abalone99 ([info]abalone99) wrote in [info]damnportlanders,
@ 2009-01-08 21:13:00
Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Computer/Virus/Trojan Horse help for a dummy!
Dear DP,

Thank you for saving my ass a million and one ways.  I need need an ass saving for the million and second time.  To preface my story of woe:  I'm a PC desktop user.  Around the middle of December my computer got infected with...something.  My somewhat computer savvy roommate got me switched over to Firefox (was using IE), got me AVG free (since I couldn't afford to renew my Norton subscription) and got me set up with the automatic scans and whatnot.  Despite that I STILL have some godawful combination of viruses and trojan horses.  Every few minutes Spybot pops up asking if I want to deny a system registry change of some sort (I deny of course) and randomly my browser (both firefox and IE, the latter I've only used to see if the problem is consistant) will open a new tab/window telling me I have a trojan horse/virus and suggesting I buy some kind of virus protection with something that looks suspciously like the Windows security logo, but is clearly not.  AVG occasionally finds something and asks if I want to delete/heal/move it to a vault but then can't find the specified file. When I try to follow the path in my folders to find and delete said viruses/trojan horses nothing's in the folder.  Half the time the folders don't even exist (like temporary internet files, for example), even when I search for them and include hidden files and folders in the search.  HOW THE HELL DO I GET RID OF THESE?!  I do have an external harddrive though I haven't used it to back anything up for fear the nasties will get on there too.  Not sure if this is possible but I figured I'd better be safe than sorry.  Now firefox is crashing regularly and all sorts of bizarre alerts which look like windows alerts but are different than the last ones are popping up and I just have no idea what the hell to trust on my computer or not.  If anyone can tell me here how the hell to remove these things in VEEEERRRY extreme detail (as in "go to the upper right of your screen, click on edit, click on 'xyz,' etc...) for someone who is not computer savvy in the least I will be extremely extremely grateful.  If someone knows that I can't fix this on my own but can do it for me I can bake you cookies, awesome cinnamon rolls or a lovely meal.  I'm a pretty stellar baker and cook.  I cannot afford to pay someone or a business to take a look, but I'm down for bartering and trade or whatever.  Seriously, I'd give my virginity away to fix this if I could.  Damn my dirty whore of a lifestyle though.  But now you know how badly I want this gone.  HALP.


On another note, hotmail is not working for me.  It does work on my live-in boyfriend and aforementioned roomate's computer both of which are Macs.  I have no idea if this is related to the above problem or not, but basically once I get into my inbox nothing wants to load/work.  I can't access my e-mail messages, I can click on messages but they won't delete (though strangely when I later access hotmail on one of the others' computers those messages are deleted), can't access other folders.  Basically useless.  And I can't forward my messages to any non-msn accounts.  Any help there?

Seriously you will have my undying love and devotion and future virginity if you can help me. 



(Post a new comment)


[info]dragon_clouds
2009-01-09 05:36 am UTC (link)
http://www.malwarebytes.org/mbam.php

Download and run their free scanner. It's awesome.

(Reply to this) (Thread)


[info]abalone99
2009-01-09 06:06 am UTC (link)
Thanks, I'm running that now and so far it's picking some things up. *crosses fingers* Thank you so much for your suggestions and help.

(Reply to this) (Parent)(Thread)


[info]dragon_clouds
2009-01-09 06:10 am UTC (link)
You bet. I got hit with Vundo awhile back. I tried MacAffee, AVG, and a couple other things people mentioned in this thread. They'd all say they were removing it, but really didn't.
The malwarebytes scanner really did fix my computer. I think it's the very best, free scanner out there.
I'd recommend keeping up with the free updates, and running it once in awhile. I think I had to run it twice to totally get Vundo off my machine.

(Reply to this) (Parent)


[info]fenixfreak
2009-01-09 05:39 am UTC (link)
My friend would like me to let you know he can fix your computer and well do it for a beer or two, although I'm gonna have him go for a six pack. Haha. Let me know if you're interested.

(Reply to this)


[info]untied
2009-01-09 05:40 am UTC (link)
download and run superantispyware

download and run vundo fix

download hijackthis and run a scan

save the scan in a txt file to your desktop

post the results to the hjt forum at techmonkeys (http://www.techmonkeys.co.uk/forums/viewforum.php?f=8&sid=474da734a62d98e0012db781bed5f308)

(Reply to this) (Thread)


[info]dragon_clouds
2009-01-09 05:42 am UTC (link)
just fyi
I had vundo. superantispyware wasn't really removing it but the malwarebytes scanner did. vundo is some nasty shit.

(Reply to this) (Parent)(Thread)


[info]untied
2009-01-09 07:56 am UTC (link)
yeah, it's important to follow sas with vundofix

(Reply to this) (Parent)


[info]abalone99
2009-01-09 06:08 am UTC (link)
Thanks. I'm running the first 2 along with malwarebytes right now. Why should I post the results of the scan to that forum, if you don't mind me asking?

