Computers |
|
| | #1 (permalink) |
| Junior Techie Join Date: Dec 2007 Location: USA
Posts: 87
| Well, i have ridded my computers of viruses before, but this one(or more than one) is just comming back and back again, im clearly not getting rid of it entirley. I beleive i got this virus from a crack website. At the time it was my old computer, and i was being very careless. It is now the family computer, and they have made the virus much worse. It keeps opening pop-ups and windows messages saying "do you want to rid your computer pop-ups?" and stuff "WARNING windows security: A virus has been detected on your computer, do you want to get rid of it?" the pop-up looks legit, with the real windows logo and stuff, so obviously the computer illiterate family members of mine fell for it and now there is tons of crap. I have gotten rid of SOME of the torjans, and 553 of the spyware things installed on the computer using AVG and anti virus. There are tons of very suspicious processes running and the pop ups continue to pop up. I have been killing the processes with task manage, but obviously i cant continue to do this every minute for the rest of my family... plus its a major pain. I restarted my comp so that all of the bad processes are up again, i am going to run hijackthis2 and post the log in a minute. I will also post a SS of the most presistent pop up. After running all programs on Orisis' guide, i will post the log again, and i hope you guys will be able to confirm that everything is gone, or help me get rid of anythign that remains. thanks in advance, b/c i already know i will get great support from the best forums on the net! Pic of the pop-ups: http://i4.photobucket.com/albums/y10...o/popupsSS.jpg -------------------------------------------------------------- EDIT: on a side note... b/c this is just as annoying as some pop-ups. How do i get rid of this, i think i started when i tried to uninstall a damaged peice of software... its been going on for like 6 months but i was able to deal with it... however my family will struggle. Everytime the system is rebooted it pops up and looks like this: below. the only way to get rid of it is by going to task manager and ending process "ISUSPM.exe" Hitting cancel does nothing. http://i4.photobucket.com/albums/y103/Klupto/isump.jpg
__________________ Laptop: Asus M51 Series http://www.newegg.com/Product/Produc...82E16834220308 My Build: Asus M2N32-SLI Deluxe || AMD Athalon x2 6000+ (3.25Ghz OC) || AC Freezer 64 Pro || nVidia GeForce 8800GT 512MB || G.Skill 2x 2GB DDR2 800 || Western Digital 500GB 7200 HDD || Samsung 20x DVD Burner || Sunbeam Transformer ATX Full Case || Windows Vista 64 Bit || Rosewill 850W PSU Logitech G15 Keyboard (new orange version) & Logitech G5 Mouse (black/blue version) 11k 3DMark06 Score Last edited by mark1413; 01-06-2008 at 01:52 PM. |
| | |
| | #3 (permalink) | |
| Junior Techie Join Date: Dec 2007 Location: USA
Posts: 87
| i also get random icons showing up on the desktop. Its virus removal and love search crap... that i obviously did not install. here is my logfile: Quote:
i will now run all of the software in the guide and post another logfile. Thankyou guys so much.
__________________ Laptop: Asus M51 Series http://www.newegg.com/Product/Produc...82E16834220308 My Build: Asus M2N32-SLI Deluxe || AMD Athalon x2 6000+ (3.25Ghz OC) || AC Freezer 64 Pro || nVidia GeForce 8800GT 512MB || G.Skill 2x 2GB DDR2 800 || Western Digital 500GB 7200 HDD || Samsung 20x DVD Burner || Sunbeam Transformer ATX Full Case || Windows Vista 64 Bit || Rosewill 850W PSU Logitech G15 Keyboard (new orange version) & Logitech G5 Mouse (black/blue version) 11k 3DMark06 Score | |
| | |
| | #5 (permalink) |
| Junior Techie Join Date: Dec 2007 Location: USA
Posts: 87
| well, i cannot get into the control panel. The icons of all places that i would get to it are simply not there anymore. The only way to try to open add/remove programs is by going to my comp, C drive, and then clicking it on the side. However when i do this a msg pops up saying that i do not have sufficient access to this. Well, i do... this is an administrator account... the virus has somehow blocked me from this.
