Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Virus - need some serious help!

Thread Tools
 
Search this Thread
 
Old 07 November 2008, 12:22 AM
  #1  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default Virus - need some serious help!

Went over a mates house tonight and he showed me his desktop PC thats having issues. I think its fair to say it has more than one virus and some other problems.

He doesnt have any av software or any malware software. So i started by trying to download Adaware and Spybot. Both programs couldnt be downloaded giving error message and i suspect the virus has made some changes to the registry to prevent them being downloaded.

I then downloaded Adaware and Spybot on his laptop to a memory stick and tried running them in SAFE MODE. Again, the virus had disabled running of these programs, registry again?

So basically, i need to know where in the registry the changes would have been made so that i can atleast start to get it back to normal.

From my limited knowledge, would the registry changes be as simple as changing a 1 to 0 or vice versa?

Any ideas?
Old 07 November 2008, 01:23 PM
  #2  
HPLovecraft
Scooby Regular
 
HPLovecraft's Avatar
 
Join Date: Jan 2006
Posts: 180
Likes: 0
Received 0 Likes on 0 Posts
Default

Don't know if this would be much help to you but I've used it in the past as an aid to removing spyware and browser hijackers, but you have to know what you're doing so you don't delete legitimate entries:

Trend Micro HijackThis - Free software downloads and reviews - CNET Download.com

theres a tutorial here:

HijackThis Tutorial - How to use HijackThis to remove Browser Hijackers & Spyware
Old 07 November 2008, 01:43 PM
  #3  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks for that, but i think i will have trouble running the program because of possible registry changes made by the virus.

I really need to know where to change permissions in the registry before i even start on getting rid of it.
Old 07 November 2008, 01:59 PM
  #4  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

If the PC really is buggered it may be quicker to do a re-build on it.

Hard to tell how badly it's infected but if its been running without AV and the like (it is behind a router?)

Hijack this as above is good also have a look at this

UBCD for Windows

could run the tools on that and try to improve it but installing AV and the like now is kinda like closing a gate after the horse has bolted if you get my drift

It may be fixable but if it's beyond the point of no return I'd rebuild it from scratch.

Use Nod32 for anti-virus (Avira if you don't want to pay), CCcleaner is also useful and make sure a firewall is present, be it router or software or both.

Then tell him some do and dont's i.e. close popups dont install what they tell you, stay away from virus ridden programs (Kazaa etc)
Old 07 November 2008, 02:00 PM
  #5  
jaytc2003
Scooby Regular
iTrader: (1)
 
jaytc2003's Avatar
 
Join Date: Aug 2005
Location: Manchester ish
Posts: 18,547
Likes: 0
Received 0 Likes on 0 Posts
Default

if he can access the web then go to the mcafee website as they do an online virus checker

alternatively, boot into safemode and log on as the administrator and hopefully it will let you install whatever needs installing.

I would also boot into windows normally and have a look at the processes that are running, and also do msconfig from the start menu then run
Old 07 November 2008, 02:02 PM
  #6  
StratosWRC
Scooby Regular
 
StratosWRC's Avatar
 
Join Date: Oct 2005
Posts: 432
Likes: 0
Received 0 Likes on 0 Posts
Default

Dont know about the registry, but can you use a restore point?
I used \malwarebytes.org recently which found a nasty virus which kaspersky, spybot, adaware missed.
Old 07 November 2008, 06:55 PM
  #7  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Will try the restore points tonight as im going back over there to have another look.

Ive already tried booting in safe mode logged on as admin and still no joy in running any programs, just keep getting declined.

Does anyone have any understanding of which registry keys would have been changed to deny permissions?
Old 07 November 2008, 07:11 PM
  #8  
Kieran_Burns
Scooby Regular
Support Scoobynet!
iTrader: (1)
 
Kieran_Burns's Avatar
 
Join Date: Jul 2004
Location: There on the stair
Posts: 10,208
Likes: 0
Received 0 Likes on 0 Posts
Default

You could try MSCONFIG and turn EVERYTHING off. This will certainly stop any startup malware from running... then try the online scans (such as Mcafee)
Old 07 November 2008, 07:20 PM
  #9  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Will try some online scans 2nite and see how that deals with it. Im not hopeful as i think the registry is fubar'd
Old 07 November 2008, 07:22 PM
  #10  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

Fixing lecturers machines over the years, msconfig may help but some will re-enable themselves and come back on at startup with all options unticked without doing serious diggin into the registry and other system files
Old 07 November 2008, 07:25 PM
  #11  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

