eXceem

Go Back   eXceem > Off Topic > Technical Help

Claim your amazing £1,000 slots booster bonus now!


Having MAJOR virus probs - PLS HELP

This is a discussion on Having MAJOR virus probs - PLS HELP within the Technical Help forums, part of the Off Topic category; Major infections - afraid to restart machine. Ran Avira after a full MSE scan and it deleted the stuff it ...

Reply
 
Thread Tools
Old 10-04-11, 05:13 PM   #1
iBook
 
barcelonic's Avatar
 
Join Date: Aug 2008
Location: Swansea
Posts: 2,927
barcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of light

Having MAJOR virus probs - PLS HELP




Major infections - afraid to restart machine.

Ran Avira after a full MSE scan and it deleted the stuff it found but the log says 19 detections found only 14 deleted.

All Im asking is if anyone who can understand this stuff would mind taking a look at the following log to tell me their thoughts

Any help massively appreciated thanks guys

Spoiler
__________________
APOLOGIES FOR TYPOS I HAVE A NEW KEYBOARD
Join the Consoles.RI conga today!

__ Free Loader | UK Freebies

Recieved:
Spoiler

"Talking about music is like dancing about architecture" - Frank Zappa

Last edited by barcelonic; 10-04-11 at 05:14 PM..
 
Reply With Quote
Old 10-04-11, 05:14 PM   #2
iBook
 
barcelonic's Avatar
 
Join Date: Aug 2008
Location: Swansea
Posts: 2,927
barcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of light
Sorry for double post - the log was too long for one post

Rest of log>>

Spoiler
__________________
APOLOGIES FOR TYPOS I HAVE A NEW KEYBOARD
Join the Consoles.RI conga today!

__ Free Loader | UK Freebies

Recieved:
Spoiler

"Talking about music is like dancing about architecture" - Frank Zappa
 
Reply With Quote
Old 10-04-11, 05:20 PM   #3
iBook
 
grabrail's Avatar
 
Join Date: Dec 2006
Location: Nottingham
Posts: 2,325
grabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to all
Send a message via MSN to grabrail
You may be better getting some proper AV rather than free stuff. McAffee works a lot better.

Anyhow, looks like protected areas of your O/S are infected, "c:\windows\system32\drivers"

Try booting in safe mode and running the scan again, this should stop the driver files loading and allw them to be removed properly.
 
Reply With Quote
Old 10-04-11, 05:24 PM   #4
HTC Sensation 4G
 
MrRedman's Avatar
 
Join Date: Sep 2010
Location: London
Posts: 346
MrRedman is an unknown quantity at this point
Send a message via twitter to MrRedman
Boot in Safe Mode - Start > Search box type "System Restore". Take your computer back to the last good configuration state.
__________________
Click here! to join the freebiejeebies gadgets conga and get 2 FREE greens!



 
Reply With Quote
Old 10-04-11, 05:28 PM   #5
iBook
 
grabrail's Avatar
 
Join Date: Dec 2006
Location: Nottingham
Posts: 2,325
grabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to all
Send a message via MSN to grabrail
Quote:
Originally Posted by MrRedman View Post
Boot in Safe Mode - Start > Search box type "System Restore". Take your computer back to the last good configuration state.
Won't help. Once your computer boots succesfully to the O/S, this is marked as the "the last know good configuration"

So basically each time you boot your computer and log on, you are working on the last known good configuration. That option helps if you cannot get into windows at all, it will boot the last time you did, removing any changes or additions to the registry since the last time you succesfully logged in.
 
Reply With Quote
Old 10-04-11, 05:34 PM   #6
iBook
 
barcelonic's Avatar
 
Join Date: Aug 2008
Location: Swansea
Posts: 2,927
barcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of light
Quote:
Originally Posted by MrRedman View Post
Boot in Safe Mode - Start > Search box type "System Restore". Take your computer back to the last good configuration state.
I never set restore points and dont wanna lose data so not really an option for me.

