Computer virus help!

Mr Unoriginal

CAGiversary!
Feedback
111 (100%)
Yesterday my computer got a virus. I ran a few scanners but it didn't find anything so I did a system restore. That didn't help and when it was done a whole bunch of random folders and files were hidden. I can open up in safe mode and I'm try to unhide everything. I ran malware, spybot, windows defender, and avast and none of them found anything. Also, when I search for something in google, when I click on a resultmit takes me to some spam page. Any advice on what to try before I reformat?
 
[quote name='Mr Unoriginal']Yesterday my computer got a virus. I ran a few scanners but it didn't find anything so I did a system restore. That didn't help and when it was done a whole bunch of random folders and files were hidden. I can open up in safe mode and I'm try to unhide everything. I ran malware, spybot, windows defender, and avast and none of them found anything. Also, when I search for something in google, when I click on a resultmit takes me to some spam page. Any advice on what to try before I reformat?[/QUOTE]
Back up your documents?
 
[quote name='WhipSmartBanky']Back up your documents?[/QUOTE]

Yeah once I found them again, I started backing up important stuff, porn, etc.
Actually, now that I unhid everything, I'm running MalAware again and it's finding stuff this time so I may be in the clear.
 
No. In fact, I was watching a few episodes of a show through the comp as a media server on the PS3. The movie stopped so I went to check on the computer and it was restarting itself and the problem happened after that.
 
For future reference, this malware usually installs a rootkit (not all variants do from what I've encountered) and can't just be fixed with a typical malware scan (meaning it'll come back eventually). Here's my removal steps off the top of my head:



1) Open RegEdit (Windows Key + R -> Type in "regedit" and hit enter) and navigate to: HK_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run (Also check RunOnce) and look for anything that points to C:\ProgramData or C:\Users\\AppData or C:\Documents and Settings\Application Data or C:\Documents and Settings\Local Data.

2) Remove any unknown shit from those locations, particularly ones with incomprehensible names. (This is done to help prevent shit from running under other user accounts)

3) Create a second user if you don't have another one you can log into. This can be done through command line (Windows Key + R -> Type in "cmd" and hit enter). The commands are "net user /add" followed by "net localgroup administrators /add"

4) Sign into said account.

5) Open up IE (I say IE because I know the shortcut) through run (Windows Key + R -> type iexplore.exe and hit enter) -- Alternatively get all this from alternate computer instead and run from thumb drive

6) Download/Install/Scan and run Malwarebytes [Removes basic shit] first. Then do the same with a program called Hitman Pro [Removes rootkits + extra shit] (Free 30 day trial for non-domain computers; no need to install/register). Finally do one called TDSSKiller [second opinion scanner] (no install) and you should be good.

7) Now download and run: http://download.bleepingcomputer.com/grinler/unhide.exe

8) You can then go to open up your temp folder and retrieve your start menu (Windows Key + R -> type %temp% and hit enter) which is located in a folder called smtms or something similar (sort by date, makes it easier). On Windows 7 you want to copy it to C:\ProgramData\Microsoft\Windows\Start Menu\

9) Reboot into safe mode. Sign into your normal user account and download/run: http://live.sysinternals.com/procexp.exe

10) Make sure you have no garbled shit attached to explorer.exe.

11) Open RegEdit (Windows Key + R -> Type in "regedit" and hit enter) and navigate to: HK_Current_User\Software\Microsoft\Windows\CurrentVersion\Run (Also check RunOnce) and look for anything that points to C:\ProgramData or C:\Users\\AppData or C:\Documents and Settings\Application Data or C:\Documents and Settings\Local Data.

12) Remove any unknown shit from those locations, particularly ones with incomprehensible names. Even though it likely points to nothing since the malware was deleted, it should be removed.



If that doesn't work (Usually does though), then I usually say fuck it and just reimage/rebuild the machine after backing stuff up. Actually removed this malware on a client machine today. One of the worse variants this time and I'm not sure who the fuck made that person a local administrator but I want to shoot them in the face. Turned into a 15 minute quick fix to a 1.5-2 hour fix. Would have reimaged it if they weren't 45 minutes away and not enough people in the office today.
 
Last edited by a moderator:
You can. I use a lot of run shortcuts and command line typically, which bypasses the that annoying hide everything shit. Unless the malware closes the window automatically, at which point I'm like "Nope. Nuke from orbit."
 
Thanks Draekon, that seemed to do it.
It was Hitman Pro that really helped out. It found a bunch of stuff that MalWare and Spybot didn't pick up.
Appreciate the help as well as all the help you bring to the PC forums. You always seem to swoop in and save the day.
 
Just be aware that if it comes back, then you are going to want to back everything up and reformat/perform a factory reset. The only way to be completely sure that it's free of any threat is to reformat. (aka Nuke or Nuke it from orbit.)

And while I know a fair deal, it's difficult to communicate it properly to people. I try to replace steps that have a possibility of harming your computer with the longer less risky solution, but it's not always so easy. Then there will be times where I can only go so far before I have to just say "Sorry, I can't help fix it. Since that's the case, I recommend backing up data and reformatting/restore back to factory settings."


I think I'm going to make a 'Proper way to setup your new computer' thread to help users prevent this in the future as using a non-administrator account for your daily activities will make a world of difference in malware infecting your computer. It'll probably be a bit until I can do that though.
 
I've had some similar shit happen to my system back in Dec and 2 weeks ago. Kept on doing some crazy "Your system is infected..." pop ups (like 40 windows) followed by a fake virus scanner running. Trying to do a system restore cause the malware/virus to give me a warning that it was infected and to run it at own risk. Safe mode didn't do shit as that was messed up as well....final solution? Nuked it! *sigh*
 
bread's done
Back
Top