Ad
News

Symantec nabs AMD64 Windows virus

Published on August 24, 2004

Anti-virus experts have intercepted the first computer virus targeting 64-bit Windows workstations. Read more

'Thursday' virus on the loose

Published on September 03, 1999

Financial institutions in eight countries have been hit by a Word 97 macro virus that threatens to destroy data when triggered in mid December First detected last month, the "Thursday" virus was reported by several anti-virus companies. Read more

PDA virus not a serious threat

Published on August 09, 2004

Brador, the new virus targeting the Pocket PC platform, is not as widespread as media reports would have you believe. Read more

Year 2000 comes early - in virus form

Published on September 16, 1999

A virus masquerading as a year 2000 countdown program is created an online e-mail hazard. Read more

Last Reviews & Articles

System Builder Marathon: Performance & Value

Published on November 28, 2008

We tightened the budget on this month’s enthusiast-level system while loosening our belt for the low-cost gamer box by a similar percentage. Today we gauge the effect of these changes on performance and value and compare to last month's machines. Read more

System Builder Marathon: $1,250 Enthusiast PC

Published on November 27, 2008

On this, the second day of our System Builder Marathon, Don turns down the price tag of his mid-range build looking for a sweet spot just above the $1,000 marker. Let's see what sort of hardware he found for it! Read more

System Builder Marathon: $625 Gaming PC

Published on November 26, 2008

This month's System Builder Marathon is all about your feedback to us. We've revamped our entry-level and mid-range PCs with new price points. Let's kick things off with what we think is the best value at a $625 price point! Read more

The State Of The Personal Computer

Published on November 25, 2008

Where were we in 2008 and where are we heading in 2009? In his State of the Personal Computer address, Alan Dang shares his insights as a user of three different platforms--Mac, Windows, and Linux. Read more

 

A big-ass virus!

Advanced Search

There are 405 identified and unidentified users. To see the list of identified users, Click here



Word :   Username :  
 
Bottom
Author
 Thread : A big-ass virus!
 
"Verba non acta"
Profile: stranger
More Information

Hi!

My computer is infected by what I believe is mutiple spyware/malware.

It started with the installation of a videocodec - then my computer became infected. Lots of "anti-virus"programs (fake obviously) started to appear on my desktop, it said "Virus alert" next to my clock, but it was fairly in control... until my father screwed everything up.. when I was away he went online and started downloading things (dont really know what it was, but I think it was updates to microsoft XP etc..)

After that everything went to hell, all virusprograms became disabled and couldnt be turned on, infact all programs with .exe at the end doesnt work, no "errors" they just wont start.

My C:\ and D:\ drive wont appear on my "This computer" (or whatever its called on the english version)

I have no access to internet, virusprograms or any other program, what should I do ?

I know it has to be done step by step and the first must be activating ".exe-programs"

I have access to CMD, Regedit and taskmanager (the last one after some tweaking) I hope any1 can help me because I got important stuff on the drives.

Related Product

Register or log in to remove.

Not today maybe tomorrow
Profile: Honorary Poster
More Information

let me guess, heatwave virus program keeps popping up. You need a injection tool to remove the runtime codes. I've removed this but to explain the process is just too friggen hard. The kernel is infected and several files that are running in memory and every time you do something to try to remove it the virus changes its name so you really never know which file to remove.
the best I can say is create an xp cd so that you can work with the harddrives to remove the problem.
http://www.diskinternals.com/boot-cd/screenshots.shtml
The way I remove this is by using a small 6 gig hard drive wiff xp installed, this allowing me to work wiff the infected drive.
You can remove this if your good wiff files, you need to check the process and remove the serverservice can not exactly remember the name.
I had to use hijackthis to remove the service from winstock then remove all files related to that serverservice process. I cannot remember the name of the other it was a tricky one, its the file that causes the heatwave icon in your toolbar taskmanager. Or take your loss and redo the system>note always remove the Internet when removing virus.
Microsoft removal tool will remove the virus for you if you can boot the system and run the tool. You still will have the payload of that virus.