Quote:
Originally Posted by grabrail View Post
You may be better getting some proper AV rather than free stuff. McAffee works a lot better.

Anyhow, looks like protected areas of your O/S are infected, "c:\windows\system32\drivers"

Try booting in safe mode and running the scan again, this should stop the driver files loading and allw them to be removed properly.
Unfortunately i can't really do that until tomorrow as I urgently need use of PC tonight and havent restarted yet since infection but tomorrow i'll definitely go into safe mode, i never thought of that really - am i right in thinking safe mode doesnt connect to internet, hence why its safe?


Oh and btw Ive found processes running which are probably blocking my success somehow like ''iexplore.exe *32'' - there are 5 of these running. I thought it could be IE but i have 6 tabs open, not 5 so thats weird.

The descriptions of files found in MSE are roughly as like this:
about 3 moderate threats [browser modifiers], about 2 trojans [severe] and about 10 or so Exploits with no names just codes [severe] - all of which came at the same time when i rushed through a software installation and accidentally forgot to untick all the cr@p they try to throw in like toolbars, homepages etc..

Fortunately i know enough about the net to know when i've been infected and i know enough about PC viruses from past experience that restarting acts as a catalyst so i'm leaving it on as i need the use of it for tonight, if only for tonight.

Sorry for length of this post btw lol im just stressin lol
__________________
APOLOGIES FOR TYPOS I HAVE A NEW KEYBOARD
Join the Consoles.RI conga today!

__ Free Loader | UK Freebies

Recieved:
Spoiler

"Talking about music is like dancing about architecture" - Frank Zappa

Last edited by barcelonic; 10-04-11 at 05:36 PM..
 
Reply With Quote
Old 10-04-11, 05:41 PM   #7
iBook
 
grabrail's Avatar
 
Join Date: Dec 2006
Location: Nottingham
Posts: 2,325
grabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to all
Send a message via MSN to grabrail
You have 2 options (depending on O/S) when choosing safe mode, with or without networking,

If you choose without then you wont have any internet access, if you choose with you probably will.

Safe mode essentially stops loading any drivers for your hardware and loads some basic legacy drivers for video etc. As your drivers folder contains infected files, these will be in use when booted in normal mode, but when loaded in safe mode these drivers shouldnt start so the files wont be in use. The AV should then be able to remove them.

Another thing you can do, is the following

start > run > msconfig

Then go to the startup tab and have a look down the list for anything weird. If its all weird to you lol, you can take a screenshot and post it on here and i will assist in disabling anything you shouldnt need.


I dont think theres anything too serious been picked up in the scan, more annoyances and trojans.
 
Reply With Quote
Old 10-04-11, 05:49 PM   #8
iBook
 
barcelonic's Avatar
 
Join Date: Aug 2008
Location: Swansea
Posts: 2,927
barcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of light
thanks grabrail - thing is when i run a scan on MSE once its completed it says the stuffs been removed but asks me to restart computer; now MSE has NEVER asked me to restart following successful removal of any kind of malware - thats the thing that got me worrying in the first place

i will try the msconfig thing i think, do i need to be in safe mode for that tho?
__________________
APOLOGIES FOR TYPOS I HAVE A NEW KEYBOARD
Join the Consoles.RI conga today!

__ Free Loader | UK Freebies

Recieved:
Spoiler

"Talking about music is like dancing about architecture" - Frank Zappa
 
Reply With Quote
Old 10-04-11, 05:53 PM   #9
iBook
 
grabrail's Avatar
 
Join Date: Dec 2006
Location: Nottingham
Posts: 2,325
grabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to all
Send a message via MSN to grabrail
Quote:
Originally Posted by barcelonic View Post
thanks grabrail - thing is when i run a scan on MSE once its completed it says the stuffs been removed but asks me to restart computer; now MSE has NEVER asked me to restart following successful removal of any kind of malware - thats the thing that got me worrying in the first place

i will try the msconfig thing i think, do i need to be in safe mode for that tho?
No you can run msconfig at anytime.

