View Full Version : Need help with Virus
captain swoop
2009-Sep-25, 09:35 PM
My AVG can't see it and when I try to run Malwarebytes or Spybot - Search & Destroy they quit as soon as they start to scan and I can't run them agai. I get a message to say I don't have permission to access the resource.
Help me out guys.
Neverfly
2009-Sep-25, 09:36 PM
First things first: Can you identify what it is that has infected you? [ETA: I mean your computer]
Checking the processes in task manager and googling unknowns may help you.
Veeger
2009-Sep-25, 10:32 PM
I know something that will probably kill it as a last resort (if indeed it is malware), but I'll wait to see if Nev can help you, first. Many such beasts are designed to shutdown common virus scanners as soon as they start. Sometimes just renaming the scanner executable does the trick.
Neverfly
2009-Sep-25, 10:37 PM
I know something that will probably kill it as a last resort (if indeed it is malware), but I'll wait to see if Nev can help you, first. Many such beasts are designed to shutdown common virus scanners as soon as they start. Sometimes just renaming the scanner executable does the trick.
Since he has not replied, we can only assume that the Captain has gone down with his computer.
His memory will live on, with every virus scan I do in the future...
Romanus
2009-Sep-25, 10:40 PM
^
What he said.
Other things that might help:
1.) Run task manager or the Windows Registry menu in safe mode, which you can get to by rebooting your computer and pushing F8 repeatedly before the main screen comes up.
2.) Two programs that helped me get rid of a particularly annoying trojan are RunAlyzer and RootAlyzer, both put out by Safer Networking. They're a little tricky to use (since you can crash your system by fudging with the wrong program), but invaluable in finding the more stealthy programs.
I found both of them through the Safer Networking forums, which are full of people who are the best possible to help you with this problem: http://forums.spybot.info/
Veeger
2009-Sep-25, 10:56 PM
Since he has not replied, we can only assume that the Captain has gone down with his computer.
His memory will live on, with every virus scan I do in the future...
:lol:
Well, it is late in Yorkshire.
Rhaedas
2009-Sep-25, 11:34 PM
Although running more than one antivirus program at the same time isn't a good thing normally, different software takes different approaches to detection and attack, so trying something other than what he has normally might weed something out. If he can switch them out at this point...
captain swoop
2009-Sep-26, 09:53 AM
I don't know what virus it is. Some kind of Adware. I have tried ACG, Malwarebytes Ad-Aware, Spybot Search and Destroy.
All of those products quit as soon as they start to scanand then I can't run them, I get an error on permissions, When I look at Security the Application file has lost permissions for Administrator. When I re ad the Admin group it runs ok again but quits wqith the same thing. Even tried renaming the .exe file
Went to Trend Micro site and ran Housecall but it doesn't find anything.
PC still slow and I am getting redirected to ad sites at random.
captain swoop
2009-Sep-26, 10:54 AM
I just ran Hijackthis to try and get a log of the registry but the same thing happened, permissions changed and it quit.
Veeger
2009-Sep-26, 12:46 PM
Try running those things in safe-mode. Reboot the computer, and when it restarts, start pressing the F8 key, until safe-mode is invoked. All unnecessary drivers will be disabled - hopefully then, you should be able to run malwarebytes, hijackthis or similar products. If not, you likely have a root-kit virus.
Rhaedas
2009-Sep-26, 02:36 PM
You might try a virus cleaner program, something that's specifically made to run on an infected PC. http://www.avast.com/eng/avast-virus-cleaner.html is one, but I'm sure other major companies have something like that on their site too. Notice in the description it recommends running as a restricted user, because of similar problems to yours, where the virus uses the user privileges to cancel programs looking for them.
Metricyard
2009-Sep-26, 02:50 PM
You might try a virus cleaner program, something that's specifically made to run on an infected PC. http://www.avast.com/eng/avast-virus-cleaner.html is one, but I'm sure other major companies have something like that on their site too. Notice in the description it recommends running as a restricted user, because of similar problems to yours, where the virus uses the user privileges to cancel programs looking for them.
I'd go with Rhaedas solution. Avast gives you the option to scan your drive on boot up. A very handy feature to have when your system is taken over.
I'm surprised that AVG doesn't have a boot scan option.
Edit to add.
Avast will not allow a boot up scan in XP or Vista 64 bit mode. If I recall correctly, it should do ask you if you want to scan on boot when you first install it.
Neverfly
2009-Sep-26, 04:24 PM
Off the top of my head, that sounds a bit like Vundo.
Using vundobegone, might help- But if you ran hijack this, can you post your scan log?
Also, check out the Geekstogo website and forum.
captain swoop
2009-Sep-26, 06:07 PM
I ran it all in safe mode, I will try avast. and I will try a user without admin privileges
captain swoop
2009-Sep-26, 10:37 PM
Well, I managed to get rid of the virus. Some very sneaky Adware.
Rhaedas
2009-Sep-26, 10:39 PM
Good news. I usually after finding bad malware (on others' PCs, I've never fortunately had mine hit), reboot and rerun checks a few times. Just to make sure. Then a good cleaning and defragging. Glad to see something worked.
Powered by vBulletin® Version 4.2.0 Copyright © 2013 vBulletin Solutions, Inc. All rights reserved.