Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Virus is beating me


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Virus is beating me
Reply
 
Thread Tools
Old 18-06-2010, 10:33   #1
Gary L
** **** ********
Frogger Champion, Air Dodge Champion, Aim & Fire Champion, Bejeweled Champion, Apple Shoot Champion, 7up Pinball Champion, Light Saber Champion, Moon Lander Champion
 
Gary L's Avatar
 
Join Date: Sep 2007
Posts: 10,765
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Virus is beating me

I'm looking at a mates laptop with virus's and trojans on. the CD drive don't work so that's buggering everything up, and I can't run .exe's. some will run and others won't.

I'm trying to run portable virus apps but they keep closing on me. I'm totally stumped without a CD drive. I'm gonna have to go and borrow an external one later.

on the USB stick it keeps making a RAR.exe. I've had a look on Google but can't find nothing. just that it's a worm when I put it on my PC.

the other thing is the wireless doesn't work on it, so I can't do an online scan either.

I'm giving up on it. I haven't got the time
__________________
We need captcha to determine whether Gary L is actually a bot.

Just a reminder - people with cups under their name are superior beings.
Gary L is offline   Reply With Quote
Advertisement
Old 18-06-2010, 10:42   #2
MetaWraith
Ghost Process Killer
 
MetaWraith's Avatar
 
Join Date: Oct 2003
Location: 2nd CPU to the right & past the cache
Posts: 1,908
MetaWraith has a bronzed appealMetaWraith has a bronzed appeal
MetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appeal
Send a message via ICQ to MetaWraith Send a message via AIM to MetaWraith Send a message via MSN to MetaWraith Send a message via Yahoo to MetaWraith
Re: Virus is beating me

Would SAFE MODE and restoring to some point prior to infection help?
You might at least then be able to at least run a scan.
Just an thought without knowing much more about the specific nasty.
__________________
Yesterday it worked. Today it is not working. VM is like that.
Three things are certain: Death, taxes and lost data. Guess which has occurred ?
MetaWraith is offline   Reply With Quote
Old 18-06-2010, 10:46   #3
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Virus is beating me

I always take out the drive, put it in another PC then virus scan it as a non-bootable drive.. (thank gawd for 2.5 to 3.5 IDE convertors)

1st thing I'd look at is the running processes, sounds like you have the virus running in memory and it's replicating itself to any drive that pops up.
Kymmy is offline   Reply With Quote
Old 18-06-2010, 10:49   #4
haydnwalker
cf.mega poster
Tetris Champion
 
haydnwalker's Avatar
 
Join Date: Jan 2007
Location: Doncaster, S. Yorks.
Age: 28
Services: TV:Sky+, BB:DRL VDSL2 40/10 with Ask4, Phone:Mobile Only
Posts: 2,227
haydnwalker has reached the bronze age
haydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze age
Re: Virus is beating me

How about looking into a USB CD/DVD Drive to flatten the drive and reinstall windows ... or even use it to boot a live version of knoppix to copy any files off that may be needed (note though these MAY be infected too).
__________________
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former." - Albert Einstein

haydnwalker is offline   Reply With Quote
Old 18-06-2010, 10:50   #5
Gary L
** **** ********
Frogger Champion, Air Dodge Champion, Aim & Fire Champion, Bejeweled Champion, Apple Shoot Champion, 7up Pinball Champion, Light Saber Champion, Moon Lander Champion
 
Gary L's Avatar
 
Join Date: Sep 2007
Posts: 10,765
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Re: Virus is beating me

System Restore has been turned off.
When he gave it me it had no boot.ini, and I'm not having any more luck in safe mode anyway.
__________________
We need captcha to determine whether Gary L is actually a bot.

Just a reminder - people with cups under their name are superior beings.
Gary L is offline   Reply With Quote
Old 18-06-2010, 10:52   #6
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Virus is beating me

Yep, safe mode will only reduce the drivers and 3rd party software running, most virii though hide themselves in the files needed for running windows even in safe mode.

Are there no AV scanners that will boot and run from the USB?
Kymmy is offline   Reply With Quote
Old 18-06-2010, 10:56   #7
Gary L
** **** ********
Frogger Champion, Air Dodge Champion, Aim & Fire Champion, Bejeweled Champion, Apple Shoot Champion, 7up Pinball Champion, Light Saber Champion, Moon Lander Champion
 
Gary L's Avatar
 
Join Date: Sep 2007
Posts: 10,765
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Re: Virus is beating me

Quote:
Originally Posted by Kymmy View Post
I always take out the drive, put it in another PC then virus scan it as a non-bootable drive.. (thank gawd for 2.5 to 3.5 IDE convertors)

1st thing I'd look at is the running processes, sounds like you have the virus running in memory and it's replicating itself to any drive that pops up.
I've got one of them adapters, but I really can't be bothered opening my PC up to go through it all.
I'm gonna get the external CD later and just do a fresh install.

---------- Post added at 10:54 ---------- Previous post was at 10:53 ----------

Quote:
Originally Posted by haydnwalker View Post
How about looking into a USB CD/DVD Drive to flatten the drive and reinstall windows ...
That's what I probably will have to do.

---------- Post added at 10:56 ---------- Previous post was at 10:54 ----------

Quote:
Originally Posted by Kymmy View Post
Are there no AV scanners that will boot and run from the USB?
I've tried them all. they just won't open. one opened found a load of stuff but they were all there again when I rebooted and rescanned.
__________________
We need captcha to determine whether Gary L is actually a bot.

