Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

never seen an virus stop me fixing it before...until today

Thread Tools
 
Search this Thread
 
Old 03 February 2009, 08:04 PM
  #1  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default never seen an virus stop me fixing it before...until today

Was asked to have a look at a computer that was 'playing up'

Turns out it has a rather nasty virus which actually stops me in a couple of ways from installing and repairing it.

Couldn't install Eset NOD32 - administrator rights had been changed! (let's me install normal application no bother)
Couldn't install MalwareBytes - refused to the run the installed. Changed the filename and got it installed, but then it wouldn't run the exe
Caused an error when I tried to install superantispyware
Checked the task manager and shut down the offending item, only to be told the PC was going to shut down in 20 secs!

Resorted to burning Kaspersky's boot CD which I'm taking along tomorrow AM.
I've also got Hiren's Boot CD for good measure.

Last edited by spectrum48k; 03 February 2009 at 08:06 PM.
Old 03 February 2009, 09:03 PM
  #2  
bioforger
Scooby Regular
iTrader: (1)
 
bioforger's Avatar
 
Join Date: Jan 2002
Location: Pig Hill, Wiltsh1te
Posts: 16,995
Received 5 Likes on 5 Posts
Default

Did u do the obvious n try to install your apps in safemode?
Old 03 February 2009, 10:45 PM
  #3  
suba
Scooby Regular
 
suba's Avatar
 
Join Date: Mar 2000
Posts: 2,462
Likes: 0
Received 0 Likes on 0 Posts
Default

turn off system restore too.
Old 03 February 2009, 10:57 PM
  #4  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Zero point in trying to fix it, you could be there hours trying to modify the registry, hosts file etc massive waste of time and energy.

Instead download Unbuntu, burn to disk, then run it as a live cd, you can then access the whole (Windows) drive, just plug in a usb drive or slave another hard drive to the computer and backup any files that are needed, reinstall Windows, job done in 35 minutes.

That's how the pros do it
Old 03 February 2009, 11:08 PM
  #5  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by bioforger
Did u do the obvious n try to install your apps in safemode?
yep, it was the only way to malwarebytes installed
Old 03 February 2009, 11:11 PM
  #6  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Dedrater
Zero point in trying to fix it, you could be there hours trying to modify the registry, hosts file etc massive waste of time and energy.

Instead download Unbuntu, burn to disk, then run it as a live cd, you can then access the whole (Windows) drive, just plug in a usb drive or slave another hard drive to the computer and backup any files that are needed, reinstall Windows, job done in 35 minutes.

That's how the pros do it
if only it were that simple! The machine has an engravr attached to it, with bespoke windows software. To reinstall would be a pain as the serials, calibration, commissioning are usually done by the supplier.

I know what you mean though - I might just pop out the hard drive and plug it into my laptop (I have a USB > SATA > ATA adapter. But I was hoping to get it done without having to open the damn thing up.

I've just tested the Kaspersky boot CD and it works rather nicely. It appears to boot a linux derivative, load a driver for the NIC and even update itself before doing a scan.

Last edited by spectrum48k; 03 February 2009 at 11:13 PM.
Old 03 February 2009, 11:26 PM
  #7  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Ah right, I know little about Kaspersky so can't comment, but look into HijackThis by Trend Micro (freeware) aswell
Old 03 February 2009, 11:36 PM
  #8  
spufus
Scooby Regular
iTrader: (2)
 
spufus's Avatar
 
Join Date: Oct 2003
Location: In the summerhouse
Posts: 661
Likes: 0
Received 0 Likes on 0 Posts
Default

I've had similar experiences.

I removed the drive(s) and put them in a USB caddy. Scanned them from my system & cleaned them with Malwarebytes, Spybot & AVG.
Took 4 attempts before they were "clean".
Reinstalled the drive in the PC, installed Malwarebytes, Spybot & AVG & ran the scan again.
Malwarebytes, Spybot & AVG all found about 18 "nasties". Cleaned them up & job done.
Took a bit of time, but both systems are back at 100% of what they were.

HTH

Just to add. Neither system would allow booting in safe mode nor allow any AV software to be installed or updated.
Old 03 February 2009, 11:41 PM
  #9  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by spufus

Just to add. Neither system would allow booting in safe mode nor allow any AV software to be installed or updated.
The simple fix to that would of been to sort the hosts file as it had been hijacked and modified. By default, the only thing that comes with a clean Windows install is 127.0.0.1 Localhost. What many new viruses / trojans attempt to do is edit your hosts file to essentially make most recognized antivirus programs unusable/disabled/non up datable.

