Author Topic: Unable to get rid or clean out virus  (Read 4532 times)

0 Members and 1 Guest are viewing this topic.

noggin

  • Guest
Unable to get rid or clean out virus
« on: November 29, 2007, 06:04:11 PM »
On a different computer, I ran avast4 and found like 15 or 20 viruses.  I moved them to the chest so that they are quarentined but still the viruses or new ones come back.  Frustrated, I figure I am now some virus super highway via the internet so I immediately disable my DSL line via windows XP "my network places" so that no more internet access is available to this computer.  I did this in order to see if new viruses would still pop up sans internet.  No internet, but still Avast4 finds more viruses.  So then I "delete all" the viruses figuring that quarentining them is not good enough.  So then after that, I run avast4 yet again and I find 10 more viruses!

what is going on?

How can my computer still be getting infected when I am eradicating the viruses and even deleting them. I am not even connected to the internet anymore!

Noggin

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Unable to get rid or clean out virus
« Reply #1 on: November 29, 2007, 06:10:29 PM »
So then I "delete all" the viruses figuring that quarentining them is not good enough.
This is not the problem. The Chest (Quarantine) is safe. The virus is replicating itself.

If a virus is replicant (coming and coming again), you could follow the general cleaning procedure:

1. Disable System Restore on Windows ME or Windows XP. System Restore cannot be disabled on Windows 9x and it's not available in Windows 2k. After boot you can enable System Restore again after step 3.

2. Clean your temporary files. You can use CleanUp or the Windows Advanced Care features for that.

3. Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot. Other option is scanning in SafeMode (repeatedly press F8 while booting).

4. It will be good if you download, install, update and run AVG Antispyware. Some users recommend SUPERantispyware, Spyware Terminator and/or a-squared (take care about false positives).
If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.

5. If you still detecting any strange behavior or even you're sure you're not clean, maybe it will be good to test your machine with anti-rootkit applications. I suggest AVG or Trend Micro RootkitBuster (for XP/Vista). For XP: Panda (for XP).

6. Also, if you still detecting strange behaviors or you want to be sure you're clean, maybe making a HijackThis log to post here and, specially, scan and submit to on-line analysis the RunScanner log would help to identify the problem and the solution.

7. After you're clean, use the immunization of SpywareBlaster or, which is better, the Windows Advanced Care features of spyware/adware cleaning and removal.

8. Finally, when you're clean, check for insecure applications with Secunia Software Inspector to update insecure applications and avoid reinfection.
The best things in life are free.

noggin

  • Guest
Re: Unable to get rid or clean out virus
« Reply #2 on: November 29, 2007, 06:30:20 PM »
So then I "delete all" the viruses figuring that quarentining them is not good enough.
This is not the problem. The Chest (Quarantine) is safe. The virus is replicating itself.

If a virus is replicant (coming and coming again), you could follow the general cleaning procedure:

1. Disable System Restore on Windows ME or Windows XP. System Restore cannot be disabled on Windows 9x and it's not available in Windows 2k. After boot you can enable System Restore again after step 3.

I am trying to do this first step.  Every which way I try to disable System Restore, I get thwarted.  This is the message that pops up and denies me further access to disable System Restore:

This operation has been cancelled due to restrictions in effect on this computer. Please contact your systems administrator.

This message and a very similar message to it also pops up when I try to access start: set program access and defaults

I think I am hosed.

Noggin

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Unable to get rid or clean out virus
« Reply #3 on: November 29, 2007, 06:37:04 PM »
Are you logged as an administrator? Or common user?
Check Control Panel > Users accounts
The best things in life are free.

noggin

  • Guest
Re: Unable to get rid or clean out virus
« Reply #4 on: November 29, 2007, 06:43:18 PM »
Are you logged as an administrator? Or common user?
Check Control Panel > Users accounts

This is one of the fishy things I think related to the virus we are seeing.... I do not have a way to access the control panel.  I have looked several places to try to get to it and I have not found a way to get there. any suggestions?

That said, if I log off of XP it gives me an option to log back on by clicking one square that says "user" on it.

Noggin

noggin

  • Guest
Re: Unable to get rid or clean out virus
« Reply #5 on: November 29, 2007, 06:55:50 PM »
Now I am getting random alert messages that say:

Warning: potential spyware operation
Your computer is making unauthorized copies of your system and internet files.  Run... blah blah blah

and then it asks me to click Yes to download some software.  This is part of the virus because two of the words are mispelled in the warning text box.. right?

I have seen this message a dozen times now in the last 4 hours.  I always get rid of it and have never clicked Yes to download their software (which is probably another virus).

help?

Noggin

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Unable to get rid or clean out virus
« Reply #6 on: November 29, 2007, 07:12:12 PM »
This is one of the fishy things I think related to the virus we are seeing.... I do not have a way to access the control panel.  I have looked several places to try to get to it and I have not found a way to get there. any suggestions?
Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.
If infected files are found, it's safer to send them to Chest instead of deleting them.
This way you can further analysis them.

That said, if I log off of XP it gives me an option to log back on by clicking one square that says "user" on it.
Are you an user called 'user'?

Now I am getting random alert messages that say:
Warning: potential spyware operation
Your computer is making unauthorized copies of your system and internet files.  Run... blah blah blah
Do not do that!
Run RogueRemover now! (www.malwarebytes.org)
The best things in life are free.

noggin

  • Guest
Re: Unable to get rid or clean out virus
« Reply #7 on: November 29, 2007, 07:39:02 PM »
This is one of the fishy things I think related to the virus we are seeing.... I do not have a way to access the control panel.  I have looked several places to try to get to it and I have not found a way to get there. any suggestions?
Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.
If infected files are found, it's safer to send them to Chest instead of deleting them.
This way you can further analysis them.

Okay I did the boot scan... it says a certain file is infected by some sort of malware-gen... my computer has now hanged itself and I tried to move this infected file to the chest but the computer is not responding... still not responding... it is frozen.  Rebooting...

Quote
That said, if I log off of XP it gives me an option to log back on by clicking one square that says "user" on it.
Are you an user called 'user'?
Yes.

Quote
Now I am getting random alert messages that say:
Warning: potential spyware operation
Your computer is making unauthorized copies of your system and internet files.  Run... blah blah blah
Do not do that!
Run RogueRemover now! (www.malwarebytes.org)

I downloaded the software and ran rogue remover.  The message still comes up though.  and I still cannot get to my control panel.
« Last Edit: November 29, 2007, 07:51:27 PM by noggin »

Spiritsongs

  • Guest
Re: Unable to get rid or clean out virus
« Reply #8 on: November 30, 2007, 07:19:04 PM »
 :)  Hi :

      You do NOT have a "virus", but something a lot more serious . You have
      NOT mentioned IF you have ANY antiSPYWARE/antiTROJAN program(s) on
      your computer !? To initially try and solve your problem, you should try to
      install, update, and run a "Complete Scan" of the FREE Version of
      "SUPERAntiSpyware" from www.superantispyware.com .

      Did "Rogueremover" say WHAT it found on your computer ? If yes,
      give details ?

      P.S. You MAY have a "rootkit"; to start the investigation as to this
      possibility, I recommend you use the FREE "RootkitRevealer", available
      from www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx
« Last Edit: November 30, 2007, 07:25:36 PM by Spiritsongs »