The reason it wants you to reboot is becuase it will probably of marked the files it cant access for deletion, it will remove them upon restart
 
Reply With Quote
Old 10-04-11, 06:12 PM   #10
iBook
 
barcelonic's Avatar
 
Join Date: Aug 2008
Location: Swansea
Posts: 2,927
barcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of lightbarcelonic is a glorious beacon of light
Quote:
Originally Posted by grabrail View Post
No you can run msconfig at anytime.

The reason it wants you to reboot is becuase it will probably of marked the files it cant access for deletion, it will remove them upon restart
the startup list contained things im familiar with, except Microsoft Intellipoint and Microsoft Security Client.

Im using Win7 64bit Home and i checked the folders for those programs and the date modified was Jan 11 and Dec 10 respectively, if that means anything.

As for running safe mode, i can do that tomorrow and hopefully im overreacting but i've lost PCs to viruses before and i cant stand being without my PC as im housebound and its my only source of entertainment [home cinema custombuilt machine]

edit: tried to rep you but couldn't sry
__________________
APOLOGIES FOR TYPOS I HAVE A NEW KEYBOARD
Join the Consoles.RI conga today!

__ Free Loader | UK Freebies

Recieved:
Spoiler

"Talking about music is like dancing about architecture" - Frank Zappa

Last edited by barcelonic; 10-04-11 at 06:13 PM..
 
Reply With Quote
Old 10-04-11, 06:13 PM   #11
iBook
 
grabrail's Avatar
 
Join Date: Dec 2006
Location: Nottingham
Posts: 2,325
grabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to allgrabrail is a name known to all
Send a message via MSN to grabrail
Quote:
Originally Posted by barcelonic View Post
the startup list contained things im familiar with, except Microsoft Intellipoint and Microsoft Security Client.
These are quite safe

Let me know how you get on
 
Reply With Quote
Old 10-04-11, 07:00 PM   #12
iPod 30gb
 
Join Date: Aug 2009
Location: Widnes
Posts: 1,090
cono1717 is a jewel in the rough
Probably the best piece of virus removal I have used.

Malwarebytes' Anti-Malware: Malwarebytes - Download it, let the database update, reboot in safe mode, full scan (while having a refreshing beverage) - Job Done.
__________________
Totally Free iPad | McFlurry Ice Cream Van

Everything I say reflects my own opinions and not that of any company.
 
Reply With Quote
Old 10-04-11, 07:26 PM   #13
Mini Mac
 
Ilikefree's Avatar
 
Join Date: Jul 2008
Location: London
Posts: 5,141
Ilikefree is a splendid one to beholdIlikefree is a splendid one to beholdIlikefree is a splendid one to beholdIlikefree is a splendid one to beholdIlikefree is a splendid one to behold
MBAM is the most powerful virus removal software I've ever used. IMO it's worth paying for the real time scanning stuff
 
Reply With Quote
Old 10-04-11, 07:38 PM   #14
Romper Stomper
 
Cruelworld's Avatar
 
Join Date: May 2009
Location: Behind the fridge...
Posts: 4,268
Cruelworld is a glorious beacon of lightCruelworld is a glorious beacon of lightCruelworld is a glorious beacon of light
Send a message via twitter to Cruelworld
format c:
Best removal tool ever
 
Reply With Quote
Old 10-04-11, 07:57 PM   #15
Mr Baldy Chicken
 
the_icks's Avatar
 
Join Date: Mar 2006
Posts: 14,487
the_icks has a reputation beyond reputethe_icks has a reputation beyond reputethe_icks has a reputation beyond reputethe_icks has a reputation beyond reputethe_icks has a reputation beyond reputethe_icks has a reputation beyond reputethe_icks has a reputation beyond repute
Send a message via MSN to the_icks
fdisk /mbr
__________________

 
Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off





All times are GMT. The time now is 08:58 PM.
All trademarks and copyrights held by respective owners. Forum posts are owned by the poster.

Powered by vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO
no new posts