Help...please...
Moderators:Best First, spiderfrommars, IronHide
- Metal Vendetta
- Big Honking Planet Eater
- Posts:4950
- Joined:Mon Feb 12, 2001 12:00 am
- Location:Lahndan, innit
I've been a bit of a naughty boy. I was looking at some...artistic...sites yesterday and crikey if my computer didn't up and freeze on me.
Now I can't get it to go back on the internet. McAfee VirusScan keeps finding odd "run.exe" files in my Temp directory and although I can establish a connection with the cable modem and obtain an IP address, I can't connect to any websites. Fortunately there doesn't seem to be anything (else) malicious being downloaded to my leper machine as I've been watching the traffic on NetLimiter but obviously I need to sort it out fast. I can download stuff on my laptop and transfer it over via my mp3 player, but if anyone knows of some killer bit of software that will purge the system of anything nasty, I'd appreciate it
Now I can't get it to go back on the internet. McAfee VirusScan keeps finding odd "run.exe" files in my Temp directory and although I can establish a connection with the cable modem and obtain an IP address, I can't connect to any websites. Fortunately there doesn't seem to be anything (else) malicious being downloaded to my leper machine as I've been watching the traffic on NetLimiter but obviously I need to sort it out fast. I can download stuff on my laptop and transfer it over via my mp3 player, but if anyone knows of some killer bit of software that will purge the system of anything nasty, I'd appreciate it
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010
Impactor returns 2.0, 28th January 2010
- Legion
- Over Pompous Autobot Commander
- Posts:2739
- Joined:Mon Jan 15, 2001 12:00 am
- Location:The road to nowhere
spybot's normally a good port of call for cleaning up computers!
http://www.safer-networking.org/en/inde ... brary/run/
that Wintasks Library site is one i always use for reference!
hope that's of some help!
[edit] thinking about it, this problem of run.exe is a virus problem, so sybot might not be able to clean it. your virus scanner should be able to tho, worrying that it's not! i'll have a nose around and see what else i can find out[/edit]
http://www.safer-networking.org/en/inde ... brary/run/
that Wintasks Library site is one i always use for reference!
hope that's of some help!
[edit] thinking about it, this problem of run.exe is a virus problem, so sybot might not be able to clean it. your virus scanner should be able to tho, worrying that it's not! i'll have a nose around and see what else i can find out[/edit]
- Metal Vendetta
- Big Honking Planet Eater
- Posts:4950
- Joined:Mon Feb 12, 2001 12:00 am
- Location:Lahndan, innit
Thanks guys, some good advice there. I'm trying to make contact with my old company to see if someone will slip me a CD of the latest anti-virus software as mine isn't the latest (although the auto-updated definitions should be) though I suspect it's only going to get worse...
www.robleesejones.com (probably not advisable to click that, actually) is also down and that's on the machine next door. I may have lost the network...
[edit] except for the bloody Mac, obviously
www.robleesejones.com (probably not advisable to click that, actually) is also down and that's on the machine next door. I may have lost the network...
[edit] except for the bloody Mac, obviously
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010
Impactor returns 2.0, 28th January 2010
- Kaylee
- Big Honking Planet Eater
- Posts:4071
- Joined:Thu Oct 26, 2000 12:00 am
- ::More venomous than I appear
- Location:Ashford, Kent, UK.
- Contact:
The first thing the virus/trojan did was probably to nuke your antivirus software.
Download Avast (www.avast.com) using another computer onto a USB drive or somesuch (or your favourite antivirus program).
Restart XP in safe mode and use Task Manager to kill all instances of run.exe (I'm assuming through literate on the trojan that it runs through registry entries, not through rundll. Viruses which respawn through rundll are an utter bitch to remove) if any.
Try using your current Antivirus to scan and locate the virus, if that fails install Avast (or whatever), reboot again into safe mode and run a scan. Since it should come with very recentivirus definition files, Avast should locate the files (there are probably several), registry entries and so on.
Let me know if that fixes it (depends on how subtle the virus is and how far it has dug itself in).
To avoid such things in the future-
Create a separate normal user account for day to day use and an administrator account for installing/altering the system. It's inconvenient but you won't get this problem any more. Also make sure you have a good uptodate antivirus and firewall (zonealarm is pretty good for a freebie). Finally, go through Internet Explorer or Firefox and disable Java, most of Javascript and ActiveX controls. Firefox is better for this because you can change them on the fly without having to relog as Administrator.
If you're feeling brave you can also try the Windows Defender Beta 2 from Microsoft- www.microsoft.com/defender. It's not perfect but it's another level of protection to keep you safe. Also make sure to scan regularly with Adaware (www.lavasoft.com) and Spybot, but if you run as a standard user most of the major nasties won't be a problem any more.
Due to Windows file permissions system being broken, however, it is inconvenient to do so. That is set to improve however with Vista (hopefully...).
Download Avast (www.avast.com) using another computer onto a USB drive or somesuch (or your favourite antivirus program).
Restart XP in safe mode and use Task Manager to kill all instances of run.exe (I'm assuming through literate on the trojan that it runs through registry entries, not through rundll. Viruses which respawn through rundll are an utter bitch to remove) if any.
Try using your current Antivirus to scan and locate the virus, if that fails install Avast (or whatever), reboot again into safe mode and run a scan. Since it should come with very recentivirus definition files, Avast should locate the files (there are probably several), registry entries and so on.
Let me know if that fixes it (depends on how subtle the virus is and how far it has dug itself in).
