your emails (servers, passwords, account names, etc) and any settings you need to access the internet.

Also remember that anything you write to disc could be infected, so you'll need to scan those after you write them (and then again before you put them in the machine once it's rebuilt) just in case.
__________________
Formerly known as 'Raistlin'
For Clarity: Bold = Moderating Decision/Comment :: Normal = My Opinion/Comment
Rob M is online now   Reply With Quote
Old 10-04-2008, 10:14   #8
That damn leprechaun!!
 
Nugget's Avatar
 
Join Date: Sep 2003
Location: I'm behind you...
Age: 33
Services: Will provides gags for cash
Posts: 8,424
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Re: PC completely virus-ridden!

Quote:
Originally Posted by Raistlin View Post
You should find that if you restart the PC with one of those discs in it will take you through the process of restoring it all to exactly how it was when you first bought it.

Remember though that this will delete all files and software from the drive. Make sure you copy any files that you need to CD first and that you have copys of any software/licence keys that you need.

You'll also need to get out any email addresses, web page bookmarks, or other information that you need to keep - this includes the settings for your emails (servers, passwords, account names, etc) and any settings you need to access the internet.

Also remember that anything you write to disc could be infected, so you'll need to scan those after you write them (and then again before you put them in the machine once it's rebuilt) just in case.
Thanks matey - looks like I know what I'm spending this evening doing
__________________
The doctor told me that BOTH my eyes were lazy! And that's why it was the best summer ever.
Nugget is offline   Reply With Quote
Old 10-04-2008, 10:15   #9
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 30
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 7,467
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Rob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kingsRob M is a king among kings
Re: PC completely virus-ridden!

Quote:
Originally Posted by Nugget View Post
Thanks matey - looks like I know what I'm spending this evening doing
Sorting out the aftermath of a rampant viral infection.....sounds like par for the course to me
__________________
Formerly known as 'Raistlin'
For Clarity: Bold = Moderating Decision/Comment :: Normal = My Opinion/Comment
Rob M is online now   Reply With Quote
Old 10-04-2008, 10:16   #10
That damn leprechaun!!
 
Nugget's Avatar
 
Join Date: Sep 2003
Location: I'm behind you...
Age: 33
Services: Will provides gags for cash
Posts: 8,424
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Re: PC completely virus-ridden!

Quote:
Originally Posted by Raistlin View Post
Sorting out the aftermath of a rampant viral infection.....sounds like par for the course to me
You know what? I really don't know how to respond to that
__________________
The doctor told me that BOTH my eyes were lazy! And that's why it was the best summer ever.
Nugget is offline   Reply With Quote
Old 10-04-2008, 10:17   #11
cf.addict
 
Join Date: Jun 2003
Posts: 105
Eric55 is on a distinguished roadEric55 is on a distinguished road
Re: PC completely virus-ridden!

Turn off system restore as the virus will replicate itself there.
Eric55 is offline   Reply With Quote
Old 10-04-2008, 10:21   #12
That damn leprechaun!!
 
Nugget's Avatar
 
Join Date: Sep 2003
Location: I'm behind you...
Age: 33
Services: Will provides gags for cash
Posts: 8,424
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Nugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star memberNugget is a Tri-Star member
Re: PC completely virus-ridden!

Quote:
Originally Posted by Eric55 View Post
Turn off system restore as the virus will replicate itself there.
Quote:
Originally Posted by Nugget View Post
I turned off System Restore, put it into Safe Mode, and ran the scan again
*ahem*

That was about the only thing that I did know to do
__________________
The doctor told me that BOTH my eyes were lazy! And that's why it was the best summer ever.
Nugget is offline   Reply With Quote
Old 10-04-2008, 11:29   #13
cf.member
 
Watching You's Avatar
 
Join Date: Mar 2008
Location: London
Services: Virgin TV + Broadband & Telephone
Posts: 31
Watching You is on a distinguished roadWatching You is on a distinguished road
Re: PC completely virus-ridden!

Quote:
Originally Posted by Nugget View Post
Hi Guys (and Gals!),

Having had Norton go completely mad last week and tell me that my PC had both the Downloader and Metajuan trojans, I ran a full scan and (I thought) cleared them.


TIA
I also used Norton but yes put your computer in safe mode and run a scan, do contact Nortons for additional help if needed - that's what they are there for.

But also suggest that you check for spyware, which are not picked up by Nortons, but can be used by viruses to invade your computer.

Suggest you also run Webroot, which also offers a free trial and picks up many spyware.

Good Luck!
Watching You is offline   Reply With Quote
Old 10-04-2008, 12:27   #14
Cable Forum Team
 
David F's Avatar
 
Join Date: Feb 2005
Location: midlands
Age: 38
Services: Mummy that man was nasty to me!!!
Posts: 17,317
David F has an impressive sixpackDavid F has an impressive sixpack
David F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpackDavid F has an impressive sixpack
Send a message via AIM to David F Send a message via MSN to David F Send a message via Yahoo to David F
Re: PC completely virus-ridden!

Check msconfig for any dodgy start up files.Note location of registry entry of these files.
Download and install avast during the install it will offer you the option of a boot time scan select yes and reboot.
The scan will start before most windows componants are running allowing the files to be deleted. Wait till it finds a virus and select delete all.Once pc has booted check msconfig for dodgy start up items .
If still present goto start run select regedit and run it. Browse to the location of said dodgy start up items in reg and delete the keys.(also Untick from start up). If its a file name then run a search though the registry for the rogue file ie illl.exe etc. Uninstall and reinstall avast selecting boot time scan again run full scan . This has often rescued me from reformats but it does depend if any of the virus's were rootkits or not
David F is offline   Reply With Quote
Old 10-04-2008, 12:37   #15
vista home premium user
 
nffc's Avatar
 
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,344
nffc is a king among kings
nffc is a king among kingsnffc is a king among kingsnffc is a king among kings
Re: PC completely virus-ridden!

FixVundo?

You could always run a scan with superantispyware as well... Otherwise rebuild tbh, Vundo is removable but it's a damn pain to.
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
10111 pts
nffc is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 11:28.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)