Page 1 of 1

Virus Problem: Won't leave me alone!

Posted: Thu Apr 05, 2007 6:59 pm
by STARWARSFREAK
Yesterday I noticed that my computer was lagging very heavily. I thought the network was screwed so I ignored it. But today, the slowness abruptly stopped, and seconds later, I got a stream of unblockable pop-ups! Hold on a second No, I don't want to know the date of my death, or see Briteny Spears naked! Blecch. Also, just now I got seven more pop ups while typing. Anyways, I did a scan and was able to find the corrupted files, I had SEVENTEEN ADWARES AND FOURTEEN TROJAN VIRUSES!! I was able to delete the trojans, which were randomly opening programs on my computer, but two of the adwares are very stubborn, and I could not delete them, and now the pop ups won't stop! Plz help, as this keeps interrupting me, even when I'm offline! I already asked my parents, but they couldn't see the problem because "they had no problems with their computer." Uggh. So plz assist on how to get rid of these things, they're ruining my nerdy life!

RE: Virus Problem: Won

Posted: Thu Apr 05, 2007 7:23 pm
by -_-
Spybot search and destroy. If that doesnt work, delete the files manually.

RE: Virus Problem: Won

Posted: Thu Apr 05, 2007 7:29 pm
by Darth_Z13
Take a look at the topic I made here. There's lots of suggestions.

RE: Virus Problem: Won

Posted: Thu Apr 05, 2007 9:02 pm
by guru
zone alarm rocks, spybots rocker too. I like suntans.

RE: Virus Problem: Won

Posted: Thu Apr 05, 2007 9:48 pm
by JabbaLovesLava
I wonder what websites you've been to :roll:

RE: Virus Problem: Won

Posted: Thu Apr 05, 2007 10:25 pm
by Fusion
Filefront without a pop-up blocker has been known to be a killer :P

RE: Virus Problem: Won

Posted: Fri Apr 06, 2007 1:33 am
by [RDH]Zerted
Stop watching porn, just make you own.

To delete those files, you could download a program to do it or:

Change the file to Archived
Change the file to Read-Only
Terminate its process if running.
If it starts again, rename the exe file.
Try deleteing it again.
If its still not working open up its security permissions, take ownership, deny everyone/everything else.
Now try to delete it again.

Posted: Fri Apr 06, 2007 8:15 am
by MasterYoda91
Prehaps reverting to a system restore point get rid of viruses, adwares ect.?

Posted: Fri Apr 06, 2007 10:57 am
by STARWARSFREAK
The only websites I've been to are here, Youtube, UGOplayer and Newgrounds to watch Star Wars Parodies, and halomaps.org. Oh, yes, I have been to Filefront, but I had my pop-up blockers running. I'll try your suggestions, hopefully it works. With one adware, it's a nightmare, but with two like I have, it's Nightmare on... is it Elm Street? I forget.

EDIT: Oh wait, I have been to one other site. TRECA Digital Academy. It's technically a form of homeschooling but on the computer. It's also, weirdly enough, where all the problems started. Once, again, hold on... For the last time, I don't want a privacy protector! WHY DOES EVERYONE THINK I WATCH PORN??!!! I'M FLIPPIN' THIRTEEN!

Posted: Fri Apr 06, 2007 11:26 am
by cloneknight
go into safemode and try to fix it from there.
oh ya Newgrounds has ben known to have viruses. even if you dont go to bad places

Posted: Sat Apr 07, 2007 7:45 pm
by Hebes24
Definitely get Spybot Search and destroy. It's like the Chuck Norris of Spyware/adware protectors! :P

Posted: Fri Apr 13, 2007 11:24 am
by STARWARSFREAK
Sorry I haven't been on in a while. Between schoolwork, Gears of War, and fighting this stupid virus, it's been a nightmare. I've tried a few of your suggestions, but nothing's working. Apparently, two of the trojan's are working together to get around my security. It seems my only option left is to upgrade to Vista. My parents have it, and they haven't ever gotten a virus. I guess it's time to smash my piggy-bank. :lol:

Posted: Fri Apr 13, 2007 11:40 am
by Moving_Target
Just make sure you do a clean sweep install or Vista will put all your old files into a folder called Windows.old. And it's ok to delete it. It's pain if you have over 30gb of crap in it

Posted: Fri Apr 13, 2007 1:54 pm
by guru
what are the trojan names? did you run norton on them ? results? spybot readouts? If those didnt work and you know the trojan name , let me know, there are tons of ways to remove them and their proccesses and move past all this. If this last bit doesnt help I wouldnt slap another OS on the same harddrive, thats bad news. Reformat and start anew. But yea if you know trojan names or info please give more details. hate to see you stuck on something is ghey as 2 trojans.

Posted: Fri Apr 13, 2007 8:41 pm
by [RDH]Zerted
You need to set those two files to read-only and archived, then change all their security permissions to deny (including for the System user). Undeny and allow write access for your account only. Now rename the files and they will no longer auto-run when their task is terminated. When they are not running, you can delete them.

If you don't want to do that, download and burn a Linux live disk (make sure it has NTFS support). Boot up into that and delete the files.

Installing Vista will not make your security/virus problems go away. All you need is a good firewall, anti-virus program, sandbox for your browser (any browser is fine if sandboxed), and a brain. (or use a Linux baised OS).

Posted: Sun Apr 15, 2007 8:12 pm
by STARWARSFREAK
Well, guys, I finally fixed the problem. Get this: I HAD 109 VIRUSES ON MY COMPUTER!! 0_o...

Anyways, Norton got totally overrun and it started hijacking my computer to spread the virus, so... I had to wipe my computer. *sniff* I think I'm gonna cry. :cry: My problem's solved... I guess. So this thread can be locked now.

And finally, a moment of silence, for my computer. Does anyone know "Taps"?

Posted: Sun Apr 15, 2007 9:31 pm
by [RDH]Zerted
I do, used to play it in Boy Scouts.

For your 'new' computer, I would recommend installing Sandboxie. Its free (but will nag you once a month). You run a program through Sandboxie, like IE, and it captures all the file access. It redirects all the writes to a shadow copy of the file. When you close the program (or really anytime) you can approve those file writes and they will be written to the real files. If not, any attempted file changes will be lost. Meaning if a virus attempts to install itself, Sandboxie will catch all the files it tries to create and lets you decide to keep or delete them. Its not a replacement for a firewall or anti-virus, but it works great and is useful for a few other things too.

http://www.sandboxie.com/

Posted: Mon Apr 16, 2007 1:10 am
by t551
Does it cause much of a performance hit, and can you disable the transient storage for certain programs? I do a lot of stuff where I can't wait to close and approve file changes (e.g. compiling/debugging code, models, textures).

Posted: Mon Apr 16, 2007 1:29 am
by [RDH]Zerted
It only runs on the programs/processes you tell it to. I've only had it running on Maxthon (like IE) and when I've run some questionable programs. I didn't notice any slowdowns, but I wasn't doing any heavy file I/O. When installed, it only takes up 3MB. It is a very lightweight program.