Overclock.net › Forums › Software, Programming and Coding › Networking & Security › HELP ME!! Virus! PLEASE!
New Posts  All Forums:Forum Nav:

HELP ME!! Virus! PLEASE!

post #1 of 17
Thread Starter 
alright somehow a damn virus just got on my pc while surfing ebay and now it's flashing the "critical system error" direct x image in my taskbar and when i click it some bogus software site comes up tryin to get me to buy it.

i have run adaware and mcafee virus scan is going now but ill wait n see what it picks up...but how can i get this **** off?!?!

i know that it's running processes in my task manager but they dont end when i click on them to end, how can i get right of this?!?!?! PLEASE HELP!!
Sandy Beach
(14 items)
 
  
CPUMotherboardGraphicsRAM
2500K @ 4.5GHz/1.32v P8P67-PRO [BIOS 1704] MSI GTX780 TFIV G.Skill 4x4GB DDR3-1600 (8-8-8-24-1T) 
Hard DriveCoolingOSMonitor
512GB 850EVO, WD Black 1TB & ES.2 1TB & Cuda 3TB XSPC Rasa w/ RS240 Windows 7 Ultimate x64 Dell SX2210 
KeyboardPowerCaseMouse
Filco Ninja w/ Browns SilverStone Strider Plus 750W [Sleeved] Custom Stacker 832 Logitech G500 
Mouse Pad
Steelseries 4HD 
  hide details  
Reply
Sandy Beach
(14 items)
 
  
CPUMotherboardGraphicsRAM
2500K @ 4.5GHz/1.32v P8P67-PRO [BIOS 1704] MSI GTX780 TFIV G.Skill 4x4GB DDR3-1600 (8-8-8-24-1T) 
Hard DriveCoolingOSMonitor
512GB 850EVO, WD Black 1TB & ES.2 1TB & Cuda 3TB XSPC Rasa w/ RS240 Windows 7 Ultimate x64 Dell SX2210 
KeyboardPowerCaseMouse
Filco Ninja w/ Browns SilverStone Strider Plus 750W [Sleeved] Custom Stacker 832 Logitech G500 
Mouse Pad
Steelseries 4HD 
  hide details  
Reply
post #2 of 17
I'd recommend going to this website to follow that procedure. I had a nasty virus and got help within a day or two and now I'm clean.

Also, download the program HiJackTHis and post a log up here. (Be sure to do it in Safemode.)
MSI Wind
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Atom 1.6Ghz Intel® 945GSE+ICH7M UMA 1GB DDR2-667 
Hard DriveOptical DriveMonitorCase
80GB N/A 10" 1024x600 MSI Wind 
  hide details  
Reply
MSI Wind
(13 items)
 
  
CPUMotherboardGraphicsRAM
Intel Atom 1.6Ghz Intel® 945GSE+ICH7M UMA 1GB DDR2-667 
Hard DriveOptical DriveMonitorCase
80GB N/A 10" 1024x600 MSI Wind 
  hide details  
Reply
post #3 of 17
You could try CCleaner... or you could just do a search for the files yourself, modify the msconfig, and delete them yourself...but I'd recommend the first

Shaggyt
Shag's stuff...
(13 items)
 
  
CPUMotherboardGraphicsRAM
Athlon64 +3200 Clawhammer Asus A8N-SLI Evga7950GT KO SC 665/1650 Ultra 1024 PC3200 DDR400 
Hard DriveOptical DriveOSMonitor
160g:XP 80g:XP Sony Duallayer DVD+RW and Sony DVD Rom Windows XP SP2 x 2 Dell E177a 1280x1024 60hz 
KeyboardPowerCaseMouse
Logitech MX3000 Cordless Ultra X-Finity 500w Ultra Black Mid-Tower Logitech Cordless Laser 
  hide details  
Reply
Shag's stuff...
(13 items)
 
