Page 1 of 4 1234 LastLast
Results 1 to 20 of 61
  1. #1
    Veteran 35th-ANV-SS's Avatar
    Join Date
    Oct 2008
    Location
    Wherever life takes me
    Posts
    12,526

    Red
    02 35th LE Camaro SS

    IT Experts Enter!!!

    So I'm using my old ass desktop for internet since I managed to download a virus. Need help deleting this motherfucker...

    It is the 2011 XP Anti-Virus trojan.

    I cannot access the internet at all. I cannot run .exe files so that means I cannot run Malware to remove it.

    I've tried booting up in safe mode, the virus still runs.

    Any suggestions??

  2. #2
    None Shall Pass Knight's Avatar
    Join Date
    Jan 2010
    Location
    East of Cleveland, Ohio
    Posts
    3,827

    Black
    99 WS.6 - Modified

    Try reinstalling Windows.

  3. #3
    let the F-Bodies roll jimmybling31's Avatar
    Join Date
    Oct 2007
    Location
    hixson tennessee
    Age
    33
    Posts
    1,641

    white
    94 camaro z28

    Quote Originally Posted by 35th-ANV-SS View Post
    So I'm using my old ass desktop for internet since I managed to download a virus. Need help deleting this motherfucker...

    It is the 2011 XP Anti-Virus trojan.

    I cannot access the internet at all. I cannot run .exe files so that means I cannot run Malware to remove it.

    I've tried booting up in safe mode, the virus still runs.

    Any suggestions??
    use a mac to retrieve personal data off the hard drive externally and run a virus scan on the files before putting them on computer again. format the computer after retrieving files with a full format, not fast. since it starts even in safe mode, not too much you can do.

  4. #4
    Senior Member Z28Thunder's Avatar
    Join Date
    Dec 2006
    Location
    Broken Arrow, Ok
    Age
    59
    Posts
    4,542

    Arctic White
    2000 Z28

    I understand the virus runs in safe mode. Do you not get to a prompt that would let you run an app?? You may need to got into recovery counsel. This should already be on your HD. If not you will need a copy of XP with the same SP you have. Once in recovery mode run fixboot and fixmbr. Then go back into safe mode and fix the issue. Another way to fix it is find a cheap external HDD case that plugs in usb. Take the HD out of your PC and plug it into another. Then run the scan on your HD from that machine. Below is one fix I googled for it.


    http://www.precisesecurity.com/rogue...ti-virus-2011/

  5. #5
    let the F-Bodies roll jimmybling31's Avatar
    Join Date
    Oct 2007
    Location
    hixson tennessee
    Age
    33
    Posts
    1,641

    white
    94 camaro z28

    Quote Originally Posted by Z28Thunder View Post
    I understand the virus runs in safe mode. Do you not get to a prompt that would let you run an app?? You may need to got into recovery counsel. This should already be on your HD. If not you will need a copy of XP with the same SP you have. Once in recovery mode run fixboot and fixmbr. Then go back into safe mode and fix the issue. Another way to fix it is find a cheap external HDD case that plugs in usb. Take the HD out of your PC and plug it into another. Then run the scan on your HD from that machine. Below is one fix I googled for it.


    http://www.precisesecurity.com/rogue...ti-virus-2011/
    if someone is asking how to deal with it on a car forum chances are they won't be very comfortable in a windows recovery console.

  6. #6
    Senior Member Z28Thunder's Avatar
    Join Date
    Dec 2006
    Location
    Broken Arrow, Ok
    Age
    59
    Posts
    4,542

    Arctic White
    2000 Z28

    Quote Originally Posted by jimmybling31 View Post
    if someone is asking how to deal with it on a car forum chances are they won't be very comfortable in a windows recovery console.
    He asked for help and got several options. The virus does not require a rebuild of windows. Not that a rebuild is not a bad idea. Just stating it can be fixed. Heck if you read the link all you need to do is use Task Manager to end the process. Then clean the drive. He asked for help just trying..

  7. #7
    Veteran 35th-ANV-SS's Avatar
    Join Date
    Oct 2008
    Location
    Wherever life takes me
    Posts
    12,526

    Red
    02 35th LE Camaro SS

    I can end the app using Task Manager, but it restarts...

