Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Help - Computer Virus

Thread Tools
 
Search this Thread
 
Old 31 March 2009, 10:08 PM
  #1  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default Help - Computer Virus

Started the computer this morning to find a couple of virus on it.
Can someone help me to remove them.

They are called

1. Win32rootkit.TDSS
2. Win32trojanOLMARIK

I currently run The following Programs on my computer but none will remove them.

1. AGV FREE
2. WINDOWS DEFENDER
3. AD-AWARE
4. CCLEANER

I googled the name of the virus's and downloaded a program called SPYWARE DOCTOR, this was of little use as well.

Anyone able to help ???

Kind Regards
Old 31 March 2009, 10:41 PM
  #2  
sti-chris
Scooby Regular
 
sti-chris's Avatar
 
Join Date: Oct 2005
Location: united kingdom
Posts: 606
Received 2 Likes on 2 Posts
Default

avg 8.5 with the latest updates should remove this for you.
have you started your pc in safe mode and ran a full scan ?

press F8 repeatedly while your pc is booting up this will give you the option to boot using safe mode , then run a full scan.

make sure that your avg is up todate.

also spybot is a free adware removal program which i find good.
Old 31 March 2009, 10:53 PM
  #3  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Good advice above. If AVG doesnt cure it, get the trial version of NOD32 from ESET.
Old 01 April 2009, 12:32 AM
  #4  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Well Ive downloaded and run NOD32. It sees it, but wont remove it .....


What can i do ??
Old 01 April 2009, 12:33 AM
  #5  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Have you run it in safe mode?
Old 01 April 2009, 01:09 AM
  #6  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

I have tried to. But It wont allow it for some reason ... I will have another go in the morning. Ive wasted too much time on it for one night.
Old 01 April 2009, 01:40 AM
  #7  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

NOD wont run in safe mode? or you cant get into safe mode at all?
Old 01 April 2009, 09:07 AM
  #8  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Safe mode opens, but NOD32 keeps bringing up the same message

"name="C:\Documnets and Settings\*****\localsettings\applications Data\Microsoft\windows\usrclass.dat.log",threat="" , action="" , info""error opening"

The hard drive is spinning but just keeps bringing this error message up.
Old 01 April 2009, 01:01 PM
  #9  
Boro
Scooby Regular
iTrader: (1)
 
Boro's Avatar
 
Join Date: Jul 2003
Location: Cornwall
Posts: 7,222
Likes: 0
Received 0 Likes on 0 Posts
Default

Where did your download come from? Was it the ESET website?

You could also try this one, its a free online scanner, but you will need to open your computer in SAFE MODE with NETWORKING.

Trend Micro HouseCall - Free Online Virus and Spyware Scan - Trend Micro UK
Old 01 April 2009, 04:14 PM
  #10  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Thanks, I have tried both now and still it wont remove it ...... Little feker!!

Ahh well I was looking at replacing my old computer
Old 01 April 2009, 05:03 PM
  #11  
Ray L
Scooby Newbie
 
Ray L's Avatar
 
Join Date: Jan 2009
Location: Willenhall
Posts: 5
Likes: 0
Received 0 Likes on 0 Posts
Default

Try getting malwarebytes' Anti-malware

that got rid of my dads virus
Old 01 April 2009, 08:43 PM
  #12  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Tried that too .....
Old 01 April 2009, 08:55 PM
  #13  
JMCG
Scooby Regular
iTrader: (1)
 
JMCG's Avatar
 
Join Date: Mar 2009
Location: Belfast
Posts: 97
Likes: 0
Received 0 Likes on 0 Posts
Default

Try all these, looks like you have tried some. Also ensure you have the latest dat updates. Some sneaky wee bastid virus block the updates of known tools, so you may have to go to the vendor site and apply the update manually.

All free:
Spybot - Search & Destroy
Malwarebytes Antimalware
XoftSpySE
SUPERAntiSpyware Free Edition

Also the latest stinger, a standalone tool
Old 02 April 2009, 12:39 AM
  #14  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

They are not a virus, AV software will do nothing/little.

Download HijackThis 2.0.2 - Download - FileHippo.com

post the log file, its all i can do to help you...
Old 02 April 2009, 12:41 AM
  #15  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

SPYWARE DOCTOR... is a rootkit,avoid
Old 02 April 2009, 12:49 AM
  #16  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by JMCG
Malwarebytes Antimalware
XoftSpySE
SUPERAntiSpyware Free Edition
do not use any of these.
Old 02 April 2009, 04:51 PM
  #17  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Dedrater
They are not a virus, AV software will do nothing/little.

Download HijackThis 2.0.2 - Download - FileHippo.com

post the log file, its all i can do to help you...
OK thanks will do


SPYWARE DOCTOR... is a rootkit,avoid
this was the first one I downloaded, but have now deleted.
Old 02 April 2009, 05:01 PM
  #18  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Dedrater
They are not a virus, AV software will do nothing/little.

Download HijackThis 2.0.2 - Download - FileHippo.com

post the log file, its all i can do to help you...
I have downloaded this, but it wont run on my computer, Ive tried it
in safe mode as well, but nothing ??
Old 02 April 2009, 05:42 PM
  #19  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

Do you have another PC? If so then you could have a look at The Ultimate Boot CD for Windows. Configure it, get the AV an Spyware software on it updated (think you may also be able to do this when booted from the disk) then build and boot from the CD and run the AV/Spyware stuff and see if it finds/fixes the issues.
Old 02 April 2009, 05:49 PM
  #20  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by Dedrater
do not use any of these.
Why not?
Old 02 April 2009, 09:09 PM
  #21  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Default

Out of curiosity, try going to this page and see what images load and then view the chart below it. Obviously you'll need to have the machine on the internet to do this.
Old 03 April 2009, 07:41 PM
  #22  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

= Normal/Not Infected by Conficker (or using proxy)
Old 03 April 2009, 10:33 PM
  #23  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

I run NOD32 and it says Ive got 25 virus and deletes 24 of them but always leaves one behind.
I currently scan twice a day and get between 25 and 75 at a time ......
Old 04 April 2009, 04:10 AM
  #24  
Dedrater
Scooby Regular
 
Dedrater's Avatar
 
Join Date: May 2008
Posts: 3,957
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by ChrisB
Why not?
Why?
Old 04 April 2009, 11:14 AM
  #25  
sti-chris
Scooby Regular
 
sti-chris's Avatar
 
Join Date: Oct 2005
Location: united kingdom
Posts: 606
Received 2 Likes on 2 Posts
Default

if its that bad then back up your pics etc to cd and just do a reinstall.

the final straw to the cure.
Old 04 April 2009, 12:01 PM
  #26  
hoochydady
Scooby Regular
 
hoochydady's Avatar
 
Join Date: Feb 2009
Location: glasgow
Posts: 67
Likes: 0
Received 0 Likes on 0 Posts
Default

have u tryd reg edit and had a go at del it from the reg
Old 04 April 2009, 12:24 PM
  #27  
Wish
Scooby Regular
Thread Starter
iTrader: (2)
 
Wish's Avatar
 
Join Date: Apr 2002
Location: Kent
Posts: 3,905
Likes: 0
Received 0 Likes on 0 Posts
Default

Nope ?? I wouldnt know what to do ??
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
Wish
Computer & Technology Related
3
30 September 2015 10:39 PM



Quick Reply: Help - Computer Virus



All times are GMT +1. The time now is 03:02 AM.