Disaster - virus!

Joined
6 Dec 2007
Messages
1,419
Reaction score
27
Location
Dundee
Country
United Kingdom
With a 50 - 50 choice whether to put this under software or hardware, I went for this section - and I'll bet it's wrong!!!!

My brother is having a disaster and I'm beginning to think it's beyond my capabilities of fixing.

When he logs onto his computer, within a very short time (up to 30 seconds), he's getting a pop up telling him that NT Authority/System is shutting down his system because the RPC terminated unexpectedly.

After having done a search, everything seemed to point towards it being the W32 Blaster Worm - but that's an ancient virus. Tried running the virus removal tool for it but it didn't detect the Blaster Worm. Checked the system files for msblast.exe and it's not there. So, I'm guessing that it's not the Blaster Worm.

Been having a bloomin nightmare though. I can terminate the shutdown but I can't get onto the internet at all - apparently the internet explorer files are nowhere to be found.

But if I start up in safe mode - I can get on the internet.

Been trying to install Ad Aware (Lavasoft's website mentions this problem) but I can't get it installed - I keep getting the message that the administrator has set policies to prevent this installation. That's when I try to install in safe mode.

If I start up in normal mode (disabling the shutdown) I still can't install it because it's telling me that it can't be installed because I might be running in safe mode or windows installer isn't working properly!

It's taken me hours just to get a new antivirus on it and update it. Ran that and it came up with two detections - searched for the files to see what they were, but there are no desciptions on the internet for them - so I don't know if it's them or a false positive.

Unfortunately, I went and forgot to disable System Restore before I ran the antivirus, so it's not done anything as yet (one detection is showing up in System and the other in Recycler and I'm sure you've got to disable System Restore to be able to get rid of them out of there).

I've given up the ghost for tonight, but I'll run the antivirus again tomorrow and see if it clears them when I have disabled the System Restore.

Question is - do I quarantine these files or delete them?

And next question is - anybody got any idea what the heck to do next?
 
Sponsored Links
This is a software problem, not hardware.

Do not run Internet Explorer until you've cleaned the machine.

1. Insulate the machine from the Internet. Physically.
2. Boot to Safe Mode.
3. Remove all temporary files.
4. Export the Registry Run containers, then remove all suspect entries.
5. Rename all suspect files in Windows and Windows\System32.
6. Terminate any processes that you don't recognise.
7. Run any anti-virus and anti-spyware software that you already have installed.
9. Use HijackThis if you know how to.
10. Boot to Normal Mode, and re-run the anti-virus and anti-spyware scans.

If it's still not clean, ask for more help.
 
Thanks, will get up to it later.

How do I export the Registry containers (sorry if this is a daft question)
 
It's taken me three days but I seem to have sorted it out.

I couldn't believe the cr@p that my brother has on his computer and the viruses!!!!

And I think it all stemmed from stupid screensavers he downloaded. Everything appeared to be OK until he uninstalled them! And that was how he got his last virus.

Be very careful of downloading screensavers.com!!!!!!
 
Sponsored Links
This all started on Sunday and I only posted when I wasn't getting anywhere!! :rolleyes:
 
That's exactly what someone would use as a cover story if they had a secret time machine and accidentally blabbed. ;)
 
I keep lecturing him about backing up his important files and making sure he's got up to date anti virus, firewall, anti spyware, etc but he just merrily goes on his way, knowing that if it all goes wrong, I'll fix it - but I'm no computer genius - most of what I can do is by luck more than knowledge - or a damned good search on the internet.

I don't have Norton Ghost, but I do back up all my files (external hard drive and DVD) and I've got all my installation discs so I'd be OK in the event of a crash - but him?

Wish I lived in the same wee happy world he's in!!!!!! :LOL: :LOL: :LOL:

With the likes of Norton Ghost or similar, do you have to save the entire drive or can you just do selected files - like My Documents/Pictures, etc?
 
if backing up individual files then any backup prog should do but programs like ghost and acronis are needed if you want a full image backup of your hdd

Not sure about ghost but Acronis true image allows individual file backup aswell as the whole hdd image.
 
Sponsored Links
Back
Top