Most will also disable the task manager, the registry key which controls whether task manager is enabled or disabled is

User Key: [HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Policies\System]System Key:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Policies\
System]

Value Name: DisableTaskMgr
Data Type: REG_DWORD (DWORD Value)
Value Data: (0 = default, 1 = disable Task Manager)
Old 04 February 2009, 12:18 AM
  #10  
Sonic'
Scooby Regular
 
Sonic''s Avatar
 
Join Date: Dec 2002
Location: Couch Spud
Posts: 9,277
Likes: 0
Received 0 Likes on 0 Posts
Default

Daft question but how does an edited hosts file affect programs from running, or your PC from booting up ?

a hosts file is only used to resolve names to ip addresses, and isnt actually needed
Old 04 February 2009, 12:38 AM
  #11  
badcompany
Scooby Regular
 
badcompany's Avatar
 
Join Date: Aug 2005
Posts: 298
Received 0 Likes on 0 Posts
Default

stopzilla if you want to pay to remove it..it does a free scan first

STOPzilla Anti-Spyware

i had the same virus a few weeks back
Old 04 February 2009, 02:50 AM
  #12  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

I was trying to repair a friends computer which had similar symptoms. A simple restore to previous safe state fixed it.
Old 04 February 2009, 09:52 AM
  #13  
Miniman
Scooby Regular
iTrader: (2)
 
Miniman's Avatar
 
Join Date: May 2002
Posts: 995
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Dedrater
reinstall Windows, job done in 35 minutes.
I agreed with the overall method, but it's going to take a lot longer than 35 minutes, except if you are only considering a base install from a windows CD, ie with no updates, no apps, no virus checker, etc etc. Or I suppose an image of a previously good version may be this quick.

So I think you need to think hard about this method before doing it.

Last edited by Miniman; 04 February 2009 at 09:53 AM.
Old 04 February 2009, 12:14 PM
  #14  
GC8WRX
Scooby Regular
 
GC8WRX's Avatar
 
Join Date: Oct 2007
Location: Wanting the English to come first in England for a change!
Posts: 2,091
Likes: 0
Received 0 Likes on 0 Posts
Default

Its not that nasty virus that sits in the Master Boot Record, below wondows if you like, and cant be got at, the only way to kill it is a re install of windows.

WTF is bill gates thinking, i cant think of one program that needs access to the MBR, it should be inaccessible!
Old 04 February 2009, 01:19 PM
  #15  
WRX_Dazza
Scooby Regular
 
WRX_Dazza's Avatar
 
Join Date: Feb 2006
Location: Going further than the station and back !!! ZZZZZZZZZzzzzzzzzzzzz
Posts: 11,097
Likes: 0
Received 0 Likes on 0 Posts
Default

i had one of these the other day on a home pc.

ended up dropping the drive aout and sticking in another with fresh xp pro.
spent about 2 hours beforehand trying everything.

also, as another PITA, the profiles "my documents" were 'empty'

that will teach them!!

[off to backup my own pc again!!!]
Old 04 February 2009, 04:19 PM
  #16  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Sonic'
Daft question but how does an edited hosts file affect programs from running, or your PC from booting up ?
I over quoted his post.
Old 05 February 2009, 11:47 AM
  #17  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

update:

So there I was plugging the affected drive into the laptop via my SATA/IDE>USB adapter, and it didn't respond! No drive letter showed up! BUGGER!

In the end I put the disk back in the PC, got a hold of the Dell WindowsXP disk and did a repair to refresh the corrupted files. Afterwards this left the pc in good enough condition to get all the latest a/v and a/spy apps to check through it and remove the reamining damage.

Anyone recommend a good SATA/IDE > USB kit ?I use the one from Maplin.
Old 05 February 2009, 12:19 PM
  #18  
Iain Young
Scooby Regular
 
Iain Young's Avatar
 
Join Date: Sep 1999
Location: Swindon, Wiltshire Xbox Gamertag: Gutgouger
Posts: 6,956
Likes: 0
Received 0 Likes on 0 Posts
Default

I've got one of these, and it's saved my bacon a few times

USB 2.0 IDE & SATA Cable Kit USBNow.co.uk
Old 05 February 2009, 12:24 PM
  #19  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Iain Young
I've got one of these, and it's saved my bacon a few times

USB 2.0 IDE & SATA Cable Kit USBNow.co.uk
Will check it out. I've always thought my maplin one was a bit flimsy. Knew it would let me down one day.
Old 05 February 2009, 02:55 PM
  #20  
unfeasablylargegonads
Scooby Regular
iTrader: (3)
 
unfeasablylargegonads's Avatar
 
Join Date: Aug 2004
Location: Cambs
Posts: 701
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by GC8WRX
Its not that nasty virus that sits in the Master Boot Record, below wondows if you like, and cant be got at, the only way to kill it is a re install of windows.

WTF is bill gates thinking, i cant think of one program that needs access to the MBR, it should be inaccessible!
LOL you think thats bad, Latest security research shows signs of virus/malware being developed that flashes itself into EPROMs on things like graphics cards, so you could clean/change your drive all you want to no effect
Old 05 February 2009, 03:09 PM
  #21  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by unfeasablylargegonads
Latest security research shows signs of virus/malware being developed that flashes itself into EPROMs on things like graphics cards..
Yeah I read about this, its the next generation of spyware/adware, which they have called ghostware.
Old 05 February 2009, 03:10 PM
  #22  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Microsoft research paper which explains it, I think, its an old bookmark..

http://research.microsoft.com/pubs/70147/tr-2005-25.pdf
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
SilverM3
ScoobyNet General
8
24 February 2021 01:03 PM
fatboy_coach
General Technical
15
18 June 2016 03:48 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
WrxSti03
Drivetrain
0
30 September 2015 10:24 PM
JackClark
Computer & Technology Related
3
30 September 2015 08:29 PM



Quick Reply: never seen an virus stop me fixing it before...until today



All times are GMT +1. The time now is 11:14 PM.