PDA

View Full Version : Help me


mmbt0ne
02-18-2005, 04:28 AM
I have a virus.

I know this much is wrong:
Ctrl-Alt-Del doesn't work
regedit doesn't work
Sometimes they show up and disappear when I move my mouse over them, sometimes they don't show up at all.

I've run AVG, it found two files infected but couldn't do anything because they were archived. I deleted these two files, but nothing has changed.

Next step?

AngryCola
02-18-2005, 04:33 AM
From here on out, I think all the computer questions have a home of their own. The new software forum definitely should take off.

As to your question, it's difficult to say.

What are "they"?
[ QUOTE ]
Sometimes they show up and disappear when I move my mouse over them, sometimes they don't show up at all.

[/ QUOTE ]

Secondly, you obviously need the most recent AVG updates to be completely sure you are catching everything.

Also, I'm not sure why you would have any trouble getting rid of the infected files it catches.
Try rebooting in safe mode to run the virus scanner again.
Sometimes that can help a lot.

WIthout a lot more information, I can't think of anything else to suggest right now.
But that might just be because I'm having a mental lapse or something.

mmbt0ne
02-18-2005, 04:38 AM
"they" are regedit and task manager. Imagine them coming up like a splash screen, and then promptly disappearing, or not coming up at all.

I updated the AVG right before I ran the scan. No updates were found. I've never seen it not heal a file before, so I have no idea what was going on with that.

I'm trying the safe mode thing right now.

EliteNinja
02-18-2005, 04:41 AM
If in doubt, backup all your stuff on CD and reinstall Windows.

AngryCola
02-18-2005, 04:41 AM
[ QUOTE ]
I've never seen it not heal a file before, so I have no idea what was going on with that.

[/ QUOTE ]

Sometimes it cant.

Depending on the type of file which was infected, it could be a bad idea to delete them. Often times a virus will infect a crucial system file. That's bad, but not as bad as when you find out the file can't be healed.

I've had to find a few replacement files for situations like this in the past. You would be wise to note which files you deleted.

mmbt0ne
02-18-2005, 11:05 AM
I deleted a zip file and a Java .class file from C:\Documents and Settings\Ryan Anderson\.jpi_cache\jar\1.0

I figured that there was nothing of major importance in there when I looked around and just saw that it's a bunch of applets that I've downloaded to run things from ESPN Gamecast, to different poker whatnots. Every file in there is a zip or an IDX, but the two it found were a zip and a .class so I figured that was were it had installed itself and just deleted it.

It's really not worth re-installing windows right now if all that is happening is those 2 symptoms, but I might do that later.

mmbt0ne
02-18-2005, 11:29 AM
I got tricky and took a screenshot for the short period of time that the task manager was up to see if I could figure something out.

http://www.f2f2s.com/images/tasks.gif

That AOLClient.exe should NOT be there. Luckily, I've been denying it access through ZoneAlarm, because it's a Trojan.

Everyone's friends are assholes. Mine are no exception.
http://computercops.biz/postt105338.html

mmbt0ne
02-18-2005, 11:49 AM
Alright, I'm back functioning. Words of advice.

1) Don't download anything from your friends' away messages
2) If you do, and Ctrl-Alt-Del/regedit/msconfig won't work, do the following

a) Search your hard drive for AOLclient

b) If you find it open up Spybot Search and Destroy and run it in Advanced Mode (if you don't have Spybot I would download it from download.com).

c) Once in spybot click on the tools button and look for the tool called "Process List". This will show you all the running processes just like TaskManager.

d) You will need to kill the AOLclient process in order to delete the file.

e) After killing the process delete the file that your search found.
Mine was in Windows/prefetch, and the actual client was in Windows/system32. I deleted them both.

AngryCola
02-18-2005, 04:07 PM
Good work.

I'm glad you were able to solve the problem yourself, because that one would have been fairly tough for others to track down.

MelchyBeau
02-18-2005, 04:11 PM
for future reference. Free antivirus.

Link (http://housecall.antivirus.com)

Melch