PDA

View Full Version : Virus taken over...


MrNightly
12-27-2008, 07:00 PM
Ok, I have some sort of trojan/virus on my desktop computer. It's a deep one too. I can't right click anything on my desktop, and it locks everything up every few minutes.

It won't let me run any spyware removal programs, and window's defenders just get locked up trying to locate it.

I can get online, but that is about it. Everything is running extremely slowly. It's killing me.

I think it's lodged itself into the memory, because when i run everything on diagnostic setup, it still won't let me install a new anti virus program. i put one on disk (locks up if i even google/yahoo anti virus software) and tried to open it but it gives me some sort of error.

Anybody have any idea how to conquer this thing?

Now my window's is yelling at me every 20 seconds with this error, "Windows - no disk - Exception processing message C0000013 parameters 75b6bf9c 4 75b6bfc9c 75b6bf9c" Cancel ,try again, continue. Doesn't matter what I click, it just pops back up.

I was going to buy a good anti virus cleaner, but what's the use if I can't get it to boot up anyways from the D drive?

I was told to start everything in safe mood, and try to install it that way, but it just locks up still.

Weird. Any help out there? I typically run Spybot Search and Destroy along with Avast and AVG. I tried all of them to no avail. :(

Keiko
12-27-2008, 07:05 PM
My advice...Replace it with a Mac.

dorokusai
12-27-2008, 07:08 PM
Backup what you can't live without and re-image the whole drive.

MrNightly
12-27-2008, 07:10 PM
Backup what you can't live without and re-image the whole drive.

How do you do that? :) And will that help if the bug is in the memory?

Phasearray
12-27-2008, 07:17 PM
www.ubuntu.com

WilliamM2
12-27-2008, 07:32 PM
It's probably malware or spyware. I've had good luck cleaning up other's PC's with this:

http://www.malwarebytes.org/

If you can't complete a scan, try booting into safe mode and scan from there.

Phasearray
12-27-2008, 07:34 PM
My computer has only been hijack like that once. What I use to do is install windows on a 2nd hard drive and use the new operating system to scan the old hard drive.

lightman1
12-27-2008, 08:18 PM
...shoot it...then set fire to it....

obieone
12-27-2008, 08:52 PM
...shoot it...then set fire to it....

I almost did! PC's= EVIL:mad::eek:

dudeinaroom
12-28-2008, 12:15 AM
start up in safe mode. click start, click run. type in msconfig.exe hit enter. Click on the tab that says services. click on the check box that says "hide all Microsoft services. uncheck every thing that does not have the name of programs,or devices that you use. Next click on the tab that says startuo, uncheck every thing. click apply, ok, then reboot. after restart run antivirus

Erik Tracy
12-28-2008, 01:13 AM
I had something like that happen to me recently.

Computer was very slow and even surfing to familiar sites like the polk forum did not always complete loading - sites would stall and not finish, or I'd get site not found errors.

I actually used a recommendation from Consumer Reports for a free antivirus program from avira.com for personal use.

It found 4 trojan viruses and I'm as right as rain - as the saying goes.

I thought my previous free anti-virus was ok, but I guess not.

I'm not advocating avira.com - just my personal experience with it - but the point is you need a good anti-virus/spyware/malware suite.

Good luck cleaning up - it is a nuisance.

WilliamM2
12-28-2008, 01:56 AM
start up in safe mode. click start, click run. type in msconfig.exe hit enter. Click on the tab that says services. click on the check box that says "hide all Microsoft services. uncheck every thing that does not have the name of programs,or devices that you use. Next click on the tab that says startuo, uncheck every thing. click apply, ok, then reboot. after restart run antivirus

Why not just scan in safe mode? I have never seen malware, spyware, or virus that showed up on the startup menu.

Lasareath
12-28-2008, 02:12 AM
Take the hard drive out of the pc and install it into another pc and scan it with malwarebytes and your anti-virus program

I had one machine last month that malwarebyte could not get all of the trojans, it killed like 137 trojans and there was one it could not kill. For that PC I downloaded the Zone Alarm full suite and installed it as a 15 day trial.

Zone alarm killed the last trojan and then I uninstalled it and the PC is still running fine.

Good Luck and stop surfing those porn sites ;)

Las

mantis
12-28-2008, 09:19 AM
My advice...Replace it with a Mac.

I gotta say listen to Keiko, he is a wise man.

Dan

Fireman32
12-28-2008, 10:25 AM
It's probably malware or spyware. I've had good luck cleaning up other's PC's with this:

http://www.malwarebytes.org/

If you can't complete a scan, try booting into safe mode and scan from there.

+1 I have cleaned up quite a few computers with this.

obieone
12-28-2008, 03:33 PM
Malwarebytes ROCKS!!! I just spent 3 days wrestling with my system, and it found SOMETHING in the registry, that AVG couldn't find. So far, so good.

SKsolutions
12-28-2008, 03:54 PM
It may not be viral. "it'' may be looking for something. . . usb, raid, stick etc.
Try:
Stop QT from loading at startup using msconfig, and then uninstall quicktime.

Also: try killing dit.exe,

Sami
12-28-2008, 07:12 PM
UBCD4Win works wonders if you have a NTFS disc you need to clean. If other then I would recommend one of the Linux LiveCD's (Knoppix, Ubuntu etc).

Rivrrat
12-28-2008, 07:19 PM
It's probably malware or spyware. I've had good luck cleaning up other's PC's with this:

http://www.malwarebytes.org/

If you can't complete a scan, try booting into safe mode and scan from there.

I just downloaded this and ran it. It picked up stuff nothing else I have found.

ohskigod
12-28-2008, 11:06 PM
My advice...Replace it with a Mac.

ding ding ding........winnah!!!!!!!!!

Sami
12-28-2008, 11:21 PM
ding ding ding........winnah!!!!!!!!!

Blah, overpriced and way too hyped. You want to go the open source based OS route, Linux is a much better choice.

MrNightly
12-28-2008, 11:31 PM
Unfortunately, nothing is working guys. This really sucks.

I can't install anything on my computer either in safe mood or not. MSConfig doesn't help either, no matter how many ways I try to boot the stupid thing. I think it's majorly fubared!

Pity. I don't have it in the budget to buy another computer either, as I just picked up the PS3 instead :)

Any other idea's fellas? Can you remove memory from the computer and try booting then? Ha.

Sami
12-28-2008, 11:40 PM
Can you burn an ISO to CD? Are you posting from that PC?

John30_30
12-28-2008, 11:42 PM
There's a bootable disk we used to use to disinfect P.C.'s called BARTPE. You have to have a bit of skill in order to build the bootable windows disk with the anti-malware apps in the image. Well, just enough skill to follow instructions.
It's a Live CD which allows you to work on the infected drive without booting into that drive. You run antivirus, trojan killers, etc. all of which you've built into the CD. They recommend Win Server2003, but I'm pretty sure we used XP Pro.
Google it, then go to the plugins page and get as many of those as you think you'll need. It'll take some time, but you'll always have that disk plus the experience.

Obviously, you have to do this from a clean install. Borrow a friend's computer if you only have the 1.
Or do as someone suggested and install a fresh version on a different partition, then work from there.....

WilliamM2
12-28-2008, 11:43 PM
Unfortunately, nothing is working guys. This really sucks.

I can't install anything on my computer either in safe mood or not. MSConfig doesn't help either, no matter how many ways I try to boot the stupid thing. I think it's majorly fubared!

Pity. I don't have it in the budget to buy another computer either, as I just picked up the PS3 instead :)

Any other idea's fellas? Can you remove memory from the computer and try booting then? Ha.

Didn't the PC come with a restore CD, or the OS on CD or DVD? It should have.

No reason to replace the whole computer.

Sami
12-28-2008, 11:46 PM
There's a bootable disk we used to use to disinfect P.C.'s called BARTPE.

I would use UBCD4Win myself (based on BartPE), but you do need to have a copy of XP to build it. Does not require much of a skill set, very easy to use.

MrNightly
12-29-2008, 09:54 PM
Can you burn an ISO to CD? Are you posting from that PC?

I don't know what an ISO means! No I am posting from my phone. I do have another computer in the house, older but it still works great! I will have to try to make a boot disk.

Also how do you just wipe everything clean on a computer and start over? Re install the Os?

Thanks!

John30_30
12-29-2008, 10:04 PM
I don't know what an ISO means! No I am posting from my phone. I do have another computer in the house, older but it still works great! I will have to try to make a boot disk.

Also how do you just wipe everything clean on a computer and start over? Re install the Os?

Thanks!

ISO just means image. It's a standard image format.

"What's that mean?"

An image of a bootable O.S.,etc will contain hundreds or thousands of files all as a single file, or image or ISO, which the burning app translates back to those hundreds of files. It's a sort of exact duplication format is the reason.

treitz3
12-29-2008, 11:15 PM
I just ran across this on another forum I hang on. I have no idea whether this is what happened to you but I figured I'd post it anyway. Anyhoo, here's the post....

Read and heed!

Subject: URGENT, URGENT, URGENT!


TWO SUBJECT LINES TO BEWARE OF:

Just verified this with Snopes and it is REAL. ALSO WENT TO TRUTH OR FICTION, IT'S on their site also.

PLEASE INFORM EVERYONE you know!

Emails with pictures of Osama Bin-Laden hanged are being sent and the moment that you open these emails your computer will crash and you will not be able to fix it!

1.) If you get an e-mail along the lines of 'Osama Bin Laden Captured' or 'Osama Hanged', don't open the Attachment!

This e-mail is being distributed through countries around the globe, but mainly in the U.S. and Israel. Be considerate & send this warning to whomever you know.

PLEASE FORWARD THIS WARNING AMONG FRIENDS, FAMILY AND CONTACTS:

2.) You should be alert during the next few days: Do not open any message with an attached file called 'Invitation' regardless of who sent it. It is a virus that opens an Olympic Torch which 'burns' the whole hard disc C of your computer! This virus will be received from someone who has your e-mail address in his/her contact list, that is why you should send this E-Mail to all your contacts. It is better to receive this message 25 times than to receive the virus and open it.

If you receive e-mail called 'invitation', though sent by a friend. Do not open it! Shut down your computer immediately! This is the worst virus announced by CNN, it has been classified by Microsoft as the most destructive virus ever. This virus was discovered by McAfee yesterday, and there is no repair yet for this kind of virus.

This virus simply destroys the Zero Sector of the Hard Disc, where the vital information is kept.

Sami
12-30-2008, 07:20 AM
I don't know what an ISO means!
Like John said, it's an image. If you don't have XP disc to make UBCD4Win, I might be able to help to get one, otherwise just make a bootable UBCD4Win disc and run virus and malware scans from it. It's easy and should do the trick, no need to format the drive.

Keiko
12-30-2008, 07:53 AM
I just ran across this on another forum I hang on. I have no idea whether this is what happened to you but I figured I'd post it anyway. Anyhoo, here's the post....

Read and heed!

Subject: URGENT, URGENT, URGENT!


TWO SUBJECT LINES TO BEWARE OF:

Just verified this with Snopes and it is REAL. ALSO WENT TO TRUTH OR FICTION, IT'S on their site also.

PLEASE INFORM EVERYONE you know!

Emails with pictures of Osama Bin-Laden hanged are being sent and the moment that you open these emails your computer will crash and you will not be able to fix it!

1.) If you get an e-mail along the lines of 'Osama Bin Laden Captured' or 'Osama Hanged', don't open the Attachment!

This e-mail is being distributed through countries around the globe, but mainly in the U.S. and Israel. Be considerate & send this warning to whomever you know.

PLEASE FORWARD THIS WARNING AMONG FRIENDS, FAMILY AND CONTACTS:

2.) You should be alert during the next few days: Do not open any message with an attached file called 'Invitation' regardless of who sent it. It is a virus that opens an Olympic Torch which 'burns' the whole hard disc C of your computer! This virus will be received from someone who has your e-mail address in his/her contact list, that is why you should send this E-Mail to all your contacts. It is better to receive this message 25 times than to receive the virus and open it.

If you receive e-mail called 'invitation', though sent by a friend. Do not open it! Shut down your computer immediately! This is the worst virus announced by CNN, it has been classified by Microsoft as the most destructive virus ever. This virus was discovered by McAfee yesterday, and there is no repair yet for this kind of virus.

This virus simply destroys the Zero Sector of the Hard Disc, where the vital information is kept.
I got this in an email from a friend a couple months back treitz. Thought I was being nice and passed it along on this board. I got blasted by a member saying I was posting spam basically.

Anyway, I'm glad I don't have to worry about computer virus's much since I use a Mac. I do wish the OP the best of luck resolving his problem though.

MrNightly
12-31-2008, 04:42 PM
Like John said, it's an image. If you don't have XP disc to make UBCD4Win, I might be able to help to get one, otherwise just make a bootable UBCD4Win disc and run virus and malware scans from it. It's easy and should do the trick, no need to format the drive.

OK. I made a UBCD4Win and have it on a disc. I will try to use it for my computer now. Do i need to put the malware program on the disc to scan from it?

Also as a side note, I tried to re instll my OS with the disc from Dell. I put the disc in, booted the computer, and booted from the disc. It ran through a bunch of files and then flashed with this error: "STOP: c0000221 Unknown Hard Error / systemroot/system32/ntdll.dll"

I have no idea what that means, but it made me abort my re installation.

Anyways, I am on my laptop to make the bootable disc. Tell me if there is anything else I need to know before I start booting up :)

Virus' watch out... here I come. Armed and Dangerous. Ha

tcrossma
12-31-2008, 04:45 PM
Sounds to me like you might possibly have a physical hardware problem -- hard drive or RAM issue maybe.

Sami
12-31-2008, 05:33 PM
Sounds to me like you might possibly have a physical hardware problem -- hard drive or RAM issue maybe.

Likely. Boot from UBCD4Win, it will give a lot of tools to diagnose the problem (antivirus etc are included standard). If that boot disc causes crashes as well, it's definitely hardware issue.

memtest86 is a must program to run (there should be an option from UBCD4Win to run it instead of booting into Windows), if not then burn a copy of UBCD or memtest86 itself.

MrNightly
01-05-2009, 12:32 AM
Well, I paid a guy $40 bucks to clean the disc for me. He erased all data and gave me a fresh start. I was tired with messing with it. I dunno how he did it, but I guess he reformatted everything. I lost all my data, but it wasn't anything worth saving anyways that I can't recreate.

I downloaded Malwarebytes, and am going to use that as my main virus protector. He said the rest of the system was in excellent condition, so it was just a software issue.

This thing is CRUISING... I love it. Back to the good old P4 days ;)

Lasareath
01-05-2009, 11:00 AM
Well, I paid a guy $40 bucks to clean the disc for me. He erased all data and gave me a fresh start. I was tired with messing with it. I dunno how he did it, but I guess he reformatted everything. I lost all my data, but it wasn't anything worth saving anyways that I can't recreate.

I downloaded Malwarebytes, and am going to use that as my main virus protector. He said the rest of the system was in excellent condition, so it was just a software issue.

This thing is CRUISING... I love it. Back to the good old P4 days ;)


$40 bucks is really cheap, I charge $300 for a complete overhaul, But I back up the client's data, itunes, My Documents, all their stuff on their desktop. and I install backup software that I wrote myself and I insist they buy an external backup drive.

I also create a Clone Image and I keep a copy of it just in case they screw up the machine again.