General Car Related Discussion. To discuss anything that is related to cars and automotive technology that doesnt naturally fit into another forum catagory.

virus help...

Thread Tools
 
Search this Thread
 
Old Jul 14, 2010 | 10:32 AM
  #1  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default virus help...

at my mum and dads theyve got windows (xp i think) the 1 before vista

and theyve got a virus on it.

ive done a system restore from safe mode to before the problem started,
and it helped for a couple of hrs but its now back.

they keep getting a security warning flash up saying the pc is infected do u wanna run a scan, then asks u to buy a program to delete it.

it wont let you open anything up to clean it tho.
theyve got windows antivrus avg (free version)
ad-aware, and norton free versions, but this virus thing wont let them open.
if you try to open it it just comes up with a warning box saying the file is infected do you wanna run antivirus program? and wont let you open it.

it happens when u try and open any program.

any1 got any ideas what i can do?
pls help.

cheers
Reply
Old Jul 14, 2010 | 10:52 AM
  #2  
phil_focus's Avatar
phil_focus
PassionFord Post Troll
 
Joined: Aug 2005
Posts: 3,094
Likes: 3
From: Under the car :cry:
Default

i had this and had a look on the pc forums and theres trcks to get rid. the virus itself doesnt appear to be damaging but it stops you from running any programs (.exe files) and basically tries to scam you into buying fake software.

iirc you need to determine what the process/s are called and as soon as the pc boots up go into task manager and delete the process, then you can delete all files assosciated with the scam program.

alternatevely i left my pc unplugged from the mains for a week as i wasnt around for that week and that worked. lol.
Reply
Old Jul 14, 2010 | 11:01 AM
  #3  
markc's Avatar
markc
Too many posts.. I need a life!!
 
Joined: Nov 2004
Posts: 525
Likes: 3
From: Essex
Default

go to safe mode with networking ( so you can still use the net)
download, install, and run a full system scan with malwarebytes
www.malwarebytes.org (get the free version)

once done reboot and go back in to windows, dowload install and run ccleaner to clear out all your temp files (where they usually like to hide)
Reply
Old Jul 14, 2010 | 11:19 AM
  #4  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

Cheers peeps, will go there later on and try it.
Reply
Old Jul 14, 2010 | 11:22 AM
  #5  
ste1806's Avatar
ste1806
Part of the Furniture
 
Joined: Apr 2007
Posts: 186
Likes: 1
From: high peak
Default

Originally Posted by markc
go to safe mode with networking ( so you can still use the net)
download, install, and run a full system scan with malwarebytes
www.malwarebytes.org (get the free version)

once done reboot and go back in to windows, dowload install and run ccleaner to clear out all your temp files (where they usually like to hide)
+1 and if you cannt get the installer to run try renaming it
Reply
Old Jul 14, 2010 | 11:24 AM
  #6  
wirralphil's Avatar
wirralphil
PassionFord Post Whore!!
 
Joined: Apr 2006
Posts: 7,297
Likes: 2
From: Wirral
Default

http://www.free-av.com/

http://www.malwarebytes.org/mbam.php

download and run both of them

This is what Danneth told me to use, got rid of the lot.

Plus makes the PC run quicker than with AVG

PS you will need to put them on a dongle 1st then run.
Reply
Old Jul 14, 2010 | 01:30 PM
  #7  
MannheimAlex's Avatar
MannheimAlex
Too many posts.. I need a life!!
 
Joined: Dec 2008
Posts: 862
Likes: 1
From: Mannheim, Germany
Default

Had this a few days ago too, it seems more and more peolpe get that virus!

But my antivirus didnt notice it?!?
Reply
Old Jul 14, 2010 | 02:46 PM
  #8  
benjaminsarmy's Avatar
benjaminsarmy
escort rst cosworth rep
 
Joined: Aug 2009
Posts: 1,103
Likes: 0
From: Stansted / Essex
Default

http://www.malwarebytes.org/mbam.php
just downloaded this too found a few objects infected wow its good
Reply
Old Jul 14, 2010 | 04:58 PM
  #9  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

Just tried doin the above but it wouldn't let ne open the net.
Just said cannot connect to Internet while in safe mode.

Also they already have malwarebytes antimalware downloaded and did a scan with it the other day and again it only helped for a few hrs.

Last edited by stu21t; Jul 14, 2010 at 05:01 PM.
Reply
Old Jul 14, 2010 | 05:04 PM
  #10  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

Just tried going on the net in normal mode and It would open, just says it's infected, so tryin again in safe mode.
Reply
Old Jul 14, 2010 | 05:04 PM
  #11  
Mark_'s Avatar
Mark_
PassionFord Post Whore!!
 
Joined: Dec 2007
Posts: 5,023
Likes: 2
From: london
Default

sounds exactly what i had on my old laptop
Reply
Old Jul 14, 2010 | 05:09 PM
  #12  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

Woohoo I'm in lol
Just downloading crap cleaner now.
Reply
Old Jul 14, 2010 | 05:20 PM
  #13  
danneth's Avatar
danneth
TORQUE!
 
Joined: Sep 2006
Posts: 11,756
Likes: 3
From: Sheffield
Default

Originally Posted by wirralphil
http://www.free-av.com/

http://www.malwarebytes.org/mbam.php

download and run both of them

This is what Danneth told me to use, got rid of the lot.

Plus makes the PC run quicker than with AVG

PS you will need to put them on a dongle 1st then run.