__________________ Laptop: Asus M51 Series http://www.newegg.com/Product/Produc...82E16834220308 My Build: Asus M2N32-SLI Deluxe || AMD Athalon x2 6000+ (3.25Ghz OC) || AC Freezer 64 Pro || nVidia GeForce 8800GT 512MB || G.Skill 2x 2GB DDR2 800 || Western Digital 500GB 7200 HDD || Samsung 20x DVD Burner || Sunbeam Transformer ATX Full Case || Windows Vista 64 Bit || Rosewill 850W PSU Logitech G15 Keyboard (new orange version) & Logitech G5 Mouse (black/blue version) 11k 3DMark06 Score |
| | |
| | #6 (permalink) | |
| Junior Techie Join Date: Dec 2007 Location: USA
Posts: 87
| ORSIS' virus removal guide completed. Here are my logs after running the programs. Quote:
system is running great now, havent had any pop-ups since running Trojan Remover... the others didnt really do much, most found nothing or only a few things... trojan remover cleaned up a TON of stuff... great guide, so far it looks like it has saved my system and a lot of important files i have on here... if you ever need a kidney let me know.... and please check my logs to see if there are anythings i need to fix... but so far so good. THANKS AGAIN SO MUCH THANK YOU lol
__________________ Laptop: Asus M51 Series http://www.newegg.com/Product/Produc...82E16834220308 My Build: Asus M2N32-SLI Deluxe || AMD Athalon x2 6000+ (3.25Ghz OC) || AC Freezer 64 Pro || nVidia GeForce 8800GT 512MB || G.Skill 2x 2GB DDR2 800 || Western Digital 500GB 7200 HDD || Samsung 20x DVD Burner || Sunbeam Transformer ATX Full Case || Windows Vista 64 Bit || Rosewill 850W PSU Logitech G15 Keyboard (new orange version) & Logitech G5 Mouse (black/blue version) 11k 3DMark06 Score | |
| | |
| | #7 (permalink) |
| Security/Hacking Mod Join Date: Jan 2005 Location: USA
Posts: 23,859
| Remove these entries O2 - BHO: (no name) - {09E5EBB0-6790-439A-9CD4-7C5B0479FB1B} - (no file) O2 - BHO: (no name) - {2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F} - C:\Program Files\Outerinfo\Outerinfo.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing) O4 - HKLM\..\Run: [avp] C:\WINDOWS\TEMP\win380 .exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - WorldWinner Cash Competitions O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab O23 - Service: Google Updater Service (gusvc) - Unknown owner - (no file) then post a new log |
| | |
| | #8 (permalink) | |
| Junior Techie Join Date: Dec 2007 Location: USA
Posts: 87
| ok i removed/fixed the ones you listed... TYVM... it all seems to be working normally now... btw this has GREATLY increased the speed of my computer... i cant express enough how much your guide has helped. Quote:
__________________ Laptop: Asus M51 Series http://www.newegg.com/Product/Produc...82E16834220308 My Build: Asus M2N32-SLI Deluxe || AMD Athalon x2 6000+ (3.25Ghz OC) || AC Freezer 64 Pro || nVidia GeForce 8800GT 512MB || G.Skill 2x 2GB DDR2 800 || Western Digital 500GB 7200 HDD || Samsung 20x DVD Burner || Sunbeam Transformer ATX Full Case || Windows Vista 64 Bit || Rosewill 850W PSU Logitech G15 Keyboard (new orange version) & Logitech G5 Mouse (black/blue version) 11k 3DMark06 Score | |
| | |
| | #9 (permalink) |
| Security/Hacking Mod Join Date: Jan 2005 Location: USA
Posts: 23,859
| Looks much better. You may need to reinstall Google, the updater service may be in an error state. Remove these 3 entries R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local O1 - Hosts: 11.18.250.4 ad.doubleclick.net O23 - Service: Google Updater Service (gusvc) - Unknown owner - (no file) Then post a new log |
| | |
![]() |
| Thread Tools | |
| Display Modes | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Symantec Screwup Is 'Worse Than Any Virus' | Osiris | Virus - Spyware Protection / Detection | 1 | 12-07-2007 11:10 AM |
| Vista attacked by 13-year-old virus | Osiris | Virus - Spyware Protection / Detection | 2 | 09-19-2007 08:51 AM |
| HELP !! MSN virus | froze | Virus - Spyware Protection / Detection | 6 | 08-12-2007 01:43 PM |
| Worm Masquerades As Phony Virus Warning | Osiris | Virus - Spyware Protection / Detection | 0 | 07-11-2007 12:08 PM |
| Proof Of Concept Virus For iPods Running Linux | Osiris | Linux, BSD, other *nixes & Open Source Software | 0 | 04-06-2007 11:57 AM |