Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: BAD virus. can't open hijack this, firefox or any other apps.  (Read 14536 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: BAD virus. can't open hijack this, firefox or any other apps.
« Reply #15 on: August 18, 2009, 05:31:13 PM »
I bought a HDD enclosure and connected the infected HDD to this laptop and my files all appear to be OK. if I transfer all my jpgs to a new hard drive..

1. will those jpgs on the new hard drive be safe?

2. should i then try to fix the existing infected HDD or just reformat and start from scratch?
Those jpg files should be ok. If you have any doubt, copy them to a DVD-RW.
2. You should try again to boot from your Windows CD. You should get a repair option and a re-install option. If you can get the repair done, you should be able to re-boot your computer and run the scans.
Windows 8 and Windows 10 dual boot with two SSD's

Helpmeh



    Guru

  • Roar.
  • Thanked: 123
    • Yes
    • Yes
  • Computer: Specs
  • Experience: Familiar
  • OS: Windows 8
Re: BAD virus. can't open hijack this, firefox or any other apps.
« Reply #16 on: August 18, 2009, 05:39:53 PM »
Take it to a professional? srry no help
Please don't post unless you can help. The members helping out who are "Malware Removal Specialists" ARE professionals.
Where's MagicSpeed?
Quote from: 'matt'
He's playing a game called IRL. Great graphics, *censored* gameplay.

landa321

    Topic Starter


    Beginner

    Re: BAD virus. can't open hijack this, firefox or any other apps.
    « Reply #17 on: August 18, 2009, 10:57:05 PM »
    someone at geekstogo suggested this: You are infected with a polymorphic file infector. This infection can and will infect all the machine's executable files .exe, .scr, .rar, .zip, .htm, .html.

    They suggested that i need a complete reformat and reinstall on ALL of my HDDs and that I should NOT connect my HDD to the laptop or the laptop may become infected as well.
    They added that i would need a Linux live disk to recover my files, but would need to run a scan to make sure those files are clean. This is about 2 TB worth of photos and music and would be devastating to lose. Especially the photos.

    what are your thoughts on this? They made this suggestion based on the same information you have heard here as I have not been able to run any scans to produce any logs.

    as of right now, i have not transferred any files yet. Now that I know those photos are still there, I was going to buy a new HDD to transfer them on to, so that I could reformat the HDD that has the OS on it.

    I do have three internal HDDs in my system and had 2 externals connected at the time of the virus. Is it possible that all the drives are infected?

    Helpmeh



      Guru

    • Roar.
    • Thanked: 123
      • Yes
      • Yes
    • Computer: Specs
    • Experience: Familiar
    • OS: Windows 8
    Re: BAD virus. can't open hijack this, firefox or any other apps.
    « Reply #18 on: August 19, 2009, 05:37:20 AM »
    It is possible that all your drives are infected, but your photos should be safe. Don't do anything else until a Malware Removal Specialist gives you the OK.
    Where's MagicSpeed?
    Quote from: 'matt'
    He's playing a game called IRL. Great graphics, *censored* gameplay.

    landa321

      Topic Starter


      Beginner

      Re: BAD virus. can't open hijack this, firefox or any other apps.
      « Reply #19 on: August 19, 2009, 06:58:04 AM »
      when you say don't do anything else, do you mean AFTER I move my jpg files? is it safe to connect the HDD to a laptop and move the files?

      SuperDave

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: BAD virus. can't open hijack this, firefox or any other apps.
      « Reply #20 on: August 19, 2009, 04:37:46 PM »
      Why not slave your HDD to your laptop and run some scans from your laptop protection on the HDD?
      Windows 8 and Windows 10 dual boot with two SSD's

      landa321

        Topic Starter


        Beginner

        Re: BAD virus. can't open hijack this, firefox or any other apps.
        « Reply #21 on: August 19, 2009, 05:51:51 PM »
        Ok, I can do that! Which scans do you suggest I run?

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: BAD virus. can't open hijack this, firefox or any other apps.
        « Reply #22 on: August 19, 2009, 05:53:19 PM »
        Whatever you have on your computer. If that's not enough, add some more to your laptop and run them.
        Windows 8 and Windows 10 dual boot with two SSD's

        smeezekitty

        • Guest
        Re: BAD virus. can't open hijack this, firefox or any other apps.
        « Reply #23 on: August 19, 2009, 05:54:07 PM »
        2TB?
        how large is that harddriver
        and how can it infect html?

        landa321

          Topic Starter


          Beginner

          Re: BAD virus. can't open hijack this, firefox or any other apps.
          « Reply #24 on: August 19, 2009, 08:55:07 PM »
          Whatever you have on your computer. If that's not enough, add some more to your laptop and run them.
          ok will try that.

