Forum Home
Press F1
 
Thread ID: 125203 2012-06-13 20:53:00 Huge virus, URGENT help needed please. Luppi (12974) Press F1
Post ID Timestamp Content User
1281507 2012-06-14 00:39:00 can you uninstall the process with revo, do an advanced uninstall, then run rkill. Nick G (16709)
1281508 2012-06-14 01:15:00 Would System Restore be of any use?

LL
Never, in fact that's an excellent way to get all the malware back again. Best to always disable it, clean up then re-enable it.
pctek (84)
1281509 2012-06-14 02:04:00 can you uninstall the process with revo, do an advanced uninstall, then run rkill. Doubt it, the infection will have gotten well into the system files, made multi copies or renamed itself as something different. They usually make "backups" so to speak so if one is removed another will kick in and carry on causing havoc.

BTW, that reinstall, done all finished and transferring the data back while having lunch ;)
wainuitech (129)
1281510 2012-06-14 03:38:00 The pics in your post #22. The run|21266 maybe pointing to a file on the hdd. Like post #5 here (forums.malwarebytes.org)

This entry O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\pol icies\Explorer\Run: 40964 = C:\PROGRA~3\LOCALS~1\Temp\msazujo.com. The filename on yours maybe different. You may have to download OTL (like post #2 in the above link)
Speedy Gonzales (78)
1281511 2012-06-14 08:43:00 Sorry about bailing out last night, was 3 AM when i posted and had an early wake up-call so i had to get some sleep.

Right now, i am posting from the infected PC. Weirdest thing happened. I start it up for the first time today and EVERYTHING starts normally. I mean Firewall works, AVG boots up (which it never did before) and the internet works. Also, the process and the files are gone, and i can't explain that.

For anyone that is working in this domain or knows malware people. Please make my problem as known as possible, send it to the major anti-virus companies so they know of it. I haven't found a single shread of details about this virus on google or any website so it must be new. Please get it researched.

I am standing by with my Windows 7 Ultimate disk as we speak, what do you recommend. Since everything is in good order, should i still wipe everything clean or let it breathe and see what i see?
Luppi (12974)
1281512 2012-06-14 08:51:00 Doubt it, the infection will have gotten well into the system files, made multi copies or renamed itself as something different. They usually make "backups" so to speak so if one is removed another will kick in and carry on causing havoc.

BTW, that reinstall, done all finished and transferring the data back while having lunch ;)
So the viruses make backups of themselves. That wakes them smarter than a lot of humans :)
Nick G (16709)
1281513 2012-06-14 08:52:00 Get rid of AVG install MSE, update it then do a full scan. See if its clean Speedy Gonzales (78)
1281514 2012-06-14 08:54:00 Sorry about bailing out last night, was 3 AM when i posted and had an early wake up-call so i had to get some sleep.

Right now, i am posting from the infected PC. Weirdest thing happened. I start it up for the first time today and EVERYTHING starts normally. I mean Firewall works, AVG boots up (which it never did before) and the internet works. Also, the process and the files are gone, and i can't explain that.

For anyone that is working in this domain or knows malware people. Please make my problem as known as possible, send it to the major anti-virus companies so they know of it. I haven't found a single shread of details about this virus on google or any website so it must be new. Please get it researched.

I am standing by with my Windows 7 Ultimate disk as we speak, what do you recommend. Since everything is in good order, should i still wipe everything clean or let it breathe and see what i see?

Well, if it is acting normall I see no need to wipe it. I would ditch AVG, get either avast or mse, and run a full scan with both it and malwarebytes. Also, it wouldn't hurt to get threatfire, or spybot, as well as running panda cloud virus. I doubt it will have just suddenly gone, viruses usually don't work like that, so still treat your computer as infected-which is why I'm recommending threatfire and panda.
Nick G (16709)
1281515 2012-06-14 09:09:00 Weird thing is, if i go to Control Pannel, my Windos Firewall says it's active, but the little flag thingy in my task-bar still says i should re-check the settings and they still point to "being controled by the system administrator", although if i go through CP i can modify them as i wish. I have Spybot, nothing but some adware found, installing threatfire and will do a panda scan.

What's the best free antivirus out there? Any other security programs i should know about if i decide to start over? Nothing but the basics, i don't want it to be full of stuff that does the same thing. Speedy you got a PM.
Luppi (12974)
1281516 2012-06-14 09:55:00 If you want a free AV, then try MSSE - but just remember, its not as good as some others. Classic example, is almost weekly I will see PC's in the workshop that have MSSE or Avast and have infections. While No One AV is perfect some are worse than others.

As for other software, did you run Super antispyware ?? thats usually picks up more than Malwarebytes.

Some systems get totally toasted, like the one I had today, had Avast and it was totally destroyed with at least 5 different rootkits and so many infections when I tried to clean it, it made it unbootable in any mode, thats why i reinstalled it.

Trouble is with some infections you think you have it clean then shortly after (a few days) WHAM right back again.
wainuitech (129)
1 2 3 4 5 6