Thank you so much for your suggestions and help, btw!

(Reply to this) (Parent)(Thread)


[info]untied
2009-01-09 07:55 am UTC (link)
your hjt log (hijackthis) allows the tech guys in the forum to see exactly what is running on your computer.

the advice there is free, prompt, and will make sure you don't overlook something or otherwise fuck up your machine by accidentally deleting/keeping something you shouldn't.

you're also getting help from folks who know what they're doing, which can remove some of the anxiety of deciding who you trust to mess with your stuff.

(Reply to this) (Parent)


[info]xaositecte
2009-01-09 05:45 am UTC (link)
If you've gotten so bad that anti-virus programs won't work, you might need a reinstall.

First off, if you haven't already, try Ad-aware - it's the best anti-spyware program I've found. If that doesn't work, you might have to reinstall windows.

Steps:

1. Backup important files. Don't copy any folders completely, just select specific files you want to backup and copy them over, you shouldn't have any problems that way. There -are- viruses and spyware programs out there that can just hop over to an external hard drive the moment they're installed, but most of those can be solved by a decent spyware or antivirus program.

2. Grab all your windows CD's, or have a friend that has some, make sure you've got everything that came with your computer before you start, including CD keys, programs you want to reinstall, drivers, etc.

3. Reinstall windows. This takes a couple hours, but doesn't require any real computer skill.

4. Slap AVG and Adaware back on your computer as soon as possible, download all the Windows updates (they're annoying, I know, but there are security patches in there you do need) - copy your backed up files over to your computer, run another scan, and you should be good.

5. Stop downloading random shit off the internet. Normally the only way computers get infected like yours is if someone is downloading random programs, porn, etc.

If you need help with that, I've got some free time. I'm not really in the market for virginities right now, but I love cookies.

(Reply to this) (Thread)


[info]dragon_clouds
2009-01-09 07:21 am UTC (link)
"5. Stop downloading random shit off the internet. Normally the only way computers get infected like yours is if someone is downloading random programs, porn, etc. "

You can get a virus just from visiting a webpage through the Java script.

(Reply to this) (Parent)(Thread)

this reminds me...
[info]untied
2009-01-09 07:58 am UTC (link)
MAKE SURE YOUR JAVA IS UP TO DATE!

if you don't have the most recent version of java, update it, then remove the old version in add/remove programs.

not updating your java is one of the easiest ways to leave yourself vulnerable.

(Reply to this) (Parent)


[info]vampyrecat
2009-01-09 06:38 pm UTC (link)
I had one of these nasties and I'm pretty sure I got it from either:

1. A facebook app plus going to an ad website to get "free" points in the app (stupid move on my part)

or possibly but much less likely

2. following a link posted in DamnPortlanders\

My wonderful guy fixed it by following the steps xaositecte posted above.

It was pretty horrible- the virus or whatever it was took control of everything including taskmanager and I suspect it hid copies of itself elsewhere because my computer is still a bit wonky.

(Reply to this) (Parent)


[info]purty286
2009-01-09 06:00 am UTC (link)
I think I got the same virus as you in mid December. Last week it got really bad, I couldn't even check my hotmail like you're saying. I basically had some critical errors and had to back up my important files on DVD-Rs and I had to do a complete system restore. I think each computer might be different but on mine I had to press Ctrl + F11 on startup to access the restore thing. Do you by any chance have a Dell? I do and my bro in law who also has a Dell has the same virus right now.

(Reply to this) (Thread)


[info]abalone99
2009-01-09 06:05 am UTC (link)
I do. You are making me a sad panda. Eek. I'm terrified of doing system restores. I seriously don't know my head from my ass when it comes to computers. Sigh... well, good to know I'm not the only one. I don't download random things off the internet at all and have no idea where the hell I picked this up. Good to know I'm not the only one who's hotmail wasn't working though. Thanks for the heads up.

(Reply to this) (Parent)


[info]abalone99
2009-01-09 11:18 am UTC (link)
Oh my goodness! My hotmail is working again! So far I've run most of the things the first several posters suggested and I'm literally bouncing up and down in my seat! My comptur's running SO much better now. Not perfectly again yet, but I'm not remaining hopeful rather than wimpering in fear of having to do something crazy and massive with my happy little compy.

(Reply to this) (Parent)


[info]kayla_malfoy
2009-01-09 08:08 pm UTC (link)
This actually happened to me a two weeks ago. my brother couldn't fix it, so yesterday the computer guy who helps out my dad's law office took it away- he is doing a hard re-format... the entire machine is being wiped as we speak. i lost everything.... all 214 days of music from itunes, my pictures, writing... ect.

next time i'm going to back my shit up >:(

(Reply to this) (Parent)(Thread)


[info]kayla_malfoy
2009-01-09 08:09 pm UTC (link)
oh, and it's a dell inspiron. i waited about 45 minutes with the dell support call line, and the guy didn't help me AT ALL then tried to sell me a 4 time package of useless 'help sessions' for $200.

useless.

(Reply to this) (Parent)


[info]circumambulate
2009-01-09 06:16 am UTC (link)
Without knowing exactly what you have, there's no way to describe how to remove it, and even then there may not be a lossless way.

The simplest route is to back up everything you care about on to your external HDD - data files only, no apps, and then blow away your primary drive and start over. Once you have the main system recovered, scan the external drive before moving anything back over.

(Reply to this)


[info]platedlizard
2009-01-09 06:17 am UTC (link)
Start googling the error messages, that's what I always do when something weird happens and so far it's worked. Also, be sure to do the regular maintenance, defraging, run check disk, etc to rule out corrupted files. You may have to back up all your data (hint: dump the porn) and do a wipe.

Um, some of this might be adware rather then a virus or trojan, so make sure you run a program that roots out adware as well if you don't want to wipe.

(Reply to this)


[info]untied
2009-01-09 08:00 am UTC (link)
please, PLEASE take the time to correct this before you wipe your entire machine.

don't replace your car just cause you don't know how to change the oil, ya know?
it CAN be fixed, and people can help you do it.

(Reply to this) (Thread)


[info]abalone99
2009-01-09 11:16 am UTC (link)
Thank you very much for all the time and effort you've involved in helping me with my problem. I'm slowly going through all the programs you suggested, following all your tips, and will DEFINITELY do everything else possible before I wipe my entire machine, as I really don't trust myself to be able to do that w/o majorly fucking something up. Is there any way to know for sure that my computer is 'clean' other than just not having the obnoxious pop-ups, spybot prompts, etc.? Sorry if that's a supremely dumb question, I seriously don't know what the hell I'm doing with computers. *facepalm* Again, thank you very very much. Your patience and help has been extremely appreciated.

(Reply to this) (Parent)(Thread)


[info]untied
2009-01-09 11:54 am UTC (link)
if the problems stop you're in good shape, but it's not a guarantee that you don't have other problems lurking (getting rid of the symptoms /= curing the disease)

i don't consider myself qualified to comb through an hjt log or i'd let you send the copy to me. techmonkeys is really a solid bet if you're unable to quell things on your own or are simply unsure that you've zapped everything.

taking the above steps is a great start, and doing your hijack this scan & submitting the log will make sure there aren't any programs or files hidden away in your machine somewhere.


good luck!

(Reply to this) (Parent)


[info]untied
2009-01-09 11:57 am UTC (link)
also, how's it going?

i realize i should have sent you some links to the programs i suggested, so i hope you found everything okay.

(Reply to this) (Parent)


[info]dj_proxy
2009-01-09 03:28 pm UTC (link)
If it's the Antivirus 2009, AVG doesn't catch it and it's impossible to completely remove from your system. I got hit with it last weekend, wasn't able to completely remove it and had to reformat :/

(Reply to this) (Thread)


[info]abalone99
2009-01-09 11:23 pm UTC (link)
YEP, that's exactly what the annoying fucker is! So far, after running a few of the programs people have suggested to me it hasn't popped up yet, but I'm just now getting onto my computer for today, so we'll see....I remain hopeful that all of untied's suggestions work out. I reeeealy don't want to reformat.

(Reply to this) (Parent)(Thread)


[info]dj_proxy
2009-01-09 11:42 pm UTC (link)
I got most of it removed but I still couldn't update my antivirus or malware tools nor going to any antivirus or malware related sites.

I would never trust a comprised system though, I would highly recommend doing a reinstall.

(Reply to this) (Parent)


[info]mspurrmeow
2009-01-10 02:15 am UTC (link)
Please be aware that Antivirus 2009 may pop back up after you've removed it with Malwarebytes and have restarted it. Just run Malwarebytes again, reboot. This really is the best answer for this particular infection. You got the best advice first, very lucky.

Encyclopedia Darmatica is unfortunately a source for this virus, and part of the virus is a clickjacker. (Meaning that you may click a link to something else, and it goes to this site.)

Good luck!

(Reply to this) (Parent)


[info]winterwhite
2009-01-10 02:40 pm UTC (link)
Hmmm... my post didn't go through.
After reading this article I'm a little scared. I use Webroot's Spy Sweeper and Trend Anti-Virus. Should I be excessively worried? Are these programs any good?

(Reply to this)


[info]untied
2009-01-18 02:02 am UTC (link)
the latest computer post brought you to mind... did you ever get things cleared up? if so, did the bugs stay gone?

(Reply to this)


Create an Account
Forgot your login or password?
Login w/ OpenID
English • Español • Deutsch • Русский…