Virus help

Associate
Joined
22 Jan 2008
Posts
351
Just looking for some idea's how to remove a nasty virus from a neighbors laptop, its running XP SP3.

I've disabled system restore.

I've tried the following :
Full scan with AntiVir - Found 5 different Trojans - Removed all
Full Scan with Malwarebytes - 436 different types of Malware - Removed all
Full Scan with SpyBot Search & Destory - Found nothing
Full Scan with AVG 8.0 - Found nothing
Full Scan with Ad-Aware - Found nothing

Yet when I restart the computer they all appear again... It also keeps popping up in the middle of the screen saying something like " visit this site for the fix " and in the bottom right next to the clock it says " VIRUS ALERT!"

Any other idea of what I could try would be much appreciated.
I could always format, but that is a last resort.

Edit: On a side note its also stopping me from opening task manager, and has also removed everything from the start menu.

Also tried running scans in safe mode

Edit: Managed to get it removed with Combofix & Vundofix.
 
Last edited:
Just looking for some idea's how to remove a nasty virus from a neighbors laptop, its running XP SP3.

I've disabled system restore.

I've tried the following :
Full scan with AntiVir - Found 5 different Trojans - Removed all
Full Scan with Malwarebytes - 436 different types of Malware - Removed all
Full Scan with SpyBot Search & Destory - Found nothing
Full Scan with AVG 8.0 - Found nothing
Full Scan with Ad-Aware - Found nothing

Yet when I restart the computer they all appear again... It also keeps popping up in the middle of the screen saying something like " visit this site for the fix " and in the bottom right next to the clock it says " VIRUS ALERT!"

Any other idea of what I could try would be much appreciated.
I could always format, but that is a last resort.

Have you tried running those antivirus scanners in safe mode?

It sounds similar to a vundo trojan and many antiviruses are hopeless at removing those type of infections.

I suggest you try running the antiviruses in safe mode. If you still have those fake popups, then install and run SuperAntiSpyware free edition (google it). It's a great program at removing these type of infections.
If that fails, then download and run smitfraudfix and vundofix (google them and follow instructions on how to use them correctly).
 
Last edited:
It sounds similar to a vundo trojan and many antiviruses are hopeless at removing those type of infections.

Just had a quick look at the last remove log, there was about 8 or 9 of vundo.H Trojans there :eek:

If you still have those fake popups, then install and run SuperAntiSpyware free edition (google it). It's a great program at removing these type of infections.
If that fails, then download and run smitfraudfix and vundofix (google them and follow instructions on how to use them correctly).

I'll try Superantispyware now, then I'll try smitfraudfix and vundofix.

Edit: On a side note its also stopping me from opening task manager, and has also removed everything from the start menu.

Also tried running scans in safe mode
 
Last edited:
Just gonna let Superantispyware finish running then I'll try smitfraudfix, Vundofix & combofix. If these don't manage to fix the problem would it be best to just format ?
 
switch off restore point and enter safe mode and then scan your software - try 30 days free trial Kaspersky AV also CounterSpy V3 and see if it high risk but it not free software.. I used KIS 2009 and CS V3...

you need switch off Restore point then reboot and enter Safe mode and scan and if you can remove it and then reboot it again.
 
Just gonna let Superantispyware finish running then I'll try smitfraudfix, Vundofix & combofix. If these don't manage to fix the problem would it be best to just format ?

I'm pretty confident they'll be able to remove it. It sounds like a load of vundo infections and those tools are the best at removing them.

If however they are not able to remove them, then you might want to try using HiJackThis and posting a log on here. It'll show what is running on the PC and some people might be able to help you remove the infections manually, but it could take some time.
 
How have you managed with the laptop ?
I've just had a PC in for repair with this -VIRUS ALERT- ransomware on . It's a killer to remove without the right software .This thing hid the HDD & CD -ROM , disabled the desktop properties , registry editor and loads of other things .It's all gone now , thanks to some excellent software .
 
Back
Top Bottom