  
CPUMotherboardGraphicsRAM
Athlon64 +3200 Clawhammer Asus A8N-SLI Evga7950GT KO SC 665/1650 Ultra 1024 PC3200 DDR400 
Hard DriveOptical DriveOSMonitor
160g:XP 80g:XP Sony Duallayer DVD+RW and Sony DVD Rom Windows XP SP2 x 2 Dell E177a 1280x1024 60hz 
KeyboardPowerCaseMouse
Logitech MX3000 Cordless Ultra X-Finity 500w Ultra Black Mid-Tower Logitech Cordless Laser 
  hide details  
Reply
post #4 of 17
Hi, Sorry to hear that..If the others dont work try this, it's a free on line service....Good Luck...Trend Microâ„¢ HouseCall
My System
(13 items)
 
  
CPUMotherboardGraphicsRAM
E8600 4545Mhz*9 w/1.29V DFI DK P45 XFX 8800 GS D9GKX & D9GMH 
Hard DriveOptical DriveOSPower
2x Seagate 160 Perp. RD-1 2x Asus Vista Premium Corsair HX 620 
Case
Open Bench 
  hide details  
Reply
My System
(13 items)
 
  
CPUMotherboardGraphicsRAM
E8600 4545Mhz*9 w/1.29V DFI DK P45 XFX 8800 GS D9GKX & D9GMH 
Hard DriveOptical DriveOSPower
2x Seagate 160 Perp. RD-1 2x Asus Vista Premium Corsair HX 620 
Case
Open Bench 
  hide details  
Reply
post #5 of 17
I've used housecall also.. use the java console much quicker
Shag's stuff...
(13 items)
 
  
CPUMotherboardGraphicsRAM
Athlon64 +3200 Clawhammer Asus A8N-SLI Evga7950GT KO SC 665/1650 Ultra 1024 PC3200 DDR400 
Hard DriveOptical DriveOSMonitor
160g:XP 80g:XP Sony Duallayer DVD+RW and Sony DVD Rom Windows XP SP2 x 2 Dell E177a 1280x1024 60hz 
KeyboardPowerCaseMouse
Logitech MX3000 Cordless Ultra X-Finity 500w Ultra Black Mid-Tower Logitech Cordless Laser 
  hide details  
Reply
Shag's stuff...
(13 items)
 
  
CPUMotherboardGraphicsRAM
Athlon64 +3200 Clawhammer Asus A8N-SLI Evga7950GT KO SC 665/1650 Ultra 1024 PC3200 DDR400 
Hard DriveOptical DriveOSMonitor
160g:XP 80g:XP Sony Duallayer DVD+RW and Sony DVD Rom Windows XP SP2 x 2 Dell E177a 1280x1024 60hz 
KeyboardPowerCaseMouse
Logitech MX3000 Cordless Ultra X-Finity 500w Ultra Black Mid-Tower Logitech Cordless Laser 
  hide details  
Reply
post #6 of 17
Spybot and adware should remove it...unless its actually a virus.
Run a deep scan for viruses..

Try removing it manually by checking your Program Files.. (I've had to do this a couple times..)

I've had some wierd stuff popup in my "msconfig" (like spyware) see if its in there.. and uncheck it..
RUN -> msconfig

And..if you arnt using firefox as your browser..
www.mozilla.com

Heh..
The Leviathan
(20 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7 6700k @ 4.7GHz MSI Z170A Gaming M7 12GB NVIDIA Titan X (Pascal) 32GB G.Skill Ripjaws V (DDR4 3200) 
Hard DriveHard DriveCoolingCooling
2x 1TB Samsung 960 PRO 193TB unRAID Server 3x 140mm Noctua NF-A14 Noctua NH-D15 
OSMonitorKeyboardPower
Windows 10 Pro x64 65" LG 65E6P (4K OLED) Ducky DK9008 Shine 3  Corsair AX860 
CaseMouseAudioAudio
Corsair Obsidian 750D Logitech G502 Proteus Sprectrum Denon X7200WA (Receiver) 2x Klipsch RF-7 (Front Speakers) 
AudioAudioAudioAudio
4x Klipsch RS-62 (Surround Speakers) Klipsch RC-64 (Center Speaker) 4x Klipsch CDT-5800-C II (Atmos Speakers) 2x SVS PB16-Ultra (Subwoofers) 
  hide details  
Reply
The Leviathan
(20 items)
 