    And correct, I've never edited a registry before or anything of that nature.

  8. #8
    Veteran 35th-ANV-SS's Avatar
    Join Date
    Oct 2008
    Location
    Wherever life takes me
    Posts
    12,526

    Red
    02 35th LE Camaro SS

    I managed to get Avast to run, but I don't know if that will detect the virus or not...scanning now.

    I also e-mailed myself STOPzilla and downloaded it. Odd, but I can access my work e-mail, but not Google or other sites b/c of the virus.

    I'm trying to get STOPzilla to run now. Doesn't look promising.

  9. #9
    Veteran 35th-ANV-SS's Avatar
    Join Date
    Oct 2008
    Location
    Wherever life takes me
    Posts
    12,526

    Red
    02 35th LE Camaro SS

    I was on that site. I didn't feel comfortable trying to use the "manual delete" option. Seems to be the only way to remove this thing though.

  10. #10
    Senior Member Z28Thunder's Avatar
    Join Date
    Dec 2006
    Location
    Broken Arrow, Ok
    Age
    59
    Posts
    4,542

    Arctic White
    2000 Z28

    Quote Originally Posted by 35th-ANV-SS View Post
    I can end the app using Task Manager, but it restarts...

    And correct, I've never edited a registry before or anything of that nature.
    The recovery console is not editing the registry.. But the link does mention edits you need to make with the registry.

  11. #11
    Senior Member Z28Thunder's Avatar
    Join Date
    Dec 2006
    Location
    Broken Arrow, Ok
    Age
    59
    Posts
    4,542

    Arctic White
    2000 Z28

    Quote Originally Posted by 35th-ANV-SS View Post
    I was on that site. I didn't feel comfortable trying to use the "manual delete" option. Seems to be the only way to remove this thing though.
    Sometimes manual delete is the only way to get rid of one. If you do not feel comfortable find a nerd or geek friend. I bet they might help out.

  12. #12
    Veteran 35th-ANV-SS's Avatar
    Join Date
    Oct 2008
    Location
    Wherever life takes me
    Posts
    12,526

    Red
    02 35th LE Camaro SS

    Quote Originally Posted by Z28Thunder View Post
    The recovery console is not editing the registry.. But the link does mention edits you need to make with the registry.
    OK - going to look at that site again about the recovery console.

    Just read this threat is a 8/10...FML.

    Don't I need to know the name of the file to stop it??? It keeps changing every time I restart the computer.

    One time it was called "dif.exe", another time "2011 XP Anti-virus".

    From site: Get rid of XP Anti-Virus 2011 start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
    (random characters).exe

    I don't know (random characters).exe

  13. #13
    Member CJREX's Avatar
    Join Date
    Oct 2007
    Location
    GA
    Posts
    701
    Gone:2001 Camaro SS #4846

    Try combofix.

    I've had it successfully remove a rootkit that Avast and MBAM couldn't budge.

    http://www.bleepingcomputer.com/down...virus/combofix

    Another thing you may be able to do is download a live Linux like Puppy and boot from the Linux CD, then mount your Windows drive and run the Clam AV on it.

  14. #14
    Senior Member Z28Thunder's Avatar
    Join Date
    Dec 2006
    Location
    Broken Arrow, Ok
    Age
    59
    Posts
    4,542

    Arctic White
    2000 Z28

    Quote Originally Posted by 35th-ANV-SS View Post
    OK - going to look at that site again about the recovery console.

    Just read this threat is a 8/10...FML.

    Don't I need to know the name of the file to stop it??? It keeps changing every time I restart the computer.

    One time it was called "dif.exe", another time "2011 XP Anti-virus".

    From site: Get rid of XP Anti-Virus 2011 start-up entry by going to Start > Run, type msconfig on the “Open” dialog box. A windows containing System Configuration Utility will be launched. Go to Startup tab and uncheck the following Start-up item(s):
    (random characters).exe

    I don't know (random characters).exe

    The site did not mention recovery console. I did as a way to stop it from doing it at start up. Again I might suggest a Tech friend help you out if your not comfortable with the tools and registry edits.

  15. #15
    Senior Member Z28Thunder's Avatar
    Join Date
    Dec 2006
    Location
    Broken Arrow, Ok
    Age
    59
    Posts
    4,542

    Arctic White
    2000 Z28

    Quote Originally Posted by CJREX View Post
    Try combofix.

