Virus Warning!!

Discussion in 'General Discussion' started by trance_fan, Mar 6, 2005.

Users Viewing Thread (Users: 0, Guests: 0)

  1. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,566
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Ok i managed to download Firefox, and used it to install AVG.

    I then ran a virus check. It found 74 infections.

    I got it to fix them, although i notice it now says it has quarantined 70 infected files. Dunno where the other 4 have gone. :confused:

    I then also ran Spybot to get rid of the Spyware.

    Unfortunately its still not behaving. Internet pages are still opening very slowly, and not fully. Its not allowing websites to use ActiveX. Spyware is still appearing left, right and centre.

    In addition it is sometimes crashing, and coming up with a blue screen which reads as follows.


    "A problem has been detected and Windows has been shut down to prevent damage to your computer.

    IRQL_NOT_LESS_OR_EQUAL

    If this is the first time you've seen this stop error screen, restart your computer. If this screen appears again follow these steps.

    Check to make sure any new hardware or software is properly installed. If this is a new installation, ask your hardware or software manufacturer for any windows updates you might need.

    If problems continue, disable or remove any newly installed hardware or software. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options and then select Safe Mode.

    Technical Information:

    *** STOP: 0x0000000A (0x00000000, 0x00000002, 0x00000000, 0x804DC244)

    Beginning dump of pyhisical memory
    Physical memory dump complete
    Contact your system administrator or technical support group for further assistance."


    Any ideas? This is worth a few pints to whoever get my computer working again.
  2. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    Did you update AVG before the scan? 4 of them could be registry keys with no corresponding files...

    Just Spybot won't be enough, download adaware and M$ Antispyware as well. Also, download tds-3 from here. Install it, then right-click this link and choose save target as/save link as, and save it in C;\program files\tds3\ folder, replacing the old one.

    Now, update avg, spybot, adaware and M$ anti-spyware. Shut off your net connection (important!!!). Run TDS-3, select System Testing from the menu, select Full System Scan. Once that's finished, run AVG. Then run all 3 anti-spyware progs. Turn on your net connection and see if there's still probs. (run housecall if you can)

    One of your drivers is fucking around with your memory - could be due to the infection. http://msdn.microsoft.com/library/default.asp?url=/library/en-us/w2kmsgs/6077.asp

    By the way, you have turned off system restore? Just checking...
  3. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    Forgot to add, did you do all the steps that I put up in previous posts? The W32.Spybot worm is a fucker to get rid of, especially if the process (eg Bling.exe) is still running, most av scans can't stop it if it's loaded. And whilst it's still running it's downloading worms, trojans and spyware, logging all your keystrokes, possibly sending thousands of requests to do a DOS attack, etc - you need to make sure that the registry keys are deleted, the Bling.exe (or whatever) ffiles are deleted, and the tftp*.* zero byte files in the startup folders are deleted too, or else you will not get rid of it.

    The safest way to try and get rid of it is to download and update the stuff in my post above. Unplug your net connection (important!!! Your ports are wide open at the moment!). Then reboot into safemode and do all the steps in my previous posts regarding regedit and the deletion of files. Reboot normally, press ctrl+alt+delete, see if hotkeysvc.exe or one of the spybot exe's (bling.exe etc) are running. If so, buggery, but end the processes. Then run the progs in the order I said above.
  4. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,566
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Think i did.



    Will try those other ones too now. I have been shutting my net connection, dont worry. Im only reconnecting once ive done everything to see if its sorted, or ask what i need to do next!



    How do i turn off System Restore? Do you mean in AVG or Spypot or Windows?




    Yeah i did do all the steps, although there wasnt any of those exe files. I didnt find any tftp*.* zero byte files either. Although i think the virus has fucked the search facility, because it searched so far then started just looping round the same few folders repeatedly.




    Im thinking il just have to back all my files up, wipe the hard drive and start again from scratch. Looking more and more like the only option. :(
  5. dodgy

    dodgy rowr kitty super meow cat

    Joined:
    Sep 18, 2003
    Messages:
    4,728
    Likes Received:
    0
    Location:
    Terra Firma
    Right-click on your My Computer icon, select properties, system restore tab, turn off system restore.

    If you can't find them files I'm guessing summinck alse is on your system. See if TDS-3 brings any joy, or if AVG detects anything again that it can't remove
  6. LeeTheMackem

    LeeTheMackem Lets Cacky Tash Him

    Joined:
    Aug 8, 2004
    Messages:
    9,970
    Likes Received:
    6
    Location:
    Sunderland
    hope you just have a cold
  7. Vin

    Vin Registered User

    Joined:
    Dec 29, 2001
    Messages:
    5,566
    Likes Received:
    1
    Location:
    1st/2nd Floor
    Re: Virus Warning!!

    Doh! :dunce:

    17 days later, i THINK i might have my computer up and running again!

    So yeah, dont click the link! :p



    For those that care, basically nothing i did would get rid of two of the viruses. I think it was these two viruses which kept just downloading other viruses. I decided to just reformat, and reinstall Windows XP. I put all my files on two Ipods before i started, which i had two wait about 5 days for my brother to bring round. Got stuck because i couldnt install the drivers and he got them installed, so got my brother round again, but i had to wait another 4 or 5 days because he lost his phone. Finally thought hed sorted it on Monday, then straight after he left, i ran a virus-scan and found the same two viruses still there. :strop: Nearly threw the computer out the window at that point.

    But today i put AVG on a cd. Reformatted and reinstalled again. Installed AVG, before connecting to the internet. And it seems to have worked! Woohoo! :clap: Well, so far so good anyway. *fingers crossed*

Share This Page