Author Topic: Odd...  (Read 1843 times)

0 Members and 1 Guest are viewing this topic.

Offline adwight

  • Neo-Terran
  • 28
  • Go Gators!
I seem to have contracted a virus, yet it does some strange things.  When I push CTL+ALT+DEL the screen doesn't show up, whenever im in google searching for something to get rid of it (spybot etc.) it closes down Mozilla.  Don't ask me how this occured, because I don't even know how.  Anyone have any ideas.  It may have something to do with a Frog getting smashed by a truck that my friend sent me, but the virus scan said it was clean.  Now I can't even open antivirus...
Neo-Terra Victorious

The Lightning Marshall

158th Banshee Squadron

Gay people are rejects who can't get girls. Period. -DragonClaw
Can I have sex with it yet? -KnightTemplar

 

Offline Rictor

  • Murdered by Brazilian Psychopath
  • 29
Here try this. Its the latest Spybot install, renamed to avoid being potentially picked up by the virus.

http://www.penguinbomb.com/rictor/inconspicous.exe

edit: I can also recommend PRCView, to view all process that are running. From there, you can pick out any suspcious ones and Google them to see how to remove them.

[l]AFAIK, it doesn't work on WinXP[/l]

http://www.xmlsp.com/pview/prcview.htm
« Last Edit: March 11, 2005, 08:52:49 pm by 644 »

 

Offline pyro-manic

  • Flambé
  • 210
Have you tried booting into safe mode? That might stop whatever it is from loading on startup. Or download spybot on another machine and move it with a floppy or flash drive. It might not cover that...
Any fool can pull a trigger...

 

Offline adwight

  • Neo-Terran
  • 28
  • Go Gators!
Rictor's inconspicious thing is dling, thank you sir.  Lets hope this works.
Neo-Terra Victorious

The Lightning Marshall

158th Banshee Squadron

Gay people are rejects who can't get girls. Period. -DragonClaw
Can I have sex with it yet? -KnightTemplar

 

Offline adwight

  • Neo-Terran
  • 28
  • Go Gators!
Damned Virus, it stops Spybot from setting up, this thing is smart?  How do I boot up in Safe Mode, I'm not very computer savvy.
Neo-Terra Victorious

The Lightning Marshall

158th Banshee Squadron

Gay people are rejects who can't get girls. Period. -DragonClaw
Can I have sex with it yet? -KnightTemplar

 

Offline Rictor

  • Murdered by Brazilian Psychopath
  • 29
What OS are you running?

Usually, you just keep hitting F8 during startup, and it should allow you to pick which mode to boot up in. It may be different depending on the BIOS, but it should say at some point which button to press.

 

Offline Rictor

  • Murdered by Brazilian Psychopath
  • 29
crap, wrong button.

ignore this.

 

Offline adwight

  • Neo-Terran
  • 28
  • Go Gators!
Rictor, PRCView doesn't work either, This freaking thing is insane.  Im prolly gonna have to take it to the shop to have them take it out.
Neo-Terra Victorious

The Lightning Marshall

158th Banshee Squadron

Gay people are rejects who can't get girls. Period. -DragonClaw
Can I have sex with it yet? -KnightTemplar

 

Offline Bobboau

  • Just a MODern kinda guy
    Just MODerately cool
    And MODest too
  • 213
does it let you run msconfig or regedit?
what about hijackthis?
Bobboau, bringing you products that work... in theory
learn to use PCS
creator of the ProXimus Procedural Texture and Effect Generator
My latest build of PCS2, get it while it's hot!
PCS 2.0.3


DEUTERONOMY 22:11
Thou shalt not wear a garment of diverse sorts, [as] of woollen and linen together

 

Offline adwight

  • Neo-Terran
  • 28
  • Go Gators!
Yes I can run msconfig.  What can I do in MSconfig that can help me.  Regedit, however, it won't let me run.

Would reformatting the computer get rid of it?  I just got the strangest popup.  It looked like it was opening a file, and in the file name part it said Ha ha I see your Pic.jpg, fat elvis.jpg etc.  This thing is really pissing me off, I want to get rid of it NOW.
« Last Edit: March 11, 2005, 11:51:07 pm by 425 »
Neo-Terra Victorious

The Lightning Marshall

158th Banshee Squadron

Gay people are rejects who can't get girls. Period. -DragonClaw
Can I have sex with it yet? -KnightTemplar

 

Offline Stealth

  • Braiiins...
  • 211
LOL!!!

guys, you can't "trick" a virus by renaming the file.  hahaaaaahhaaha.  they're a lot smarter than you :p

E for Effort though

 

Offline Windrunner

  • 210
  • The Hammer.
i've had this problem before just like you adwight, its probably a virus like you said, it installs it self in the C:\WINDOWS\SYSTEM32 folder, Run  
avast antivirus, it will most likely find the virus, then you have to delete  some lines in the registry that virus made, but first you have to know what is the name of the virus. And runt the msconfig, see if there is any strange program that installed it self under the Autostart tab.
Staffmember: Hard Light Productions
I said a lot of things.  Some of them were even true. - Aldo_14

 

Offline WMCoolmon

  • Purveyor of space crack
  • 213
Quote
Originally posted by Stealth
LOL!!!

guys, you can't "trick" a virus by renaming the file.  hahaaaaahhaaha.  they're a lot smarter than you :p

E for Effort though


Depends on how well the virus is written. You should really know these things, Stealth...you do after all run a hosting server. :)
-C

 

Offline Bobboau

  • Just a MODern kinda guy
    Just MODerately cool
    And MODest too
  • 213
if it lets you run MSconfig that seems like a glaireing mistake on the virus writers fault, disable everything in the startup tab for start, and run in safe mode (you can do that from msconfig).

it also might be a good idea to disconect frome the internet whaile fighting this thing. you don't know what it's doing
Bobboau, bringing you products that work... in theory
learn to use PCS
creator of the ProXimus Procedural Texture and Effect Generator
My latest build of PCS2, get it while it's hot!
PCS 2.0.3


DEUTERONOMY 22:11
Thou shalt not wear a garment of diverse sorts, [as] of woollen and linen together

 

Offline adwight

  • Neo-Terran
  • 28
  • Go Gators!
Spybot from Safe Mode didn't do a thing, I was able to install it, but it doesn't detec the virus.  Im probably just going to take it to the store and have them clean it out.
Neo-Terra Victorious

The Lightning Marshall

158th Banshee Squadron

Gay people are rejects who can't get girls. Period. -DragonClaw
Can I have sex with it yet? -KnightTemplar

 

Offline Flipside

  • əp!sd!l£
  • 212
www.trend.com

Try the online scan there, it's not too shabby ;)

 

Offline adwight

  • Neo-Terran
  • 28
  • Go Gators!
Scan won't work, because the virus closos the window as soon as that pops up.  Any of you guys ever caught a thing this smart???  It's insane.
Neo-Terra Victorious

The Lightning Marshall

158th Banshee Squadron

Gay people are rejects who can't get girls. Period. -DragonClaw
Can I have sex with it yet? -KnightTemplar

 
A format would kill it....

Can you still burn CD's? Then see if you can grab Knoppix. It's a Linux version on CD. You don't have to install anything, but it'll boot from the CD. You can have some working safe net acces, allowing you to use one of those internet scans without the virus interfering.

I haven't heard of a virus that can defeat Knoppix, since Knoppix won't even touch the hard drive unless you tell it to.
just another newbie without any modding, FREDding or real programming experience

you haven't learned masochism until you've tried to read a Microsoft help file.  -- Goober5000
I've got 2 drug-addict syblings and one alcoholic whore. And I'm a ****ing sociopath --an0n
You cannot defeat Windows through strength alone. Only patience, a lot of good luck, and a sledgehammer will do the job. --StratComm

 

Offline Kie99

  • 211
Check your PMs Adwight.
"You shot me in the bollocks, Tim"
"Like I said, no hard feelings"

 

Offline Bobboau

  • Just a MODern kinda guy
    Just MODerately cool
    And MODest too
  • 213
if you were able to install spybot in safe mode then maybe it doesn't load up in safe mode (they usualy don't)

try the virus scan mentioned when in safe mode.

if that doesn't work, run hijackthis and report what it finds. _do not do anything untill one of use tells you to_. hijackthis will report everything that _could_ be a virus, includeing things that arn't, things that might very well be critical to your computer running. it is a nuke.

I have had virus/spyware programs nearly/as smart as this one, as soon as you are able to figure out a way to run the computer without wakeing it up you are half way to killing it. it does not wake up in safe mode, you have managed to boot into safe mode, if you can find were it is hideing now it will not come back.
Bobboau, bringing you products that work... in theory
learn to use PCS
creator of the ProXimus Procedural Texture and Effect Generator
My latest build of PCS2, get it while it's hot!
PCS 2.0.3


DEUTERONOMY 22:11
Thou shalt not wear a garment of diverse sorts, [as] of woollen and linen together