Virus Deletion

Berne

Member
Feb 16, 2010
91
0
61
Hi,
So I have a virus on my machine. Unable to access Safe Mode, Booting to desktop is possible and getting online also, BUT , desktop is freezing, no internet activity allowed, and unable to run antivirus even offline due to freezing desktop....seemed like an antivirus company trying to sell me thier product, wierd.

Anyhow been looking around on the issue but it looks like a format OR can you save me doing that?

All good advice welcome,

Berne
 

VirtualLarry

No Lifer
Aug 25, 2001
56,453
10,120
126
Sounds like you need to use a second, working computer, to download and burn an anti-virus bootable CD, that will scan your computer and hopefully remove the infection. I don't know of any URLs offhand, someone a long time ago posted a list of the most popular ones.

Either that, or get a hold of rkill, it comes it several flavors, and put it on a USB stick. It's wierd that you claim that the mouse isn't working, does it move the mouse cursor at all? Is it just that you cannot click on anything?

Maybe you would have to use keyboard shortcuts to launch rkill. Once you get rkill running, it will (hopefully) terminate the rogue AV process, and then allow you to launch a real malware removal tool, like malwarebytes, etc.

Those are my only two suggestions that I can think of offhand, other than a reformat.
 

Lemon law

Lifer
Nov 6, 2005
20,984
3
0
If you can get to the desktop, using system restore to an earlier date will sometimes save your butt. Can't hurt.
 

Berne

Member
Feb 16, 2010
91
0
61
Hi People,
Well this virus was good, if you dont mind wanted me to buy a years subscription their antivirus product! Froze on boot at desktop mouse was moveable but commands not activated. It blocked sys restore as well as not allowing anyprogrames to run at desktop level.

Safe mode was the saviour, sys restore was wide open.

Many thanks people, this site is also a saviour to many many people.

Berne
 

Berne

Member
Feb 16, 2010
91
0
61
Hi People,

Many thanks for the replies. The dreaded format, ....backup.

Berne
 

LiuKangBakinPie

Diamond Member
Jan 31, 2011
3,910
0
0
Well that sounds like the dangerous sality virus. Its a deadly file virus. So Combofix won't work against it. What tools do you have with you or on a cd that you assist with trying to kill its startup process. You need Autoruns, process explorer, unlocker, gmner and killbox. Do you have or can you get any off those applications?

if you can get me a hijack this log i can analyze it for you
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |