Poll

Can you help?

Hope so!
6 (85.7%)
I don+t understand this
1 (14.3%)

Total Members Voted: 0

Author Topic: Computer taken over by Virus?  (Read 13592 times)

0 Members and 1 Guest are viewing this topic.

qim

  • Guest
Computer taken over by Virus?
« on: November 09, 2010, 08:57:31 PM »
I am gradually losing the computer. First Avast disappeared and eventually found that it had been disativated. I cannot get cMalawarebytes to open and now not ven any IE page.  I cannot open Java in the ControlPanel.  I can no longer go into safe mode... I tried to do a systen«m restore but can't open the necessary page, etc,

E

What do I do now?

Thanks~

« Last Edit: January 05, 2011, 04:43:37 PM by qim »

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: Computer taken over by Virus?
« Reply #1 on: November 09, 2010, 09:05:28 PM »
1.Get dr.web cure it and scan your computer with it
http://www.freedrweb.com/cureit/?lng=en
2.After doing that download mbam and do a full scan after updating it.
http://www.malwarebytes.org/mbam.php
3.Do a hijack hunter log and post it.
http://www.novirusthanks.org/products/hijack-hunter/
Those are the first steps
Dreams don't die, they just fall asleep.

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
Re: Computer taken over by Virus?
« Reply #2 on: November 09, 2010, 09:57:29 PM »
could we have a picture of your taskmngr?Also msconfig.Click start>run>msconfig>Start
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: Computer taken over by Virus?
« Reply #3 on: November 09, 2010, 10:21:54 PM »
Hi qim

If you are totally unable access your computer to scan your computer, you will need to a Bootable Antivirus to scan and remove all malwares, Here is manual how to use one: http://www.omidfarhang.com/computer/security/avira-rescuecd (You will need to Burn the disc using a clean computer)

And then return to windows and scan your computer using Hitman Pro:
How to use it: Download Hitman Pro (or Hitman Pro 64 Bit) to your desktop, Hold the Left Ctrl Key on your keyboard and double click on Hitman Pro to run it, keep Ctrl key holding until Hitman Pro screen appear. then click on next and let it scan your computer, let it remove the malwares it find, if it ask you for license active the 30 Days trial version. after removal, restart your computer.

if you have windows installation disc, after reboot your computer, insert the disc in drive, open 'Run' and type 'sfc /scannow' to let windows restore damaged or missing windows files from installation disc.

Now repair avast by going to control panel -> Add/remove programs (Program and Features in Vista/7) -> select avast, click change, in the opened windows scroll down to find repair, select it and follow setup to repair avast.
Twitter: OmidFarhangEn - OS: Manjaro KDE

qim

  • Guest
Re: Computer taken over by Virus?
« Reply #4 on: November 10, 2010, 09:32:33 AM »
Thank you everybody

Meanwhile, after a good night sleep the computer has regained most of what it had lost, for reasons I cannot understand.  Yesterday, I still managed to run Malawarebytes which did not show any problems, but got an error when I tried to update.  Thjis morning, it updated and ran without problems.  Last night, I managed to run Avast boot scan and again without finding anything. One puzzling fact: yesteday I had trouble opening MyComputer/Proiperties and when I did the tab about SystemRestore was missing; I also could not get to SystemRestore through SystemTools. This morning I accessed both. I still cannot open Java in the ControlPanel. Finally, I ran OTL twice but did not get the Extras.txt. I am attaching the OTL.txt.

qim

  • Guest
Re: Computer taken over by Virus?
« Reply #5 on: November 11, 2010, 07:40:56 AM »
hello Superhacker

I managed to download Dr Web Cure it.  The first scan found nothing, but the second FULL scan found Dellth.txt in c:\I386\compdata\dellth.txt, infected with modification to IRC.sleeper.

Unfortunately, my problem has returned and at times I am unable to do anything once the system restarts: unresponsice Start, Mycomputer\Properties, Ctrl-Alt-Del, or even the power-down button, forcing me to disconnect by pressing the power button for about 4 seconds.

Right now I am doing a Spybot scan (I am using a different computer to send you this message).  I wonder if something drastic like ComboFix might do the trick.  Can you help, please?

Thank you

qim

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: Computer taken over by Virus?
« Reply #6 on: November 11, 2010, 11:30:00 AM »
qim, did you read my post?
Twitter: OmidFarhangEn - OS: Manjaro KDE

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Computer taken over by Virus?
« Reply #7 on: November 11, 2010, 11:32:59 AM »
Quote
Right now I am doing a Spybot scan
SpyBot is usless, the only thing it can remove is tracking cookies....
« Last Edit: November 11, 2010, 11:36:30 AM by Pondus »

qim

  • Guest
Re: Computer taken over by Virus?
« Reply #8 on: November 11, 2010, 11:38:03 AM »
Hi Omid

Yes, I did read your post. Thank you very much.  However, I managed to get the computer going again and I am starting to understand what is going on. I expect that I have some sort of virus that installs itself when the computer restarts.  When it does Comodo Firewall alerts me to a Services.exe that is about to change the registry.  I assumed this was essential to the system so I allowed it and lost virtually all control.  I have just seen EventViwewer and most services were denied access as I restarted.

Last time I told Comodo not to accept the change and the computer now seems to be responding normally.  However, the virus is still there, I think, and would like to get rid of it.

I ran avast boorscan, Malawarebytes, Spybot, Bitdefender and Dr Web. They showed a clean computer except for Dr Web that found IRC.sleeper.

If you can help me get rid of whatever is lurking I would be very grateful.

Regards

qim

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: Computer taken over by Virus?
« Reply #9 on: November 11, 2010, 11:55:07 AM »
I ran avast boorscan, Malawarebytes, Spybot, Bitdefender and Dr Web. They showed a clean computer except for Dr Web that found IRC.sleeper.
It won't hurt try my manual that I said above ;)
Twitter: OmidFarhangEn - OS: Manjaro KDE

qim

  • Guest
Re: Computer taken over by Virus?
« Reply #10 on: November 11, 2010, 02:48:27 PM »
Helo Ormid

I had a look at the manual re rescue disks.  I will try and do one.  But my problem now is to sort out the computer.  It is nearlu normal but only nearly.  For instance, I am unable to edit Msconfig/start.  When I try to save nothing happens.  Either I have a virus lurking or the Firewall is blocking something, possible through my own errors.

I need to make sure the computer is clean while I have reasonable access.

Thanks

qim

Offline Omid Farhang

  • Frontend Developer
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1660
  • I wish I could write longer personal text!!
    • Homepage
Re: Computer taken over by Virus?
« Reply #11 on: November 11, 2010, 03:11:06 PM »
qim, I'm not using comodo so I'm not sure if blocking something by Comodo caused that you have not full access over your computer configuration? you may try reset all rules in comodo and start using your computer again (after making sure your computer is clean).
Twitter: OmidFarhangEn - OS: Manjaro KDE

qim

  • Guest
Re: Computer taken over by Virus?
« Reply #12 on: November 11, 2010, 03:21:30 PM »
Hello Superhacker

Finally, I managed to do the HijackHunter. Log attached.

Thanks

qim

Offline mikaelrask

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1556
Re: Computer taken over by Virus?
« Reply #13 on: November 12, 2010, 09:50:17 AM »
i would suggest you try superantispyware also and see if it comes up with anything. sometimes it detects things malwarbytes don't and vice versa.

http://superantispyware.com/

if you have internet access again of course.

good luck
Windows 8.1 amd a10-5700 64 bit
12 GB ram 1 tb hard drive. Avast 18, MBAM

Offline superhacker

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 979
  • superhacker != super mario
Re: Computer taken over by Virus?
« Reply #14 on: November 12, 2010, 01:10:54 PM »
Sorry for late i had to study a lot yesterday.
Even the only suspect item in the report is not a malware ;)
Code: [Select]
C:\WINDOWS\system32\ckldrv.sys
So i think you are clean and th your problem caused by comodo firewall which may sandbox essential processes so i suggest:
1.Uninstall comodo"restart"
2.activate windows firewall from control panel
3.after doing that do a dr.web scan.
I think you wont get the problem again.
4.Reinstall comodo firewall and i suggest a more easy one like outpost free firewall.
Dreams don't die, they just fall asleep.