    I've had it successfully remove a rootkit that Avast and MBAM couldn't budge.

    http://www.bleepingcomputer.com/down...virus/combofix

    That is a good tool as well. But you will have to rename it from combofix. Many rootkits know about combofix.

  16. #16
    let the F-Bodies roll jimmybling31's Avatar
    Join Date
    Oct 2007
    Location
    hixson tennessee
    Age
    33
    Posts
    1,641

    white
    94 camaro z28

    IF I get a problem like this at work I just use a mac to recover files, scan them, then rebuild the system. takes 2-3 hours instead of.... whatever it takes to deal with it. 9/10 it's faster to just rebuild.

  17. #17
    Veteran 35th-ANV-SS's Avatar
    Join Date
    Oct 2008
    Location
    Wherever life takes me
    Posts
    12,526

    Red
    02 35th LE Camaro SS

    I cannot download anything on the infected computer from a website. I can't access the internet on it at all, not even booting up in safe mode with networking.

    I tried renaming my current spam removal tools...they still will not run.

    I am in the system config utility now and under the start-up tab...

    Looking for the exe file that starts up. I don't see anything though really. There are about 20 files that start-up, none of which look like a virus to me.

    And as I type this, STOPzilla just started scanning finally. My computer is running EXTREMELY slow though. Guessing this is because the virus is running in the background.

  18. #18
    Senior Member Z28Thunder's Avatar
    Join Date
    Dec 2006
    Location
    Broken Arrow, Ok
    Age
    59
    Posts
    4,542

    Arctic White
    2000 Z28

    Quote Originally Posted by jimmybling31 View Post
    IF I get a problem like this at work I just use a mac to recover files, scan them, then rebuild the system. takes 2-3 hours instead of.... whatever it takes to deal with it. 9/10 it's faster to just rebuild.
    I agree sometimes it is faster to just rebuild. But I fix issues like this daily for users. With the right tools it might take 20 or 30 minutes to fix it. If I get close to an hour then yes it is rebuild time. We have a default image at work and to install off a thumb drive takes about 6 minutes.

  19. #19
    ʢ ൧ ൨ ൩ ൪ ൫ ൬ ൭ ൮Ր Ց Ւ Փ Smittro's Avatar
    Join Date
    Feb 2009
    Location
    Pittsburgh
    Posts
    9,963

    White
    2008 Hummer H3

    Clean install, then better virus protection..

    Main reason I got rid of Xp was because of it's huge number of internet vulnerabilities and massive amounts of updates it required after reboot..

    Get a WIN7 PRO (64bit) powered comp..

    I do a clean boot every 30-60 days..

  20. #20
    let the F-Bodies roll jimmybling31's Avatar
    Join Date
    Oct 2007
    Location
    hixson tennessee
    Age
    33
    Posts
    1,641

    white
    94 camaro z28

    Quote Originally Posted by Z28Thunder View Post
    I agree sometimes it is faster to just rebuild. But I fix issues like this daily for users. With the right tools it might take 20 or 30 minutes to fix it. If I get close to an hour then yes it is rebuild time. We have a default image at work and to install off a thumb drive takes about 6 minutes.
    for our main client we have an image we use. For external clients that hold on to every penny would rather have a certain bill for 2-3 hours rather than chancing it for a 1-6 hour bill. Just how my job works though. Small businesses seem to hold their wallets very close when it comes to computer work.

Page 1 of 4 1234 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. any Experts ?
    By ahmadooo in forum GTO
    Replies: 8
    Last Post: 01-22-2011, 02:44 PM
  2. Home Audio Experts Enter
    By 35th-ANV-SS in forum Almost Anything Goes
    Replies: 11
    Last Post: 12-13-2009, 05:14 AM
  3. C3 experts please help
    By justinmc978 in forum Corvette
    Replies: 0
    Last Post: 06-19-2009, 08:58 AM
  4. HELP!.. L92 experts look here
    By redsap05 in forum General Help
    Replies: 0
    Last Post: 02-16-2008, 05:17 PM
  5. Internet experts
    By Sarge in forum Almost Anything Goes
    Replies: 39
    Last Post: 11-13-2007, 11:13 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •