Need help with persistant virus

Associate
Joined
11 Dec 2003
Posts
599
Location
London
I foolishly opened a questionable execution file (something I never do under normal circumstances) - and now am paying for it...

I have tried both Lavasoft Ad-Aware & my resident anti virus software (F-Secure), but neither seem to see it.

I however see it constantly from boot up:

As soon as windows launches a red bordered popup appears to the right over the taskbar informing me:

"Your Computer is Infected!

Critical System Error!
System detected virus activities.
They may cause critical system failure.
Please use antimalware software to
clean and protect your system from
parasite programs. Click here to get
all available software"

clicking on this obviously opens a browser page to a scam site. In this case:

http://www.spywarequake.com/?aff=247

Ignoring the infuriating flashing icon that has taken up residence beside my clock doesnt help as I inevitably start to get automatic sporadic internet explorer launches (i always use firefox incidentally) these are usually porn or gambling popups followed immediately by invitations to "rid your system of malware!" linking to shady looking 'PC protection' sites.

an example being : http://malwarewipe.com/?rid=247

in addition a couple of shortcuts have mysteriously apeared on my desktop linking to:

http://realsecurityonline.com/ and http://youronlinesecurity.com/phptest/

Can't see anything running in task manager (to tell the truth I wouldn't recognise half of the 46 processes I have running)

I am at a total loss, any help would be much appreciated as it interferes with everything I'm doing on my PC, stopping me from working..

Thanks,

Sols
 
Hmmm well, tried that and during the process (and much screaming popups) my browser mysteriously shutdown.

pretty damn odd

Is F-Secure likely to protest a Trend Micro house probe? or is this the virus/spyware being very crafty? :confused:
 
I have used TrendMicro for years whenever my resident AV has been disabled by a virus. Norton, McAffee and NOD32 have never had any problems with it.

You can try disabling F-Secure and try the online scan again. If that doesn't work, you have a rather crafty virus!

You could also try HijackThis. It is a small utility that scans ya registry for all sorts of nasties that may be lurking. You will have to ask someone else, or check out the HijackThis help for how to use it, though.

At this point I would probably be noting down any process name I didn't recognise and googling it and see what it is. Eventually you should come across something thats identified as being a nasty. Having found it, I would reboot into Safe Mode then go about killing it and killing the registry entry for it wherever it can be found.

It isn't entirely recommended, however, to go rooting around in your registry if you don't know what you are doing.

I strongly suggest you backup your registry before you start deleting stuff lol.

I have been poking around in my registry for years so I have absolutely no fear [or sense :p] about nuking something I dont like the look of.

SiriusB
 
Sound advice, thanks

I'd much rather not go poking around the registry as i really have no idea what i'm doing on that kind of level.

Trying the Trend Micro site again using a different kernal, but it seems to have stalled.

browser taskbar reading: Wating for eu-trendmicro-europe.com...

and the in-frame Staus says it's Idle

though it doesnt appear to be hanging, as firefox is letting me access other sites as i write (this one included of course).

popups have calmed down though
 
Start -> Run -> Type in MSCONFIG.

Look for anything suspicious in amongst that list, reboot and test. :)

Now run your spyware checkers and see what happens. But make sure you are using the most updated definations. :)
 
Thnks all - in the end I just rolled back 24hrs with System Restore and it seems to have cured the problem - hope to god I haven't just buried it, to lurk invisibly below the surface :eek:
 
oh not this again, had this on a win2k machine, worked on it for 3 days, somehow it stayed there and refused to go, got rid of it a few times, but kept coming back, in the end i had to upgrade the machine to XPH
 
chex said:

Looks pretty thorough, will certainly try this if it pops up again (fingers crossed)



uk_viper said:
oh not this again, had this on a win2k machine, worked on it for 3 days, somehow it stayed there and refused to go, got rid of it a few times, but kept coming back, in the end i had to upgrade the machine to XPH

Yes indeed, XP's system restore saves the day yet again



ShakenNstirred said:
could also try kasperskys online scan
http://www.kaspersky.com/virusscanner

Wasn't aware of this one. Have bookmarked, ta
 
Back
Top Bottom