Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Virus is beating me

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion
Register FAQ Community Calendar

Virus is beating me
Reply
 
Thread Tools
Old 18-06-2010, 11:33   #1
Gary L
cf.mega poster
 
Join Date: Sep 2007
Posts: 16,324
Gary L has a nice shiny starGary L has a nice shiny star
Gary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny star
Virus is beating me

I'm looking at a mates laptop with virus's and trojans on. the CD drive don't work so that's buggering everything up, and I can't run .exe's. some will run and others won't.

I'm trying to run portable virus apps but they keep closing on me. I'm totally stumped without a CD drive. I'm gonna have to go and borrow an external one later.

on the USB stick it keeps making a RAR.exe. I've had a look on Google but can't find nothing. just that it's a worm when I put it on my PC.

the other thing is the wireless doesn't work on it, so I can't do an online scan either.

I'm giving up on it. I haven't got the time
Gary L is offline   Reply With Quote
Advertisement
Old 18-06-2010, 11:42   #2
MetaWraith
Inactive
 
MetaWraith's Avatar
 
Join Date: Oct 2003
Location: 2nd CPU to the right & past the cache
Posts: 1,949
MetaWraith has a bronzed appealMetaWraith has a bronzed appeal
MetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appealMetaWraith has a bronzed appeal
Send a message via ICQ to MetaWraith Send a message via AIM to MetaWraith Send a message via MSN to MetaWraith Send a message via Yahoo to MetaWraith
Re: Virus is beating me

Would SAFE MODE and restoring to some point prior to infection help?
You might at least then be able to at least run a scan.
Just an thought without knowing much more about the specific nasty.
MetaWraith is offline   Reply With Quote
Old 18-06-2010, 11:46   #3
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Virus is beating me

I always take out the drive, put it in another PC then virus scan it as a non-bootable drive.. (thank gawd for 2.5 to 3.5 IDE convertors)

1st thing I'd look at is the running processes, sounds like you have the virus running in memory and it's replicating itself to any drive that pops up.
Kymmy is offline   Reply With Quote
Old 18-06-2010, 11:49   #4
haydnwalker
Inactive
 
Join Date: Jan 2007
Location: Doncaster, S. Yorks.
Age: 42
Services: TV:Sky+, BB:DRL VDSL2 40/10 with Ask4, Phone:Mobile Only
Posts: 2,320
haydnwalker has reached the bronze age
haydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze agehaydnwalker has reached the bronze age
Re: Virus is beating me

How about looking into a USB CD/DVD Drive to flatten the drive and reinstall windows ... or even use it to boot a live version of knoppix to copy any files off that may be needed (note though these MAY be infected too).
haydnwalker is offline   Reply With Quote
Old 18-06-2010, 11:50   #5
Gary L
cf.mega poster
 
Join Date: Sep 2007
Posts: 16,324
Gary L has a nice shiny starGary L has a nice shiny star
Gary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny star
Re: Virus is beating me

System Restore has been turned off.
When he gave it me it had no boot.ini, and I'm not having any more luck in safe mode anyway.
Gary L is offline   Reply With Quote
Old 18-06-2010, 11:52   #6
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Virus is beating me

Yep, safe mode will only reduce the drivers and 3rd party software running, most virii though hide themselves in the files needed for running windows even in safe mode.

Are there no AV scanners that will boot and run from the USB?
Kymmy is offline   Reply With Quote
Old 18-06-2010, 11:56   #7
Gary L
cf.mega poster
 
Join Date: Sep 2007
Posts: 16,324
Gary L has a nice shiny starGary L has a nice shiny star
Gary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny star
Re: Virus is beating me

Quote:
Originally Posted by Kymmy View Post
I always take out the drive, put it in another PC then virus scan it as a non-bootable drive.. (thank gawd for 2.5 to 3.5 IDE convertors)

1st thing I'd look at is the running processes, sounds like you have the virus running in memory and it's replicating itself to any drive that pops up.
I've got one of them adapters, but I really can't be bothered opening my PC up to go through it all.
I'm gonna get the external CD later and just do a fresh install.

---------- Post added at 10:54 ---------- Previous post was at 10:53 ----------

Quote:
Originally Posted by haydnwalker View Post
How about looking into a USB CD/DVD Drive to flatten the drive and reinstall windows ...
That's what I probably will have to do.

---------- Post added at 10:56 ---------- Previous post was at 10:54 ----------

Quote:
Originally Posted by Kymmy View Post
Are there no AV scanners that will boot and run from the USB?
I've tried them all. they just won't open. one opened found a load of stuff but they were all there again when I rebooted and rescanned.
Gary L is offline   Reply With Quote
Old 18-06-2010, 11:58   #8
Kymmy
Inactive
 
Join Date: Dec 2007
Posts: 18,385
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Kymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny starsKymmy has a pair of shiny stars
Re: Virus is beating me

Quote:
Originally Posted by Gary L View Post
I've tried them all. they just won't open. one opened found a load of stuff but they were all there again when I rebooted and rescanned.
It happens a lot..

