PDA

View Full Version : My pc is screwed...........adware


worangejuice
12-02-2008, 11:19 PM
So I gots a nasty trojan virus that will not cease to exist. I've used
Spybot
Super anti spyware
Bazooka
Spyware Blaster
2005 copy of norton (did nothing)

Windows defender will not load cause my xp pro is pirated
AGV will also not load up, prob cause of adware!

Scanned, deleted problems, then they come right back!

Read old threads on adware. Tried everything, not working.

Takes over my desktop pic and puts up a 'warning; comp infected'

Crap, any other suggestions?

I read that system restore may let the trojan back its ass up and screw shit up again.

Geek squad charges $170 over the phone to fix it. (NO)

So looks like I'll have to reformat my comp, backed up all files I need.

Problem is, I dont have the books on my custom built pc.

A friend is gonna send me a corp. copy of windows xp pro 2 and a corporate copy of Norton.

Looks like this is all thats left.

gay.

Any suggestions appreciated.

Oh yeah,
In safe mode now.
:wtf:

hunter8411
12-02-2008, 11:28 PM
Your pretty much stuck on doing one of 2 things.

Either paying Geek Squad to fix it because they have tools which will allow the them to view your .dll's(which most likely there is an infected or multiple infected .dll) as well as one or more of your .exe files has been infected to allow the trojan to reinstall itself whenever the system restarts no matter how many times you remove it with the generic removal tools. Yes they are expensive because they have the right tools and the know how to remove the problem.

Or

Backup all your files, format, and reinstall everything. You can find missing drivers by looking at the parts you have installed and finding the model number, then look them up online where there are a few sites you can get drivers from. This is not going to be fun or quick but it is the cheapest route, and probably what your gonna do.


P.S. You could be lucky enough to have a friend or friend of a friend that works for the Geek Squad, and ACTUALLY knows how to use their tools properly.

Good Luck with whatever you do.

240love
12-02-2008, 11:34 PM
geek squad is sooo expensive...

worangejuice
12-02-2008, 11:34 PM
word.........haven't been able to find anyone locally that has the time or gives a crap really. Yeah, I used spybot and jumped to the source on the problems, but could not delete anything. It was the registry where it planted new user files.

Ze Geek squad goes like so
24hr. phone service $170
in store $200
in home $300

Dont wanna dick around w/ local shops (probably shoul look into them though) may have to do calls tomorrow. Probably slightly less than geek squad.
Don't really trust computer shops for one reason or another.
this sucks

any reccommendations for a local shop in Los Angeles?

tgd89
12-02-2008, 11:39 PM
If you're worried about losing files you can do an non-destructive reinstall, but any installed programs will need to be reinstalled, but all the data is still there. This could solve most of the problems, but isn't as effective as a full reformat.

Another option is doing a repair install, which sometimes will also help, but is not as effective as the option above or a full reformat, but keeps everything the same.

Either way I would back up what's important first if you can.

hunter8411
12-02-2008, 11:41 PM
Geek Squad is expensive. But for a reason, anyone can erase and reinstall everything. Thats what the local shops will do, hell thats even what the Geek Squad agents who don't know to how work on computers very well recommend doing.

The main thing is the software they have, some mom & pop shops steal and use their software, Circuit City, Staples, Make it Work(such a rip) have all been caught stealing and using Geek Squad tools. It makes it so you can easily clean up a computer if you know what your doing.

Good luck with the local shops. Just make sure to backup EVERYTHING you don't want to lose before you take it in. And check what their warranty is, some places like Make it Work only has a 3 day warranty.

If you have a AAA card you can get 20% off Geek Squad services which may put it in a better price range for you. DON'T do the phone support, its just not worth the cost or time IMHO.

^^ You could try the non-destructive restore, but based on the problems your having I wouldn't expect that to clear it all up.

worangejuice
12-02-2008, 11:43 PM
whoooaaaa,
I'm from Albuquerque originally ^^ (tgd89)
cool.
Now in Hollywood.
Anywho

I guess I can just google those procedures then.
Would it be in the safemode menu?
got everything backed up already.