  
CPUMotherboardGraphicsRAM
Intel i7 6700k @ 4.7GHz MSI Z170A Gaming M7 12GB NVIDIA Titan X (Pascal) 32GB G.Skill Ripjaws V (DDR4 3200) 
Hard DriveHard DriveCoolingCooling
2x 1TB Samsung 960 PRO 193TB unRAID Server 3x 140mm Noctua NF-A14 Noctua NH-D15 
OSMonitorKeyboardPower
Windows 10 Pro x64 65" LG 65E6P (4K OLED) Ducky DK9008 Shine 3  Corsair AX860 
CaseMouseAudioAudio
Corsair Obsidian 750D Logitech G502 Proteus Sprectrum Denon X7200WA (Receiver) 2x Klipsch RF-7 (Front Speakers) 
AudioAudioAudioAudio
4x Klipsch RS-62 (Surround Speakers) Klipsch RC-64 (Center Speaker) 4x Klipsch CDT-5800-C II (Atmos Speakers) 2x SVS PB16-Ultra (Subwoofers) 
  hide details  
Reply
post #7 of 17
Here's a shot of ccleaner... does a pretty good job

Attachment 33491
Shag's stuff...
(13 items)
 
  
CPUMotherboardGraphicsRAM
Athlon64 +3200 Clawhammer Asus A8N-SLI Evga7950GT KO SC 665/1650 Ultra 1024 PC3200 DDR400 
Hard DriveOptical DriveOSMonitor
160g:XP 80g:XP Sony Duallayer DVD+RW and Sony DVD Rom Windows XP SP2 x 2 Dell E177a 1280x1024 60hz 
KeyboardPowerCaseMouse
Logitech MX3000 Cordless Ultra X-Finity 500w Ultra Black Mid-Tower Logitech Cordless Laser 
  hide details  
Reply
Shag's stuff...
(13 items)
 
  
CPUMotherboardGraphicsRAM
Athlon64 +3200 Clawhammer Asus A8N-SLI Evga7950GT KO SC 665/1650 Ultra 1024 PC3200 DDR400 
Hard DriveOptical DriveOSMonitor
160g:XP 80g:XP Sony Duallayer DVD+RW and Sony DVD Rom Windows XP SP2 x 2 Dell E177a 1280x1024 60hz 
KeyboardPowerCaseMouse
Logitech MX3000 Cordless Ultra X-Finity 500w Ultra Black Mid-Tower Logitech Cordless Laser 
  hide details  
Reply
post #8 of 17
Quote:
Originally Posted by kidwolf909
somehow a damn virus just got on my pc while surfing ebay
....you sure you didn't have any other *special* tabs in the background?
    
CPUMotherboardGraphicsRAM
i5 4430 MSI H81M-P33 MSI GTX960 2x4GB GSKILL DDR3 1600 
Hard DriveOSPowerMouse
Samsung EVO 850 256GB Win 10 EVGA 500B Zowie EC2-A 
Mouse PadAudioOther
Zowie GSR SHP 9500S + FIO E10K ASUS VG248QE Black 24" 144Hz 1ms  
  hide details  
Reply
    
CPUMotherboardGraphicsRAM
i5 4430 MSI H81M-P33 MSI GTX960 2x4GB GSKILL DDR3 1600 
Hard DriveOSPowerMouse
Samsung EVO 850 256GB Win 10 EVGA 500B Zowie EC2-A 
Mouse PadAudioOther
Zowie GSR SHP 9500S + FIO E10K ASUS VG248QE Black 24" 144Hz 1ms  
  hide details  
Reply
post #9 of 17
Just locate the files that will not end in task manager, once you know where they are just rename them! EX. Loader.exe to Loader.ex_ or whatever, then go into the registry and delete all keys that spawn these programs HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\ CurrentVersion\\Run
Then restart. This should at least disable the virus from being active.

Unfortunatly, they payload has already taken effect by the sounds of it, so I would strongly suggest formatting,

NOTE: if the registry contains no keys associated with these programs try going to START - RUN - and type msconfig
There you can manually adjust your configuration *.INI files.

Hope this helps! but seriously you should format if ANY malicious code is present on your disk.
4Tango
(13 items)
 
  
CPUMotherboardGraphicsRAM
Q6600 GO DFI DK P35 T2RS GTX280 G.SKILL PC2-8000 2X2GB 
Hard DriveOptical DriveOSMonitor
WD5000ABYS 500GB HL-DT-ST BDDVDRW GGC-H20L Vista X64 DELL 2407WFP REV A03 
PowerCase
Silencer 610 CM 690 
  hide details  
Reply
4Tango
(13 items)
 
  
CPUMotherboardGraphicsRAM
Q6600 GO DFI DK P35 T2RS GTX280 G.SKILL PC2-8000 2X2GB 
Hard DriveOptical DriveOSMonitor
WD5000ABYS 500GB HL-DT-ST BDDVDRW GGC-H20L Vista X64 DELL 2407WFP REV A03 
PowerCase
Silencer 610 CM 690 
  hide details  
Reply
post #10 of 17
Thread Starter 
Quote:
Originally Posted by Fatal05
....you sure you didn't have any other *special* tabs in the background?
Hahaha...no, no "special" tabs were open. I got a popup and seconds later mcaffee set off an alert for a trojan downloader and then the "critical system error" started going. Moments later, another little alert started to flash in my taskbar because the virus had downloaded ANOTHER trojan onto my desktop. Ugh...I just spent the past 3 hours cleaning my desktop of EVERYTHING to do with it. I got AVG and that got rid of the trojans themselves, then I had to end the stupid process tree of the downloader to kill it and then sort through my program files/control panel and delete each one (there were like 4 downloaders).

But I'm clean now and I have AVG Anti-Virus on here now since McAffee picked up NOTHING AT ALL!!! I'm extremely disgusted with Mcafee right now. A 45 minute long full system scan returned NOTHING under mcaffee, but two trojans were detected by FREEWARE! Amazing...

Oh well, thank god for AVG! I would be dead right now...let's just hope that nothing else comes down the pipe...
Sandy Beach
(14 items)
 
  
CPUMotherboardGraphicsRAM
2500K @ 4.5GHz/1.32v P8P67-PRO [BIOS 1704] MSI GTX780 TFIV G.Skill 4x4GB DDR3-1600 (8-8-8-24-1T) 
Hard DriveCoolingOSMonitor
512GB 850EVO, WD Black 1TB & ES.2 1TB & Cuda 3TB XSPC Rasa w/ RS240 Windows 7 Ultimate x64 Dell SX2210 
KeyboardPowerCaseMouse
Filco Ninja w/ Browns SilverStone Strider Plus 750W [Sleeved] Custom Stacker 832 Logitech G500 
Mouse Pad
Steelseries 4HD 
  hide details  
Reply
Sandy Beach
(14 items)
 
  
CPUMotherboardGraphicsRAM
2500K @ 4.5GHz/1.32v P8P67-PRO [BIOS 1704] MSI GTX780 TFIV G.Skill 4x4GB DDR3-1600 (8-8-8-24-1T) 
Hard DriveCoolingOSMonitor
512GB 850EVO, WD Black 1TB & ES.2 1TB & Cuda 3TB XSPC Rasa w/ RS240 Windows 7 Ultimate x64 Dell SX2210 
KeyboardPowerCaseMouse
Filco Ninja w/ Browns SilverStone Strider Plus 750W [Sleeved] Custom Stacker 832 Logitech G500 
Mouse Pad
Steelseries 4HD 
  hide details  
Reply
New Posts  All Forums:Forum Nav:
  Return Home
  Back to Forum: Networking & Security
Overclock.net › Forums › Software, Programming and Coding › Networking & Security › HELP ME!! Virus! PLEASE!