The virii files are removed quite happily, but the virii installer/package isn't found (hard to tell if a encrypted and compress installer is safe or not.) When you reboot afterwards the package is run and the deleted files re-appear.
Kymmy is offline   Reply With Quote
Old 18-06-2010, 11:59   #9
zing_deleted
Guest
 
Posts: n/a
Re: Virus is beating me

do you know what virus it is causing the main problems?

I use a bootable usb stick with live xp on with AV and Malware aps

if its really that bad just recover to factory defaults and tell him lesson learnt lol
  Reply With Quote
Old 18-06-2010, 12:16   #10
Gary L
cf.mega poster
 
Join Date: Sep 2007
Posts: 16,324
Gary L has a nice shiny starGary L has a nice shiny star
Gary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny star
Re: Virus is beating me

Quote:
Originally Posted by zing View Post
do you know what virus it is causing the main problems?

I use a bootable usb stick with live xp on with AV and Malware aps

if its really that bad just recover to factory defaults and tell him lesson learnt lol
There was too many to know who's the most dominant
it has got it's own restore partition, and even that was infected. I only said I'd have a look at it because I thought it wouldn't be too bad.

if I can't get it back to normal with the recovery CD, he'll just have to sort it out some other way.
Gary L is offline   Reply With Quote
Old 18-06-2010, 13:22   #11
Dai
Inactive
 
Join Date: Dec 2006
Location: Lincoln UK
Age: 77
Services: 50Mb, TV & Phone
Posts: 3,673
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Dai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronzeDai is cast in bronze
Send a message via MSN to Dai
Re: Virus is beating me

If it's that bad Gary, you'll never be certain you've got every one of the nasties.

Better, quicker and safer to flatten and reinstall otherwise it may come back to haunt you later when something you missed steals the customer's bank details.
Dai is offline   Reply With Quote
Old 18-06-2010, 14:48   #12
Gary L
cf.mega poster
 
Join Date: Sep 2007
Posts: 16,324
Gary L has a nice shiny starGary L has a nice shiny star
Gary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny star
Re: Virus is beating me

I'm reinstalling now. I tried the same CD drive in it and it worked, so I borrowed that to do it with.
Gary L is offline   Reply With Quote
Old 18-06-2010, 15:49   #13
Anonymouse
RIP Tigger - 12 years?!
 
Join Date: Jul 2005
Location: Bolton
Age: 60
Services: BT Superfast Broadband
Posts: 1,605
Anonymouse has a bronzed appealAnonymouse has a bronzed appeal
Anonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appealAnonymouse has a bronzed appeal
Re: Virus is beating me

It sounds as if you have some sort of rootkit on your hands. Very difficult to kill without the right software...but a doddle to kill with it.

I suggest you try Blacklight Beta - excellent app. I had a rootkit a few years ago - I was always redirected to Microsoft.com regardless of what browser I used, IE6 was somehow downgraded to IE5, so I couldn't even run the repair tool, and McAfee was somehow disabled. Spybot & Ad-Aware were baffled. Luckily I had an uninfected laptop, with which I conducted desperate research. I discovered Blacklight, put it on the case, and voila!

Try it. The worst that'll happen is that it won't work.

One thing I always advise when someone's buying and setting up a computer: always set up two accounts, not one, even if you are the only user, and then downgrade the one you're going to use to access the Internet from Administrator to User. That stops most malware in its tracks because it can't install. Never use an Admin account to access the Internet unless you know the site is safe; only use the Admin account to install/uninstall software. It annoys me that this is never explained by either the setup manual or the store you're buying the computer from. For anyone not all that tech-savvy, there's a simple analogy between Administrators and Users: it's the difference between having a ticket to a concert and having a backstage pass.

If this advice had been given out routinely 10 or more years ago, the malware problem would be nowhere as prevalent as it is. If it were given out routinely now, the problem would perhaps not get any worse.
__________________
"People tend to confuse the words 'new' and 'improved'."
- Agent Phil Coulson, S.H.I.E.L.D.

WINDOWS 11, ANYONE?!
Anonymouse is offline   Reply With Quote
Old 18-06-2010, 16:38   #14
Gary L
cf.mega poster
 
Join Date: Sep 2007
Posts: 16,324
Gary L has a nice shiny starGary L has a nice shiny star
Gary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny starGary L has a nice shiny star
Re: Virus is beating me

All done now. he just needs to reinstall everything himself now.

regarding the seperate accounts, I always have at least 2 Windows installs on all my PC's. easier to get in and fix things
Gary L is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 14:40.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum