Help...please...

If the Ivory Tower is the brain of the board, and the Transformers discussion is its heart, then General Discussions is the waste disposal pipe. Or kidney. Or something suitably pulpy and soft, like 4 week old bananas.

Moderators:Best First, spiderfrommars, IronHide

Post Reply
User avatar
Metal Vendetta
Big Honking Planet Eater
Posts:4950
Joined:Mon Feb 12, 2001 12:00 am
Location:Lahndan, innit
Help...please...

Post by Metal Vendetta » Tue Apr 04, 2006 10:40 am

I've been a bit of a naughty boy. I was looking at some...artistic...sites yesterday and crikey if my computer didn't up and freeze on me.

Now I can't get it to go back on the internet. McAfee VirusScan keeps finding odd "run.exe" files in my Temp directory and although I can establish a connection with the cable modem and obtain an IP address, I can't connect to any websites. Fortunately there doesn't seem to be anything (else) malicious being downloaded to my leper machine as I've been watching the traffic on NetLimiter but obviously I need to sort it out fast. I can download stuff on my laptop and transfer it over via my mp3 player, but if anyone knows of some killer bit of software that will purge the system of anything nasty, I'd appreciate it :)
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010

User avatar
Legion
Over Pompous Autobot Commander
Posts:2739
Joined:Mon Jan 15, 2001 12:00 am
Location:The road to nowhere

Post by Legion » Tue Apr 04, 2006 10:47 am

spybot's normally a good port of call for cleaning up computers!

http://www.safer-networking.org/en/inde ... brary/run/

that Wintasks Library site is one i always use for reference! :)

hope that's of some help!


[edit] thinking about it, this problem of run.exe is a virus problem, so sybot might not be able to clean it. your virus scanner should be able to tho, worrying that it's not! i'll have a nose around and see what else i can find out[/edit]

User avatar
Brendocon
Big Honking Planet Eater
Posts:5299
Joined:Tue Sep 19, 2000 11:00 pm
Location:UK

Post by Brendocon » Tue Apr 04, 2006 10:50 am

You need to find Grace Park and plug your computer into her arm.

Then send her to me so I can plug something else into her.

:oops:
Grrr. Argh.

User avatar
Legion
Over Pompous Autobot Commander
Posts:2739
Joined:Mon Jan 15, 2001 12:00 am
Location:The road to nowhere

Post by Legion » Tue Apr 04, 2006 10:54 am

Brendocon wrote:Then send her to me so I can plug something else into her.
:oops:
:no: ;)


MV: If your virus scanner is having troubles removing the little bugger, try doing a scan (with mcafee and/or spybot) from safe mode - might have better results.

User avatar
Metal Vendetta
Big Honking Planet Eater
Posts:4950
Joined:Mon Feb 12, 2001 12:00 am
Location:Lahndan, innit

Post by Metal Vendetta » Tue Apr 04, 2006 11:01 am

Thanks guys, some good advice there. I'm trying to make contact with my old company to see if someone will slip me a CD of the latest anti-virus software as mine isn't the latest (although the auto-updated definitions should be) though I suspect it's only going to get worse...

www.robleesejones.com (probably not advisable to click that, actually) is also down and that's on the machine next door. I may have lost the network... :(

[edit] except for the bloody Mac, obviously :x
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010

User avatar
Kaylee
Big Honking Planet Eater
Posts:4071
Joined:Thu Oct 26, 2000 12:00 am
::More venomous than I appear
Location:Ashford, Kent, UK.
Contact:

Post by Kaylee » Tue Apr 04, 2006 11:11 am

The first thing the virus/trojan did was probably to nuke your antivirus software.

Download Avast (www.avast.com) using another computer onto a USB drive or somesuch (or your favourite antivirus program).

Restart XP in safe mode and use Task Manager to kill all instances of run.exe (I'm assuming through literate on the trojan that it runs through registry entries, not through rundll. Viruses which respawn through rundll are an utter bitch to remove) if any.

Try using your current Antivirus to scan and locate the virus, if that fails install Avast (or whatever), reboot again into safe mode and run a scan. Since it should come with very recentivirus definition files, Avast should locate the files (there are probably several), registry entries and so on.

Let me know if that fixes it (depends on how subtle the virus is and how far it has dug itself in).

To avoid such things in the future-

Create a separate normal user account for day to day use and an administrator account for installing/altering the system. It's inconvenient but you won't get this problem any more. Also make sure you have a good uptodate antivirus and firewall (zonealarm is pretty good for a freebie). Finally, go through Internet Explorer or Firefox and disable Java, most of Javascript and ActiveX controls. Firefox is better for this because you can change them on the fly without having to relog as Administrator.

If you're feeling brave you can also try the Windows Defender Beta 2 from Microsoft- www.microsoft.com/defender. It's not perfect but it's another level of protection to keep you safe. Also make sure to scan regularly with Adaware (www.lavasoft.com) and Spybot, but if you run as a standard user most of the major nasties won't be a problem any more.

Due to Windows file permissions system being broken, however, it is inconvenient to do so. That is set to improve however with Vista (hopefully...).

User avatar
Brendocon
Big Honking Planet Eater
Posts:5299
Joined:Tue Sep 19, 2000 11:00 pm
Location:UK

Post by Brendocon » Tue Apr 04, 2006 11:17 am

Metal Vendetta wrote:Thanks guys, some good advice there.
Letting me plug Grace Park? Always sound advice!

Seriously, though - it's only because I have nothing else to contribute. :(

My approach would be Spybot S&D, then AdAware, then an AV scan. All the while soundtracked by a panic attack and hyperventilation. :oops:
Grrr. Argh.

User avatar
Metal Vendetta
Big Honking Planet Eater
Posts:4950
Joined:Mon Feb 12, 2001 12:00 am
Location:Lahndan, innit

Post by Metal Vendetta » Tue Apr 04, 2006 11:21 am

Brendocon wrote:My approach would be Spybot S&D, then AdAware, then an AV scan. All the while soundtracked by a panic attack and hyperventilation. :oops:
I've already run Spybot and AdAware - but they turned up nothing except some cookies that they deemed "harmless", which I deleted just to be on the safe side. VirusScan keeps finding the run.exe file in my Temp folder but by the time I open the folder the run.exe file has already disappeared. Hyperventilation is coming quite naturally - I tried to give up fags yesterday, consequently I've had about 1 hour's sleep, and am now puffing away like a trooper.

Bloody Cylons.

[edit] Thanks for the advice Karl - avast is now on my mp3 player and ready to be installed when I get home.
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010

Guest

Post by Guest » Tue Apr 04, 2006 11:44 am

If it was me, being somewhat technical in these matters (and the fact that I recently had to do this to a machine that wouldn't even admit to having an OS on it!), I'd use the recovery console to replace the current registry with the most recent snapshot prior to the naughtiness. That way, the nasty bit wouldn't be activated with the system and removal would not be hampered.

But that's really not a straight-forward process, as I found out.

User avatar
Kaylee
Big Honking Planet Eater
Posts:4071
Joined:Thu Oct 26, 2000 12:00 am
::More venomous than I appear
Location:Ashford, Kent, UK.
Contact:

Post by Kaylee » Tue Apr 04, 2006 12:37 pm

Rebis wrote:If it was me, being somewhat technical in these matters (and the fact that I recently had to do this to a machine that wouldn't even admit to having an OS on it!), I'd use the recovery console to replace the current registry with the most recent snapshot prior to the naughtiness. That way, the nasty bit wouldn't be activated with the system and removal would not be hampered.

But that's really not a straight-forward process, as I found out.
:up:

Perhaps recovery console might be a simpler option for Rob?

User avatar
Legion
Over Pompous Autobot Commander
Posts:2739
Joined:Mon Jan 15, 2001 12:00 am
Location:The road to nowhere

Post by Legion » Tue Apr 04, 2006 12:39 pm

only if his system has got valid restore points... the last time i tried using that it scuppered my xp install as it had somehow lost all of my system restore points... :(

User avatar
Kaylee
Big Honking Planet Eater
Posts:4071
Joined:Thu Oct 26, 2000 12:00 am
::More venomous than I appear
Location:Ashford, Kent, UK.
Contact:

Post by Kaylee » Tue Apr 04, 2006 12:43 pm

Legion wrote:only if his system has got valid restore points... the last time i tried using that it scuppered my xp install as it had somehow lost all of my system restore points... :(
Rebis means something different, but system restore might also be an option (that's what I meant but I typed recovery console by accident).

User avatar
Legion
Over Pompous Autobot Commander
Posts:2739
Joined:Mon Jan 15, 2001 12:00 am
Location:The road to nowhere

Post by Legion » Tue Apr 04, 2006 12:47 pm

Karl Lynch wrote:
Legion wrote:only if his system has got valid restore points... the last time i tried using that it scuppered my xp install as it had somehow lost all of my system restore points... :(
Rebis means something different, but system restore might also be an option (that's what I meant but I typed recovery console by accident).
d'oh! recovery console... of course, sorry! that's what i get for trying to read, post and eat lunch at the same time as thinking... ;)

User avatar
Metal Vendetta
Big Honking Planet Eater
Posts:4950
Joined:Mon Feb 12, 2001 12:00 am
Location:Lahndan, innit

Post by Metal Vendetta » Tue Apr 04, 2006 2:32 pm

Well I met up with my buddy from the IT support company and he gave me a CD with everything I'd need on...however it transpires the virus has also spread to my router, which means tonight is going to be even more fun than I expected. While I have internet access here at work I'm also Googling "recovery console" :)
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010

User avatar
Kaylee
Big Honking Planet Eater
Posts:4071
Joined:Thu Oct 26, 2000 12:00 am
::More venomous than I appear
Location:Ashford, Kent, UK.
Contact:

Post by Kaylee » Tue Apr 04, 2006 3:49 pm

Microsoft tech support is very good for that, very comprehensive and detailed. I've only used RC for reinstalling damaged bootloaders myself. A boot CD with an antivirus on it sounds like a good way to go :)

User avatar
The Last Autobot
Skull faced assassin
Posts:1057
Joined:Wed Jul 23, 2003 11:00 pm
Location:Peru, South America
Contact:

Post by The Last Autobot » Tue Apr 04, 2006 9:45 pm

Metal Vendetta wrote:Well I met up with my buddy from the IT support company and he gave me a CD with everything I'd need on...however it transpires the virus has also spread to my router, which means tonight is going to be even more fun than I expected. While I have internet access here at work I'm also Googling "recovery console" :)
A couple of months ago when my pc couldnt access the internet because of a damn virus (after my norton crashed). What I did was entering in safe mode and then restoring the system to a week before the incident. And then scanning all the pc to finally get rid of the bastard.

Well all this in like 6 hours of headache.
Image

A dream come true. Transformers Perú is online!!!
Visit:
www.transformersperu.com

And my Transformers blog in: www.transformers-peru-tla.blogspot.com

User avatar
Metal Vendetta
Big Honking Planet Eater
Posts:4950
Joined:Mon Feb 12, 2001 12:00 am
Location:Lahndan, innit

Post by Metal Vendetta » Tue Apr 04, 2006 11:38 pm

Hello from home...

Stoned and kinda drunk but back on mama-flippin online.

Delighted. Thanks fellas.
I would have waited a ******* eternity for this!!!!
Impactor returns 2.0, 28th January 2010

User avatar
Kaylee
Big Honking Planet Eater
Posts:4071
Joined:Thu Oct 26, 2000 12:00 am
::More venomous than I appear
Location:Ashford, Kent, UK.
Contact:

Post by Kaylee » Tue Apr 04, 2006 11:43 pm

huzzah :)

User avatar
Legion
Over Pompous Autobot Commander
Posts:2739
Joined:Mon Jan 15, 2001 12:00 am
Location:The road to nowhere

Post by Legion » Wed Apr 05, 2006 9:01 am

Metal Vendetta wrote:Stoned and kinda drunk
the best way to be when trying to fix a Windows install! ;)
it's a lot less painful! :D

Post Reply