Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

I think I have a virus!

Thread Tools
 
Search this Thread
 
Old 16 September 2008, 08:51 AM
  #1  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default I think I have a virus!

This morning my computer seems to have come under attack and it decided to randomly change the desktop background to white with a box displaying a message (see picture). I went to system restore to roll back and, conveniently, it appears all my restore points are gone! This looks like virus activity.

Does anyone know what I'm dealing with here, what it does and how I can get rid of it?

Old 16 September 2008, 09:10 AM
  #2  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

I'd try products like Spybot. The home of Spybot-S&D!
Old 16 September 2008, 09:43 AM
  #3  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

God, this thing is a nightmare. When you do google searches it redirects you from nearly all helpful links to other sites. It simply won't open the link above but my laptop, which I'm using just now, will!
Old 16 September 2008, 09:48 AM
  #4  
myblackwrx
Scooby Regular
iTrader: (1)
 
myblackwrx's Avatar
 
Join Date: Mar 2006
Location: Dorset
Posts: 8,787
Likes: 0
Received 1 Like on 1 Post
Default

Google search the items in your 'alert' and have a look as there seem to be a lot of removal tips and tools out there.

It's scamware trying to force you to buy some crap.
Old 16 September 2008, 09:53 AM
  #5  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

The problem on my computer is when I click the links it re-directs me. I've done the google search from the laptop and I did manage to directly type the link to a piece of software that scanned and found the problem but, shock, horror, they wanted $39 to remove it It was probably the company that provide the software that made the virus/scamware/whatever in the fvcking first place.
Old 16 September 2008, 10:11 AM
  #6  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Download the software on your laptop, then copy the set up files to your PC. You may be able to do the install and repair in Safe Mode, which would help.
Old 16 September 2008, 11:06 AM
  #7  
pimmo2000
Scooby Regular
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default

Originally Posted by Saxo Boy
The problem on my computer is when I click the links it re-directs me. I've done the google search from the laptop and I did manage to directly type the link to a piece of software that scanned and found the problem but, shock, horror, they wanted $39 to remove it It was probably the company that provide the software that made the virus/scamware/whatever in the fvcking first place.
It is.. they have probably changed your DNS settings.

Assumin it XP

control pannel, network connections, right click on the one you use for the internet and click properties..

Yours Looking for IP v4 I cant remember the full title.. double click it and make sure everything DNS is set to auto !

Then install Spybot
Old 16 September 2008, 12:21 PM
  #8  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

Pimmo I've tried going into properties of my internet connection but there is nothing like or relating to IP v4. There is a check next to each of the following:

Client for Microsoft Networks
File and Printer Sharing for Microsoft Networks
QoS Packet Scheduler
Internet Protocol (TCP/IP)

I've been in the properties for each of those and, again, nothing like you describe. It's XP btw.
Old 16 September 2008, 12:49 PM
  #9  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

ARRRRRRRRR!!!!! This is impossible!!! Every time I try to navigate to a website to download a program to kill this thing I get re-directed or told the page is unavailable, which is blatant lies as my laptop can get there no problem!!!!
Old 16 September 2008, 12:59 PM
  #10  
phoenixgold
Scooby Regular
iTrader: (2)
 
phoenixgold's Avatar
 
Join Date: Oct 2007
Posts: 348
Likes: 0
Received 0 Likes on 0 Posts
Default

It's the Internet Protocol (TCP/IP) settings. You need to check that your DNS settings are on automatic.
Old 16 September 2008, 01:04 PM
  #11  
pimmo2000
Scooby Regular
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default

Protocol (TCP/IP) settings sorry

Old 16 September 2008, 01:37 PM
  #12  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

So should I set mines to have all those numbers
Old 16 September 2008, 01:38 PM
  #13  
joey_turbo
Scooby Regular
iTrader: (26)
 
joey_turbo's Avatar
 
Join Date: Apr 2006
Location: Essex
Posts: 6,547
Received 9 Likes on 6 Posts
Default

I had one like this. Has it disabled your Task Manager too?
I used Spyware Doctor, was the only thing that worked in the end.
Old 16 September 2008, 01:39 PM
  #14  
pimmo2000
Scooby Regular
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default

Originally Posted by Saxo Boy
So should I set mines to have all those numbers
No mate, you see where the options to set as automatic .. set as that
Old 16 September 2008, 02:45 PM
  #15  
GC8
Scooby Regular
 
GC8's Avatar
 
Join Date: Aug 2003
Location: Sheffield; Rome of the North
Posts: 17,582
Likes: 0
Received 0 Likes on 0 Posts
Default

Does it only work in IE or does it affect Mozilla/Firefox too?
Old 16 September 2008, 03:36 PM
  #16  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

It's kicking the crap out of them both - I normally use Mozilla fwiw.
Old 16 September 2008, 08:35 PM
  #17  
GC8
Scooby Regular
 
GC8's Avatar
 
Join Date: Aug 2003
Location: Sheffield; Rome of the North
Posts: 17,582
Likes: 0
Received 0 Likes on 0 Posts
Default

Probably easiest to boot from a write protected Win98 (or WinXP if you use NTFS, youll need to download the WinXP bootbisk maker from MS) diskette and manually remove it.
Old 16 September 2008, 08:45 PM
  #18  
MJW
Scooby Senior
 
MJW's Avatar
 
Join Date: Nov 2001
Location: West Yorks.
Posts: 4,130
Likes: 0
Received 0 Likes on 0 Posts
Default

Can you download Spybot on your laptop & copy the installer to the infected machine with a USB flashdrive or something ? If Spybot finds something that it can't remove there & then it will reboot your machine and run itself before any other programs start up
Old 16 September 2008, 09:23 PM
  #19  
GC8
Scooby Regular
 
GC8's Avatar
 
Join Date: Aug 2003
Location: Sheffield; Rome of the North
Posts: 17,582
Likes: 0
Received 0 Likes on 0 Posts
Default

Anti-spyware type applications only tend to work with the lower end malware. Id suggest downloading McAfee's 'Rootkit detective' and see what hidden processes and keys are found. Google them and take it from there (in addition to googling the virus: Im assuming that you AV software detects it but cant remove it?).
Old 16 September 2008, 10:16 PM
  #20  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

Update

I appear to have killed the bugger - took 14 hours!! I found a thread on MajorGeeks forum that gave a step by step guide to kill all malware from your computer and it worked well. I also got rid of Norton and am tooled up with recommended firewall (online armor) and AV (AGV). Fingers crossed

Thanks for input in this thread.
Old 16 September 2008, 10:22 PM
  #21  
Aztec Performance Ltd
Former Sponsor
iTrader: (234)
 
Aztec Performance Ltd's Avatar
 
Join Date: Jan 2003
Location: Over 500ft/lbs of torque @ just 1.1bar
Posts: 14,406
Likes: 0
Received 0 Likes on 0 Posts
Default

Glad you got it in the end.

Just stay off those dodgey websites

Vista is streets ahead of XP IMHO.
Old 16 September 2008, 10:54 PM
  #22  
pimmo2000
Scooby Regular
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default

For a change I'll say it before Ian does... AVG is poo ..
Old 16 September 2008, 10:58 PM
  #23  
MJW
Scooby Senior
 
MJW's Avatar
 
Join Date: Nov 2001
Location: West Yorks.
Posts: 4,130
Likes: 0
Received 0 Likes on 0 Posts
Default

No virus thread would be complete without at least 5 posts from people who claim your PC will explode if you don't un-install AVG and install NOD32 instead.
Old 16 September 2008, 11:01 PM
  #24  
Aztec Performance Ltd
Former Sponsor
iTrader: (234)
 
Aztec Performance Ltd's Avatar
 
Join Date: Jan 2003
Location: Over 500ft/lbs of torque @ just 1.1bar
Posts: 14,406
Likes: 0
Received 0 Likes on 0 Posts
Default

I hate virus checkers.
Old 16 September 2008, 11:11 PM
  #25  
GC8
Scooby Regular
 
GC8's Avatar
 
Join Date: Aug 2003
Location: Sheffield; Rome of the North
Posts: 17,582
Likes: 0
Received 0 Likes on 0 Posts
Default

Far more computer engineers use Eset than AVG.....
Old 16 September 2008, 11:19 PM
  #26  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

Ok so what do I want to replace AGV with (direct link please so I defo get legit software). It must be free btw
Old 16 September 2008, 11:19 PM
  #27  
pimmo2000
Scooby Regular
iTrader: (6)
 
pimmo2000's Avatar
 
Join Date: Sep 2004
Location: On a small Island near France
Posts: 14,660
Received 4 Likes on 4 Posts
Default

Originally Posted by GC8
Far more computer engineers use Eset than AVG.....
What is a computer engineer ???

Surely billy IT support sees more Viruses that an "engineer" ??
Old 17 September 2008, 03:46 AM
  #28  
kbsub
Scooby Regular
 
kbsub's Avatar
 
Join Date: Oct 2004
Location: Kamloops British Columbia Canada
Posts: 1,863
Likes: 0
Received 0 Likes on 0 Posts
Default

Antivirus and Antispyware Software - Download ESET NOD32 Antivirus or ESET Smart Security and eliminate viruses

Its not free but do want to spend another 14 hours ....

Why does it have to be free ?
Old 17 September 2008, 07:35 AM
  #29  
JackClark
Scooby Senior
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

Originally Posted by pimmo2000
What is a computer engineer ???

Surely billy IT support sees more Viruses that an "engineer" ??
An engineer creates. Billy IT support might see a lot of virus alerts but has probably never seen a virus.
Old 17 September 2008, 08:03 AM
  #30  
LG John
Scooby Regular
Thread Starter
 
LG John's Avatar
 
Join Date: Mar 2002
Location: Bradford
Posts: 13,720
Likes: 0
Received 0 Likes on 0 Posts
Default

Why does it have to be free?
Why pay for something when, it seems, there are free versions that work just as effectively


Quick Reply: I think I have a virus!



All times are GMT +1. The time now is 12:20 PM.