Just a reminder - people with cups under their name are superior beings.
Gary L is offline   Reply With Quote
Old 18-06-2010, 10:58   #8
Kymmy
Cable Forum Team
 
Kymmy's Avatar
 
Join Date: Dec 2007
Age: 43
Posts: 16,278
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Virus is beating me

Quote:
Originally Posted by Gary L View Post
I've tried them all. they just won't open. one opened found a load of stuff but they were all there again when I rebooted and rescanned.
It happens a lot..

The virii files are removed quite happily, but the virii installer/package isn't found (hard to tell if a encrypted and compress installer is safe or not.) When you reboot afterwards the package is run and the deleted files re-appear.
Kymmy is offline   Reply With Quote
Old 18-06-2010, 10:59   #9
zing_deleted
Guest
 
Posts: n/a
Re: Virus is beating me

do you know what virus it is causing the main problems?

I use a bootable usb stick with live xp on with AV and Malware aps

if its really that bad just recover to factory defaults and tell him lesson learnt lol
  Reply With Quote
Old 18-06-2010, 11:16   #10
Gary L
** **** ********
Frogger Champion, Air Dodge Champion, Aim & Fire Champion, Bejeweled Champion, Apple Shoot Champion, 7up Pinball Champion, Light Saber Champion, Moon Lander Champion
 
Gary L's Avatar
 
Join Date: Sep 2007
Posts: 10,765
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Re: Virus is beating me

Quote:
Originally Posted by zing View Post
do you know what virus it is causing the main problems?

I use a bootable usb stick with live xp on with AV and Malware aps

if its really that bad just recover to factory defaults and tell him lesson learnt lol
There was too many to know who's the most dominant
it has got it's own restore partition, and even that was infected. I only said I'd have a look at it because I thought it wouldn't be too bad.

if I can't get it back to normal with the recovery CD, he'll just have to sort it out some other way.
__________________
We need captcha to determine whether Gary L is actually a bot.

Just a reminder - people with cups under their name are superior beings.
Gary L is offline   Reply With Quote
Old 18-06-2010, 12:22   #11
DaiNasty
Old dog, New tricks
 
DaiNasty's Avatar
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 63
Services: 50Mb, TV & Phone
Posts: 3,511
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
DaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronzeDaiNasty is cast in bronze
Send a message via MSN to DaiNasty
Re: Virus is beating me

If it's that bad Gary, you'll never be certain you've got every one of the nasties.

Better, quicker and safer to flatten and reinstall otherwise it may come back to haunt you later when something you missed steals the customer's bank details.
__________________
-= David =-

Under socialism ideology always trumps rationality.
DaiNasty is offline   Reply With Quote
Old 18-06-2010, 13:48   #12
Gary L
** **** ********
Frogger Champion, Air Dodge Champion, Aim & Fire Champion, Bejeweled Champion, Apple Shoot Champion, 7up Pinball Champion, Light Saber Champion, Moon Lander Champion
 
Gary L's Avatar
 
Join Date: Sep 2007
Posts: 10,765
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Re: Virus is beating me

I'm reinstalling now. I tried the same CD drive in it and it worked, so I borrowed that to do it with.
__________________
We need captcha to determine whether Gary L is actually a bot.

Just a reminder - people with cups under their name are superior beings.
Gary L is offline   Reply With Quote
Old 18-06-2010, 14:49   #13
Anonymouse
Owned by my cat Tigger
 
Join Date: Jul 2005
Location: Bolton
Age: 46
Services: None
Posts: 895
Anonymouse has reached the bronze age
Anonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze ageAnonymouse has reached the bronze age
Re: Virus is beating me

It sounds as if you have some sort of rootkit on your hands. Very difficult to kill without the right software...but a doddle to kill with it.

I suggest you try Blacklight Beta - excellent app. I had a rootkit a few years ago - I was always redirected to Microsoft.com regardless of what browser I used, IE6 was somehow downgraded to IE5, so I couldn't even run the repair tool, and McAfee was somehow disabled. Spybot & Ad-Aware were baffled. Luckily I had an uninfected laptop, with which I conducted desperate research. I discovered Blacklight, put it on the case, and voila!

Try it. The worst that'll happen is that it won't work.

One thing I always advise when someone's buying and setting up a computer: always set up two accounts, not one, even if you are the only user, and then downgrade the one you're going to use to access the Internet from Administrator to User. That stops most malware in its tracks because it can't install. Never use an Admin account to access the Internet unless you know the site is safe; only use the Admin account to install/uninstall software. It annoys me that this is never explained by either the setup manual or the store you're buying the computer from. For anyone not all that tech-savvy, there's a simple analogy between Administrators and Users: it's the difference between having a ticket to a concert and having a backstage pass.

If this advice had been given out routinely 10 or more years ago, the malware problem would be nowhere as prevalent as it is. If it were given out routinely now, the problem would perhaps not get any worse.
__________________
"A government is a group of people - usually, notably, ungoverned."

- Shepherd Derrial Book, quoting Malcolm Reynolds, Captain of Firefly-class transport Serenity

Last edited by Anonymouse; 18-06-2010 at 14:53.
Anonymouse is offline   Reply With Quote
Old 18-06-2010, 15:38   #14
Gary L
** **** ********
Frogger Champion, Air Dodge Champion, Aim & Fire Champion, Bejeweled Champion, Apple Shoot Champion, 7up Pinball Champion, Light Saber Champion, Moon Lander Champion
 
Gary L's Avatar
 
Join Date: Sep 2007
Posts: 10,765
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Gary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronzeGary L is cast in bronze
Re: Virus is beating me

All done now. he just needs to reinstall everything himself now.

regarding the seperate accounts, I always have at least 2 Windows installs on all my PC's. easier to get in and fix things
__________________
We need captcha to determine whether Gary L is actually a bot.

Just a reminder - people with cups under their name are superior beings.
Gary L is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT +1. The time now is 08:44.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2