(Hunter)
The guy I'm talking to has the corp version of windows xp pro pack 2. Said it formats fine, as he also has a custom built pc.(he's in another state)
Said it works fine for him, as hes built a couple.

Really wouldnt mind reformatting it just to clean it up.
Should I worry bout grabbing files that the trojan has possibly infected? I'm putting them on my portable, don't wanna transmit it again. (sounds gross)

hunter8411
12-02-2008, 11:53 PM
You don't have to worry about re-infecting. As long as you are not taking any zipped files that you downloaded. Pictures, Music, Movies, documents will not re-infect your system because they will not be infected themselves.

If your system is custom built and EVERYTHING is onboard then windows will probably have all the generic drivers built in for everything. If its not onboard then it will be easy enough for you to find the driver. The only thing you may have problems with are the Network card, sound card, video card. Then you would just have to look those up individually.

Vision Garage
12-02-2008, 11:55 PM
haha. I would remove the infected hard drive and do an install on either a new hard drive to keep your new drive from being infected. or just try to save as much as you can on either DVDs or some other source.

I dont kno about trojan horses, but most viruses ive dealt with do not attach to shit i usually backup: ie... pictures, word documents, pdf files, videos...

I usually find the viruses somewhere in my system files.

Kalashnikov
12-02-2008, 11:56 PM
You can also download Drivers from the manufacturers site.

I remember, I had such a bad virus, it Fried my hard drive. I just bought a new hard drive on Ebay and solved.

Most of the time, virus can be erased using "Reformat". But the one I had a few months ago, was super crazy and will not let me access anything. Cannot access BIOS, Cannot access start up set, pretty much, I could not Boot the system. The HD was Fried.

It was my brother who downloads a lot of B.S. And Now I make An Admin Account and a Limted account / guest account.
It does help a bit doing this. Just don't download Porn. You can Stream them now...so I don't download anything now a days.

Porn= Stream
Music=Online Radio
Movies=Stream, bitttorrent
Games=Borrow from friends
Everything else, Google, youtube, and Zilvia

worangejuice
12-03-2008, 12:01 AM
sweeet,
Sounds like I will be doing the reformat.
one of my friends is always telling me to re format my pc or 'just buy a new one' whatever.
Got all my music and pics, all I really need, can get a copy of the new adobe suite easy enough.
Just got the damn thing fixed to.
Was watching mad Southpark and the Office and all that online crap.

I will be using Mozilla from now on, I was using Microsoft Internet Explorer.

Just can't stand waiting.

tgd89
12-03-2008, 12:06 AM
Yeah the options I mentioned will be when you put the in the windows disk when you boot( remember to set the cd drive as the first boot device in the BIOS), just read the options on the bottom of the page. It will ask you if you want to re-format, "repair current installation", or install a new copy.

worangejuice
12-03-2008, 12:07 AM
haha. I would remove the infected hard drive and do an install on either a new hard drive to keep your new drive from being infected. or just try to save as much as you can on either DVDs or some other source.

I dont kno about trojan horses, but most viruses ive dealt with do not attach to shit i usually backup: ie... pictures, word documents, pdf files, videos...

I usually find the viruses somewhere in my system files.

So I just have to get a new internal Hard Drive?
They have a lot more memory now and are also cheaper.

Damn a hard drive fryer huh....must been some really good porn...haha.

Yeah the pop up I x'd out of was in Russian!
(shouldn't a done that)
Linked off of 'google' image search to 'freeones.forums'.
Watch out for those links if anyone on here knows what I'm talkin bout. Bad shit dude.

thanks for all the help guys.
:trogdor:

RiversideS13
12-03-2008, 12:17 AM
what do you do with your computer? if just go online, chatting, type papers, watch video, listen to music... i would suggest you switch to linux OS (ubuntu). it is FREE and comes pretty much every software you need including bittorrent, open office (word document process, powerpoint...etc), video player, firefox, all messengers...etc

Ubuntu Home Page | Ubuntu (http://www.ubuntu.com/)

you do not need to reformat your pc for ubuntu, however, it needs at least 5 or 8GB of hard disk. after you will pretty much never worry about any malwares.