          2TB?
          how large is that harddriver
          and how can it infect html?
          well, there were multiple HDDs adding up to a total of about 2TB
          i was told they could infect html files. which isn't good, because i have a couple of websites, so i have some html files

          landa321

            Topic Starter


            Beginner

            Re: BAD virus. can't open hijack this, firefox or any other apps.
            « Reply #25 on: August 26, 2009, 07:39:47 PM »
            I ran a scan with avast on my main HDD. it found a tremendous amount of infected files, as expected. there are lots of different results.
            some of the results:
            win32:vitro
            win32:notre
            win32:small NAD
            win32: fake alert cr
            win32:fakeav-pa
            win32:refpron
            win32:spyware-gen
            win32:trojan-gen
            unable to scan. the file is decompression bomb.
            unable to scan. archive is password protected.

            lots of different operations:
            file was successfully moved to chest
            error occurred during file repair. the file was not repaired.
            error occurred during file repair. access was denied.


            what to do? i have not taken any "actions"
            should i delete the files that were not repaired?

            what should i do next?


            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: BAD virus. can't open hijack this, firefox or any other apps.
            « Reply #26 on: August 26, 2009, 07:55:26 PM »
            Landa, try scanning with MBAM. You will have to select "perform full scan in order to select your slave drive but it will scan your HDD. The same with SAS(SuperAntiSpyware). Make sure you select your slave HDD. If you're successful, please post your logs.
            Windows 8 and Windows 10 dual boot with two SSD's

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: BAD virus. can't open hijack this, firefox or any other apps.
            « Reply #27 on: August 26, 2009, 08:09:05 PM »
            win32:vitro

            Geeksquad was right. Vitro is another name for Virut.

            You can try backing up your pictures but they are likely infected or have been quarantined by Avast. I would scan any drive that you have connected to this computer as they may have been compromised also.

            Unfortunately the only reliable cure is a complete reformat and reinstall. See here for more information. Virut and other File infectors - Throwing in the Towel?

            Many of the major antivirus vendors have Virut removal tools but many times Virut  not repairable. The only reliable way to remove Virut is removing the system files it has infected and in turn crippling the system and calling for a reformat/reinstall anyway. Remember it is always spreading so trying to contain it is impossible. See this article on why it is so destructive. Under the Hood: Virut

            If you do try to repair this without reformatting then your best chance is using the Avira AntiVir Rescue CD. (free) And/or the Dr Web LiveCD. (also free)

            Backing up files before formatting

            If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like text documents and personal photos.

            Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

            I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.
             
            -) Dr.Web CureIt!
            -) AVG Win32/Virut Removal Tool
            -) Symantwc W32.Virut Removal Tool
            -) McAfee Avert Stinger
            -) Microsoft Windows Malicious Software Removal Tool

            If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

            Very important, do the following immediately or as soon as possible!

            If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.
             
            From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

            DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.

            smeezekitty

            • Guest
            Re: BAD virus. can't open hijack this, firefox or any other apps.
            « Reply #28 on: August 26, 2009, 08:11:57 PM »
            Geeksquad was right. Vitro is another name for Virut.

            You can try backing up your pictures but they are likely infected or have been quarantined by Avast. I would scan any drive that you have connected to this computer as they may have been compromised also.

            Unfortunately the only reliable cure is a complete reformat and reinstall. See here for more information. Virut and other File infectors - Throwing in the Towel?

            Many of the major antivirus vendors have Virut removal tools but many times Virut  not repairable. The only reliable way to remove Virut is removing the system files it has infected and in turn crippling the system and calling for a reformat/reinstall anyway. Remember it is always spreading so trying to contain it is impossible. See this article on why it is so destructive. Under the Hood: Virut

            If you do try to repair this without reformatting then your best chance is using the Avira AntiVir Rescue CD. (free) And/or the Dr Web LiveCD. (also free)

            Backing up files before formatting

            If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like text documents and personal photos.

            Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

            I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.
             
            -) Dr.Web CureIt!
            -) AVG Win32/Virut Removal Tool
            -) Symantwc W32.Virut Removal Tool
            -) McAfee Avert Stinger
            -) Microsoft Windows Malicious Software Removal Tool

            If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

            Very important, do the following immediately or as soon as possible!

            If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.
             
            From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

            DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.
            i agree virut is a horrable virus but i think you maybe going alittle overboard

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: BAD virus. can't open hijack this, firefox or any other apps.
            « Reply #29 on: August 26, 2009, 08:14:01 PM »
            Take the time to read the information in the links and then give an educated reply. ::)

            I don't pull what I post out of my a$$.