Message edited by gomerpile on 06-21-2008 at 02:02:33 PM

---------------
WAITING FOR THE NEXT MOMENT TO STRIKE

 

Profile: enthusiast
More Information

use windows task maneger and exmaine for new services that weren't runnign ealier. if you find which belongs to viruses etc. stop them.

GO to folder option and turn on view hide files and system files

if it shows the original files backup them .

Not today maybe tomorrow
Profile: Honorary Poster
More Information

no this virus does not show up in task manager, after the virus is removed the payload does show up but you cannot delete it or stop the service, the only way is with an injection tool to remove the lines of codes from kernel32. then you are able to remove the files.


Message edited by gomerpile on 06-29-2008 at 07:50:25 AM

---------------
WAITING FOR THE NEXT MOMENT TO STRIKE

 

Profile: enthusiast
More Information

so what's and injection tool ?? is it different from a virus guard or is it something like a patch ??

Not today maybe tomorrow
Profile: Honorary Poster
More Information

sqlmap is an automatic blind SQL injection tool capable to enumerate entire remote database, perform an active database fingerprint and much more. The aim of this project is to implement a fully functional database mapper tool which takes advantages of web application security flaws.
this is one tool now scripts are running bots to use this and inject thier codes into kernel.dill and windows core components. I use hijactthis to map the kernel.dll and display the files that kernel calls upon. You can use tools to remove the lines of code a bad site put there.
Pavark is a good tool to check the rootkits


Message edited by gomerpile on 06-30-2008 at 10:36:26 AM

---------------
WAITING FOR THE NEXT MOMENT TO STRIKE

 

Profile: enthusiast
More Information

try this in this order:

spybot 1.6 scan and clean
avg antispyware scan and clean
counterspy scan and clean
superantispyware scan in safemode and clean
Malwarebytes' Anti-Malware scan and clean
RogueRemover PRO scan and clean

They can all be downloaded from www.download.com

www.portfolio.j-henderson.co.uk
Profile: Honorary Poster
More Information

and run them in safe mode (press f8 when booting up the pc)

Profile: journeyman
More Information

try this.
ttp://forums.whatthetech.com/VIRUS_ALERT_In_the_system_tray_next_to_the_clock_t92655.html
this guide usually removes all spyware i have seen
of course you have to adapt the guide for your situation with hijack this.
also disconnect from internet.

edit the address is not hot linkable just add the H in front of the ttp://
can't remember the forums hotlinking rules.


Message edited by donald7777 on 08-20-2008 at 05:53:29 AM
Profile: stranger
More Information

It sounds like the virus, whatever it is, has latched on to the kernel and is going to be a little trickier to remove than simply booting in to safe mode and removing a known executable. If its running in the memory and changing its name to evade detection, you're going to have to isolate it carefully.

techguy911's advice seems pretty good to me. I've had good experience (if you can all it that!) by using the Malwarebytes program to get rid of bad files. Give that one a go for sure.


---------------
http://www.pcfixreview.com
Profile: stranger
More Information

THAT IS A VERY TRICKY VIRUS INDEED.I SUGGEST YOU USE THE SMITFRAUD REMOVAL TOOL.DISABLE YOUR AV BEFORE DOWNLOADING CAUSE C=SOME DETECT IT A A VIRUS(WHICH IT IS NOT) FORM:
http://siri.urz.free.fr/Fix/SmitfraudFix.exe
AND THEN REBOOT YOUR SYSTEM.BOOT UP IN SAFE MODE THEN RUN THE TOOL WITH THE LOGO ON IT.IT WILL TERMINATE ALL PROCESSES SO DONT FREAK OUT OR WHAT EVER.IF U DONT UNDERSTAND THIS GO TO:
http://forum.securitycadets.com/in [...] wtopic=283 AND FOLLOW THE INSTRUCTIONS.



Go to:
 

Google ads