ALTRNTV
12-03-2008, 12:27 AM
Waits for the Mac owners to chime in... :keke:
I have a Mac but I'll bite my tongue.

I hate viruses, had so many of them on my old laptop. I just got frustrated and
threw it against the wall. I won.

Kalashnikov
12-03-2008, 12:31 AM
Some Douche bag at Bestbuys told me that Mac's never get viruses.

I told him, get the fuck away from me. Is there any truth in this?

I like macs for video and imagine software, I can't stand them ever since the first ones with a one Click mouse. WTF?

tgd89
12-03-2008, 12:39 AM
Anything can get a virus, Macs are just less exploited than pc's, and internet explorer. Most virus/adware ect.. problems go away if you use a decent browser( opera, firefox, chrome), and don't do anything stupid.

ALTRNTV
12-03-2008, 12:44 AM
From what I heard, Mac's have only 4 known viruses. Don't quote me on that though.

HyperTek
12-03-2008, 12:45 AM
open msconfig

go to startup, look for any suspecious looking programs and unclick...
go to uninstall software via control panel, there could be some ad programs installed.. delete.

Next time install Firefox and only use firefox.

Uninstall all ur virus protection, and reinstall AVG Free - Download antivirus and antispyware software for Windows XP and Vista (http://free.avg.com/)
Try again.

Are you sure you are getting a virus? Ive seen some programs install a internet explorer pop up window that looks like a virus warning so you can download thier software..

luftrofl
12-03-2008, 12:52 AM
Some Douche bag at Bestbuys told me that Mac's never get viruses.

I told him, get the fuck away from me. Is there any truth in this?

I like macs for video and imagine software, I can't stand them ever since the first ones with a one Click mouse. WTF?

There is a little truth to it. It's true that macs get far fewer viruses/spyware/etc.. It's to the point where people can generalize and say that they don't because, compared to a windows machine, a mac is far less likely to get a virus.

There is a problem with saying that, however, because for those who say "macs don't get viruses," there is the implication that because macs are very secure (which they are, actually, and more so than windows), if not completely secure, they get so few viruses. Unfortunately for the douchebags who like to say that sort of thing, what really makes that statement true is that apple is still relatively small which means that a virus written for windows will have a greater effect than one for macs simply based on the ratio of windows machines to apple machines. In short, Macs can get viruses, but they generally don't because they're rarely targeted.

serris
12-03-2008, 01:22 AM
+1 to what HyperTek said. Using Firefox is more secure than IE.

Did you run Spybot in Safe Mode? The thing keeps coming back because you have System Restore on. If you're sure that you don't need to restore to a previous point, turn it off, then run Spybot in Safe Mode, along with all the antivirus tools you might have.

If you can get the exact name of the virus/trojan, you can usually google it and find solutions. Symantec's web site also has tools for each virus they've found. Just search for the virus/trojan on their site and they'll list the tools available to remove it.

If none of this really works for you, I would do what hunter8411 said and go with option 2. The only 100% way. Unless you happen to back up the virus...then that's another can of worms. :-/

Good luck! (I live near LA and I could look at it for you, however, I don't have any openings in my schedule until the 13th.)

SochBAT
12-03-2008, 01:42 AM
I actually do my own anti-virus busting by doing regedit. Then again, i'm coming from linux, and am used to the DIY mentality. Seriously, find the problem, diagnose, and find the manual way to remove it. tedious, but you know it will remove all spiders that will be lurking.

PS. I never use any kinda adware/spycrap shit. Safe browsing with the right settings is enough. firefox > all. GoogleChrome for the leet. If you want any help, holla! Aim= Socheatmen

One known bug that XP does is the Windows Messager program. it is pretty much an open window for trojans and stupid users that actually click anything that comes up instead of just Xing the corner/pressing ESC.

I love virus busting though. Makes me feel like a 1995 Hackorz.

