Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Just got my 1st serious Virus and can't get rid!

Thread Tools
 
Search this Thread
 
Old Aug 27, 2008 | 09:11 AM
  #1  
iamevilhomer's Avatar
iamevilhomer
Thread Starter
Scooby Regular
 
Joined: Mar 2005
Posts: 225
Likes: 0
Default Just got my 1st serious Virus and can't get rid!

I have had my laptop for 4 years and just picked up my 1st virus that i have been unable to remove manually.
I keep getting a red x in the task bar with the message"your computer has been infected"
I dont run with any anti-virus software and guess i have been lucky up until now.
I installed Spydoctor and ran the scan, but it then wants me to purchase the full version online.

I tried to install windows defender this morning but it only got so far before it stopped saying that i may not have enough priviliges, even though i am the only admin on the laptop.

I am now thinking of popping to PC world and buying something like norton anti virus.
Would this be capable of removing the virus ?
Reply
Old Aug 27, 2008 | 09:30 AM
  #2  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Default

Sounds like the fake AV doing the rounds, which goes under different names like XP Antivirus 2008.

I've found Malwarebytes does a good job at cleaning up the PCs I've found it on. There's a free version too.
Reply
Old Aug 27, 2008 | 09:30 AM
  #3  
bob269's Avatar
bob269
Scooby Regular
 
Joined: Mar 2003
Posts: 2,654
Likes: 1
Default

Download Nod 32 trial and see how it goes, you may have to purchase it to remove any problems but it's probably one of the best and quickest on the market.

Antivirus Software - from ESET

Viruses are a pita to remove once you're infected so it may be easier to format. Prevention is better than cure
Reply
Old Aug 27, 2008 | 09:51 AM
  #4  
Dracoro's Avatar
Dracoro
Scooby Regular
 
Joined: Sep 2001
Posts: 10,261
Likes: 0
From: A powerslide near you
Default

Originally Posted by iamevilhomer
I dont run with any anti-virus software and guess i have been lucky up until now.
do you leave your car parked with the keys in the ignition all the time too ?

Who knows how many viruses you have that you are unaware of!!!!
Reply
Old Aug 27, 2008 | 10:12 AM
  #5  
The Chief's Avatar
The Chief
Scooby Regular
 
Joined: Oct 2004
Posts: 8,328
Likes: 0
From: There is only one God - Elvis!
Default

I've got this myself, have got rid of the viruses but have an annoying message on my desktop background of 'your computer is infected blah, blah'

Just cant seem to get rid of it.
Reply
Old Aug 27, 2008 | 11:06 AM
  #6  
iamevilhomer's Avatar
iamevilhomer
Thread Starter
Scooby Regular
 
Joined: Mar 2005
Posts: 225
Likes: 0
Default

this is the log file of the scan with malwarebytes-fingers crossed it did the trick, although i then got a message to say that some files windows needed to run properly had been replaced/altered and that i should insert my windows cd-which i cant bloody find!

Malwarebytes' Anti-Malware 1.25
Database version: 1088
Windows 5.1.2600 Service Pack 2

11:07:55 27/08/2008
mbam-log-08-27-2008 (11-07-55).txt

Scan type: Quick Scan
Objects scanned: 75680
Time elapsed: 31 minute(s), 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\buritos (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\karina.dat (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\karina.dat (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winivstr.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.Sys) -> Quarantined and deleted successfully.
C:\WINDOWS\buritos.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Reply
Old Aug 27, 2008 | 10:22 PM
  #7  
jono300's Avatar
jono300
Scooby Regular
iTrader: (8)
 
Joined: Sep 2002
Posts: 4,455
Likes: 0
From: Fife - Scotland
Default

Yep would try superantispware, in my view one off the best for cleaning out this type off thing, may well just be spyware as opposed to an actual virus ??

funny enough have recently started to get this " you may not have enough privellages etc mesage " when trying to open one or two programmes recently strangely enough this was also when trying to run one or two other security related programmes that I had recently d/loaded. even thou I like youself am the only user off the actual pc.
Reply
Old Aug 29, 2008 | 07:32 PM
  #8  
iamevilhomer's Avatar
iamevilhomer
Thread Starter
Scooby Regular
 
Joined: Mar 2005
Posts: 225
Likes: 0
Default

just a quick update, all seems to be ok now so a big thanks to all
Reply
Old Aug 29, 2008 | 08:41 PM
  #9  
jono300's Avatar
jono300
Scooby Regular
iTrader: (8)
 
Joined: Sep 2002
Posts: 4,455
Likes: 0
From: Fife - Scotland
Default

Tell me mate was it this Superantispyware programme which actually got rid off the nsties for you ?? just be interested to know ??

cheers
Reply
Old Aug 29, 2008 | 09:57 PM
  #10  
scoobz72's Avatar
scoobz72
Scooby Regular
 
Joined: Nov 2007
Posts: 754
Likes: 0
From: Webbed Feet Land
Default

Originally Posted by The Chief
I've got this myself, have got rid of the viruses but have an annoying message on my desktop background of 'your computer is infected blah, blah'

Just cant seem to get rid of it.
For this use SMITFRAUDFIX, google it and download. Its superb for removing this.
Reply
Old Aug 30, 2008 | 10:57 AM
  #11  
stiscooby's Avatar
stiscooby
Scooby Regular
 
Joined: Sep 2001
Posts: 1,822
Likes: 0
From: Suffolk
Default

Use the SDFix.exe tool to remove this, can be downloaded from here - Bleeping Computer Downloads: SDFix

You need to run the .exe file in normal mode which extracts the files to a "sdfix" folder on your C:\ drive then reboot to safe mode and run the "runthis" file which is in C:\sdfix. You have to press "y" to start the scan, this can then take a while as scans your PC.

Once complete reboot your PC and let it boot normally.

Once removed you should be able to change your wallpaper as the virus changes your wallpaper showing the "your infected" message and sets a policy which stops you from changing the desktop settings.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Frizzle-Dee
Essex Subaru Owners Club
13
Dec 1, 2015 09:37 AM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
Nov 18, 2015 07:03 AM
south_scoob
ScoobyNet General
22
Oct 3, 2015 01:05 PM
the shreksta
General Technical
27
Oct 2, 2015 03:20 PM




All times are GMT +1. The time now is 09:12 AM.