Reply
Old Jul 15, 2010 | 06:39 AM
  #14  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

well i tried the antimalware program and ccleaner
and it was ok for a few hrs but doesnt work this mornin

im going to try and run norton 360 on it, ive got it on cd.

other than that any ideas?
Reply
Old Jul 15, 2010 | 06:48 AM
  #15  
rich123's Avatar
rich123
I've found that life I needed.. It's HERE!!
iTrader: (3)
 
Joined: Jun 2008
Posts: 1,243
Likes: 0
From: north wales
Default

just format it job done,can be a mission getting rid of these virises i had the same problem,i had to down load malware to sort it
Reply
Old Jul 15, 2010 | 07:54 AM
  #16  
tsutton's Avatar
tsutton
I've found that life I needed.. It's HERE!!
15 Year Member
 
Joined: Mar 2006
Posts: 1,100
Likes: 0
From: Norfolk, UK
Default

Originally Posted by MannheimAlex
But my antivirus didnt notice it?!?
Because it's not a virus, that's why it didn't get picked up. You need a malware protection.

stu21t - looks like you've tried everything and if it keeps coming back, it's very deep... best to start clean & format!
Reply
Old Jul 15, 2010 | 09:04 AM
  #17  
wirralphil's Avatar
wirralphil
PassionFord Post Whore!!
 
Joined: Apr 2006
Posts: 7,297
Likes: 2
From: Wirral
Default

Is this what the pop up/virus says?

Trojan-BNK.Win32.Keylogger.gen

is the file name, also have a program with

Also a program comes up with XP Internet Security 2010 - Unregistered Version.

Saying 25 infection found.
If so full scan with the programs i mentioned will clear them.
Reply
Old Jul 15, 2010 | 09:21 AM
  #18  
S1's Avatar
S1
...............
 
Joined: Jul 2003
Posts: 2,663
Likes: 0
From: Essex
Default

Chances are if you've got one trojan then you've got a few. You will need to use a few utils to clean it.

We use Microsoft Security Essentials, free download from Microsoft, Malwarebytes as already recommended plus SuperAntiSpyware and sometimes Adaware, all downloadable from www.download.com.

Download and update each util, then remove network cable or switch off wireless to ensure the trojan cant re-infect itself from the 'net. Start one of the utils off, leave it for ten mins, then start another off, might take some time depending on spec of pc. Also ensure to run full & complete scans rather than quick scans.

Depending how pc savvy you are run up msconfig and check the startup items for unusual .exe's. Google them if neccessary from another PC to see if they are malicious and unselect from startup if the are. (Start button, click "run", type msconfig into the run box.)
Reply
Old Jul 15, 2010 | 10:18 AM
  #19  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

thanks,

ive just done the startup thing and unchecked about 10 things that werent needed on startup.
dunno if any of them were the problem tho.

also the norton is still going, been scanning for at least 2 hrs now.



the error message above isnt what theyve been getting
it just says whatever program you try to open is infected and do you want to run an antivirus program or continue uncovered?
but wont let you open the programs.
then the net wont work as it says its an unsafe website and opens its own page which is a virus scanner saying you have loads of faults.

once the norton is finished i will try the super anti spyware and adaware

it seems to fix for a little while after i have a play but then comes back again so either reloads or comes back through the net.

i dont want to wipe the pc and start again as its used for bussiness. if i cant fix it i will have to take it to a pc shop.
Reply
Old Jul 15, 2010 | 11:16 AM
  #20  
stonehavencossie's Avatar
stonehavencossie
Advanced PassionFord User
 
Joined: Jun 2004
Posts: 1,521
Likes: 0
From: Aberdeenshire
Default

watch what your doing with it but this is far more effective than anything else;

http://www.bleepingcomputer.com/comb...o-use-combofix

if it does not run then boot up in safe mode (tap f8 just before wondows starts to load)
Reply
Old Jul 15, 2010 | 12:03 PM
  #21  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

Well norton came up with no viruses or spyware
Reply
Old Jul 15, 2010 | 12:32 PM
  #22  
S1's Avatar
S1
...............
 
Joined: Jul 2003
Posts: 2,663
Likes: 0
From: Essex
Default

So what did the rest find?
Reply
Old Jul 15, 2010 | 02:47 PM
  #23  
stu21t's Avatar
stu21t
Thread Starter
PassionFord Post Whore!!
 
Joined: Oct 2004
Posts: 3,902
Likes: 12
From: south london
Default

antimalware got nothing
norton...nothing

just about to download and run the other above now.
Reply
Old Jul 15, 2010 | 02:57 PM
  #24  
Psycho Warren's Avatar
Psycho Warren
Carbon Crazy
iTrader: (5)
 
Joined: Jun 2004
Posts: 20,725
Likes: 128
From: Stoke on Trent
Default

if it were me, if you still cant get rid then run in safe mode to copy all your important files onto a USB or similar then format the drive with a fresh XP install. Remember to scan the USB stick before copying files across to fresh install though.
Reply
Old Jul 15, 2010 | 04:18 PM
  #25  
danb21t's Avatar
danb21t
PassionFord Regular
 
Joined: Sep 2009
Posts: 421
Likes: 0
From: high wycombe
Default

you will have no luck clearing it up now the spyware is in this state Stu, just get the data off you need and then format, reinstall xp. then install antivirus (I have a corporate version of Symantec if you want; nice and light weight) then whack spybot - S&D on and immunize.

unfortunately your a bit screwed when they dig their way in.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
PhoneShopRS
PassionFord FAQs
3
Nov 5, 2020 06:50 PM
Dr. Ickxs
Ford Escort RS Turbo
5
Aug 15, 2015 11:34 AM
Rob_DOHC
Computers, Consoles and I.T.
5
Aug 15, 2015 11:17 AM
bassboy
Ford Escort RS Turbo
5
Aug 5, 2015 08:21 AM
skillicky
Ford Escort RS Turbo
3
Mar 29, 2004 09:15 AM




All times are GMT. The time now is 08:38 PM.