To avoid such things in the future-
Create a separate normal user account for day to day use and an administrator account for installing/altering the system. It's inconvenient but you won't get this problem any more. Also make sure you have a good uptodate antivirus and firewall (zonealarm is pretty good for a freebie). Finally, go through Internet Explorer or Firefox and disable Java, most of Javascript and ActiveX controls. Firefox is better for this because you can change them on the fly without having to relog as Administrator.
If you're feeling brave you can also try the Windows Defender Beta 2 from Microsoft- www.microsoft.com/defender. It's not perfect but it's another level of protection to keep you safe. Also make sure to scan regularly with Adaware (www.lavasoft.com) and Spybot, but if you run as a standard user most of the major nasties won't be a problem any more.
Due to Windows file permissions system being broken, however, it is inconvenient to do so. That is set to improve however with Vista (hopefully...).
Letting me plug Grace Park? Always sound advice!Metal Vendetta wrote:Thanks guys, some good advice there.
Seriously, though - it's only because I have nothing else to contribute.
My approach would be Spybot S&D, then AdAware, then an AV scan. All the while soundtracked by a panic attack and hyperventilation.
Grrr. Argh.
- Metal Vendetta
- Big Honking Planet Eater
- Posts:4950
- Joined:Mon Feb 12, 2001 12:00 am
- Location:Lahndan, innit
I've already run Spybot and AdAware - but they turned up nothing except some cookies that they deemed "harmless", which I deleted just to be on the safe side. VirusScan keeps finding the run.exe file in my Temp folder but by the time I open the folder the run.exe file has already disappeared. Hyperventilation is coming quite naturally - I tried to give up fags yesterday, consequently I've had about 1 hour's sleep, and am now puffing away like a trooper.Brendocon wrote:My approach would be Spybot S&D, then AdAware, then an AV scan. All the while soundtracked by a panic attack and hyperventilation.
Bloody Cylons.
[edit] Thanks for the advice Karl - avast is now on my mp3 player and ready to be installed when I get home.
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010
Impactor returns 2.0, 28th January 2010
If it was me, being somewhat technical in these matters (and the fact that I recently had to do this to a machine that wouldn't even admit to having an OS on it!), I'd use the recovery console to replace the current registry with the most recent snapshot prior to the naughtiness. That way, the nasty bit wouldn't be activated with the system and removal would not be hampered.
But that's really not a straight-forward process, as I found out.
But that's really not a straight-forward process, as I found out.
- Kaylee
- Big Honking Planet Eater
- Posts:4071
- Joined:Thu Oct 26, 2000 12:00 am
- ::More venomous than I appear
- Location:Ashford, Kent, UK.
- Contact:
Rebis wrote:If it was me, being somewhat technical in these matters (and the fact that I recently had to do this to a machine that wouldn't even admit to having an OS on it!), I'd use the recovery console to replace the current registry with the most recent snapshot prior to the naughtiness. That way, the nasty bit wouldn't be activated with the system and removal would not be hampered.
But that's really not a straight-forward process, as I found out.
Perhaps recovery console might be a simpler option for Rob?
- Kaylee
- Big Honking Planet Eater
- Posts:4071
- Joined:Thu Oct 26, 2000 12:00 am
- ::More venomous than I appear
- Location:Ashford, Kent, UK.
- Contact:
Rebis means something different, but system restore might also be an option (that's what I meant but I typed recovery console by accident).Legion wrote:only if his system has got valid restore points... the last time i tried using that it scuppered my xp install as it had somehow lost all of my system restore points...
- Legion
- Over Pompous Autobot Commander
- Posts:2739
- Joined:Mon Jan 15, 2001 12:00 am
- Location:The road to nowhere
d'oh! recovery console... of course, sorry! that's what i get for trying to read, post and eat lunch at the same time as thinking...Karl Lynch wrote:Rebis means something different, but system restore might also be an option (that's what I meant but I typed recovery console by accident).Legion wrote:only if his system has got valid restore points... the last time i tried using that it scuppered my xp install as it had somehow lost all of my system restore points...
- Metal Vendetta
- Big Honking Planet Eater
- Posts:4950
- Joined:Mon Feb 12, 2001 12:00 am
- Location:Lahndan, innit
Well I met up with my buddy from the IT support company and he gave me a CD with everything I'd need on...however it transpires the virus has also spread to my router, which means tonight is going to be even more fun than I expected. While I have internet access here at work I'm also Googling "recovery console"
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010
Impactor returns 2.0, 28th January 2010
- The Last Autobot
- Skull faced assassin
- Posts:1057
- Joined:Wed Jul 23, 2003 11:00 pm
- Location:Peru, South America
- Contact:
A couple of months ago when my pc couldnt access the internet because of a damn virus (after my norton crashed). What I did was entering in safe mode and then restoring the system to a week before the incident. And then scanning all the pc to finally get rid of the bastard.Metal Vendetta wrote:Well I met up with my buddy from the IT support company and he gave me a CD with everything I'd need on...however it transpires the virus has also spread to my router, which means tonight is going to be even more fun than I expected. While I have internet access here at work I'm also Googling "recovery console"
Well all this in like 6 hours of headache.
A dream come true. Transformers Perú is online!!!
Visit:
www.transformersperu.com
And my Transformers blog in: www.transformers-peru-tla.blogspot.com
- Metal Vendetta
- Big Honking Planet Eater
- Posts:4950
- Joined:Mon Feb 12, 2001 12:00 am
- Location:Lahndan, innit