Oo_Skyline_oO
12-03-2008, 01:54 AM
Easy as this, if you're gonna spend 170 on geek squad, instead back up all your stuff and spend those 170 on a new operating system(vista, linux, xp) with a legit license, and a good antivirus subscripsion like kaspersky, norton makes your computer SLOOOOOOOWW as FUUUUUUUUU*, takes too many recources, and it is nowhere near as effective on stopping your computer from getting infected. As of the xp, trust me, I've been building computers for about 4 years, Microsoft will ALWAYS find some other stupid way to hastle you about the stupid serial code, one day you will not be able to download an update which without it your computer will have some sort of stupid random problem and it will either irritate the hell out of you or it will render you computer useless. A pirated copy will only make your computer new for a few months, till microsoft finds away to screw you over

neverrain
12-03-2008, 04:40 AM
Did you make a decision on this yet? One of my good friends used to work for Geek Squad and will probably do it for less than what they charge. Plus we are both local in LA.

And stay the fuck away from Norton. That program is such a piece of shit. It's sold to stupid people who don't know any better.

PM me if you are interested. I can ask my buddy.

hunter8411
12-03-2008, 10:38 AM
Actually if you want to use Norton, then use the Norton AV 2008 version, not the system works and not the Internet Security, just the plain old Anti-Virus version. It is actually better than a lot of the other Virus protections right now, but still not the best by far.

However if you use Firefox and don't go downloading everything that pops up on your screen you really do not need a virus protection. I have NEVER had one on my PC and only rarely get virus or spyware and thats from something I downloaded which I shouldn't have. The protection software is for piece of mind and for those that are click happy.

There is a lot of bad information in this thread being posted because someone read or heard something from a friend most likely.

Future240
12-03-2008, 10:41 AM
Maybe a 2008 copy of norton would help, seein as its virus definition base is in computer time, old as fucking hell

LeftNutOfGowd
12-03-2008, 10:43 AM
I got a program you can use that will remove spywear and ad-wear if you want. Its only a trial but just run the full scan once and it detects everything. One of the IT guys at my work hooked me up with it just send me your email address and ill send it to you

worangejuice
12-03-2008, 11:53 AM
Alright.....WOW
Thanks for all the input gentleman. Unfortunately I have to go to work for my 10 hr shift, So I'll hit this bitch up again tonight. let my computer and brain turn off last night.
Once again this is my place of intarnet familia.hehe

keistyle
12-03-2008, 01:06 PM
you could ghost..
or just save everything to an external hard drive (music, pictures, video), all the important stuff, its not like you cant get music twice?
nuking then re-installing isnt all too hard. just make sure you install office, then anti virus first, before going on the internet.
i think . .

jc
12-03-2008, 02:32 PM
Malwarebytes.org (http://www.malwarebytes.org/mbam.php)

Removes a good chuck of those FakeAV style trojans. If you can get it running in normal mode do so and update the definitions then reboot and run the scan in safe mode. If you're Windows is so screwed you can't run it in normal mode you probably have a Rootkit and it's not worth cleaning up and you should do a re-load.

DALAZ_68
12-03-2008, 03:28 PM
I actually do my own anti-virus busting by doing regedit. Then again, i'm coming from linux, and am used to the DIY mentality. Seriously, find the problem, diagnose, and find the manual way to remove it. tedious, but you know it will remove all spiders that will be lurking.

PS. I never use any kinda adware/spycrap shit. Safe browsing with the right settings is enough. firefox > all. GoogleChrome for the leet. If you want any help, holla! Aim= Socheatmen

One known bug that XP does is the Windows Messager program. it is pretty much an open window for trojans and stupid users that actually click anything that comes up instead of just Xing the corner/pressing ESC.

I love virus busting though. Makes me feel like a 1995 Hackorz.
fire fox or chrome for me...to bad i wasnt so aware with my desktop as i am with my laptop...

my harddrive is still good on my desktop, but it keeps looping... keep tryin to do CTRL ALT DELETE and run Explorer.exe but th escreen keep swiping out and only leaving the backround, when the icons show up they only last for 10 seconds, i was abel to take out my music and picture files with my external HD....400GB External HD FTW

LeftNutOfGowd
12-03-2008, 03:38 PM
I got a 750 external HD from target for 88 bucks so i back-up all my shit there music, important files, movies, pics, and most important my porn collection

theronin
12-03-2008, 08:23 PM
just learn how to partition. keep all ur important shit on ur d,e,f etc drives. then when shit like this happens, its easy as fuck to reinstall on ur C partition.

look for partition magic at your favorite pirate place.