What would have changed in the registry to disallow programs to run or even be downloaded? Im sure i just need to change a 1 to a 0 somewhere. But where?
Old 07 November 2008, 07:33 PM
  #12  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

dont get me wrong msconfig is a good idea, but things may re-eanble on boot, you may be able to see which ones by checking msconfig again on re-boot seeing which things are ticked and looking at the reg location of that entry. As above check running processes and google dubious ones, if a nasty program has been installed google for a removal tool. I've used a few over the years which were great. Not sure off the of my head why all progs wouldnt run (gota shoot off for a curry) but sounds like it's boogered from that
Old 07 November 2008, 08:06 PM
  #13  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Does anyone know anything about regedit and the registry?
Old 07 November 2008, 09:21 PM
  #14  
bioforger
Scooby Regular
iTrader: (1)
 
bioforger's Avatar
 
Join Date: Jan 2002
Location: Pig Hill, Wiltsh1te
Posts: 16,995
Received 5 Likes on 5 Posts
Default

Run all your tools in safemode 1st.
Old 08 November 2008, 03:04 AM
  #15  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Boro
Ive already tried booting in safe mode logged on as admin and still no joy in running any programs, just keep getting declined.
Managed to find an old restore point before the point of infection.
Old 08 November 2008, 10:28 AM
  #16  
jaytc2003
Scooby Regular
iTrader: (1)
 
jaytc2003's Avatar
 
Join Date: Aug 2005
Location: Manchester ish
Posts: 18,547
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Boro
Managed to find an old restore point before the point of infection.
the virus and malware will still be there though, so get hold of a virus checker spyware checker and run them by doing full deep system scans and include all archives etc
Old 08 November 2008, 02:20 PM
  #17  
Boro
Scooby Regular
Thread Starter
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks for everyones input. Didnt have time to cleanse the whole system last night but have downloaded a couple of malware checkers and FREE AVG (better than nothing, lol). I will run them in safemode next time i pop over.
Old 09 November 2008, 12:04 AM
  #18  
Simon 69
Scooby Regular
 
Simon 69's Avatar
 
Join Date: Apr 2007
Location: GC8 Enthusiast - Scumball3000 Team 69
Posts: 2,002
Likes: 0
Received 0 Likes on 0 Posts
Default

Malwarebytes will help.
Old 10 November 2008, 09:12 AM
  #19  
jowl
Scooby Regular
 
jowl's Avatar
 
Join Date: Aug 2004
Posts: 1,882
Likes: 0
Received 0 Likes on 0 Posts
Default

Being Brutally honest: Stop pissing around.

If they had no AV or Malware protection then just wipe the whole thing and re-install. It's the only way you can be sure you've removed the virus.

You'll probably want to move the documents to another location. Just make sure you scan them thoroughly when moving them back!
Old 10 November 2008, 10:02 AM
  #20  
Simon 69
Scooby Regular
 
Simon 69's Avatar
 
Join Date: Apr 2007
Location: GC8 Enthusiast - Scumball3000 Team 69
Posts: 2,002
Likes: 0
Received 0 Likes on 0 Posts
Default

FDisk; Format; re-master.
Old 10 November 2008, 11:57 AM
  #21  
Iain Young
Scooby Regular
 
Iain Young's Avatar
 
Join Date: Sep 1999
Location: Swindon, Wiltshire Xbox Gamertag: Gutgouger
Posts: 6,956
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Boro
Does anyone know anything about regedit and the registry?
Yes, and you are very unlikely to be able to fix anything by manually hacking it, especially without a lot of experience. You can easily do a lot more damage than good. I'd recommend formatting and a re-install as well...
Old 12 November 2008, 10:23 PM
  #22  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Just to add, this MSCONFIG talk will never work if its a virus, because ultimately its not a process but a service, a hidden one at that and has been said, once a computer has been compromised by a virus, it is not wise to continue using the same computer without completely reinstalling the operating system.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
south_scoob
ScoobyNet General
22
03 October 2015 01:05 PM
Lillyart14
ScoobyNet General
24
01 October 2015 01:29 AM
Blue by You
Non Scooby Related
48
30 September 2015 01:27 PM
stipete75
Non Scooby Related
37
25 September 2015 02:27 PM
blackknight350
Projects
1
21 September 2015 11:25 PM



Quick Reply: Virus - need some serious help!



All times are GMT +1. The time now is 02:28 PM.