Vision Garage
12-03-2008, 10:42 PM
haha. A new hard drive will do wonders for your computer. It will probably load faster since it has a faster seek time and what not. Technology gets better with time so maybe it is time to upgrade. Just save the shit you really need to. Then you got a spare hard drive to put the PORNZ!

ALTRNTV
12-04-2008, 12:48 PM
lulz at the Apple ad on Zilvia.

http://www.tqlkg.com/gn122xjnbhf0335AA1A02158A896

rc1honda
12-04-2008, 12:53 PM
1 Dont download porn from strange sites
2 Buy a MAC, you will never have to worry about a virus again.

And some guy said that MAC dosen't have as many viruses cuz there are not as many MAC computers as PC. That's not really true. PC has so many viruses cuz of the way it operates. It uses executable files(.exe) . MAC does not. They operate and open and run programs way differently. Fact is that it's way harder to create a MAC program file virus then a PC due to the way they operate. No small or maybe even semi-good hacker wants to take the time to create a MAC virus and have it be obsolete by the time it's finished due to a update. But .exe files never change and will run the same everytime the only way stop them is by recognizing that they are viruses and prohibit windows from executing the programs. BTW is it "viruses" or "virui" ?

ALTRNTV
12-04-2008, 01:05 PM
http://img216.imageshack.us/img216/176/lulhn3.jpg

http://www.winboard.org/forum/attachments/witze-comics/22514d1195342676-im-mac-im-unix-im-vista-1-2a6099f6f340bfc9.jpg

worangejuice
12-04-2008, 09:12 PM
Malwarebytes.org (http://www.malwarebytes.org/mbam.php)

Removes a good chuck of those FakeAV style trojans. If you can get it running in normal mode do so and update the definitions then reboot and run the scan in safe mode. If you're Windows is so screwed you can't run it in normal mode you probably have a Rootkit and it's not worth cleaning up and you should do a re-load.
*update*
Mad Props to you JC sir!!!!!
HOLY SHIT!!!!!!!!
Ran this download^^^
I ran this in safe mode. It deleted 57 bad files, and it had a couple files it could not delete until reboot. Soes I did, and BAM no more annoying adware!!!!
Not sure if were out of the woods yet.
Everything is running as normal.
No Sound yet, gotta reinstall that. Adware knocks this out I understand.
Just Psyched something actually worked!
So what steps should I take now?
My desktop reset, but still has all the icons.Itunes crapped out. what does that mean? It's all running smooth now :goyou:

Here's what it came up with:
http://i13.photobucket.com/albums/a253/worangejuice/adwareshit.jpg
http://i13.photobucket.com/albums/a253/worangejuice/adwareshit2-1.jpg

Running Spyware Doctor right now..........
as of now still finding infections and some viral things. 'Residue'?
http://i13.photobucket.com/albums/a253/worangejuice/adwareshit3.jpg

jc
12-04-2008, 09:25 PM
Looks like you had a couple rootkit variants. I would suggest backing up any files you need and trashing that windows install and starting over. Once you get a rootkit it's so hard to say if you got everything. If you miss even one it can re-enable the downloader part and re-infect you and you'll be back at square one.

Good luck.

SochBAT
12-04-2008, 09:48 PM
Unless, again, you're daring enough to use redegit for registry-busting action!

Otherwise, fresh install!

worangejuice
12-04-2008, 10:24 PM
I may try that. regedit.
That's where Spybot directed me when r/clicked jump to spot.
Went to registry editor. It wouldn't let me delete the items.
Like they were new/false users.
Running scans again, still in 'normal mode'.
Happy for now, but a reformat is long overdue.
So if these bad products are 'blocked' as stated on the immunization process of these adware deleters.
Does that mean there gone, or is it just exactly what it states. There is no delete option........
Alsooooo..
Those password and such detectors, do they only pick up on new visits to password sites?
Or can it search the comp. for sites visited in the past?