Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > Forest of True Sight > Technician's Corner

Notices

Reply
 
Thread Tools Display Modes
Old Oct 17, 2006, 02:24 PM // 14:24   #21
Jungle Guide
 
D.E.V.i.A.N.C.E's Avatar
 
Join Date: Aug 2005
Profession: Mo/
Advertisement

Disable Ads
Default

Mcafee hasnt reported it in thier threat list yet, another guy has been infected with this, he was on a french forums, yet no solution in sight, guess what they listed;
spybot s&d
ad-aware and avast.. this was back on the 14th. hmmm...

I hate zone alarm with a passion, I hear these stories of i deactivated (norton or zone alarm) and got infected, basicly they STOP it from activating but dont remove it. so once u de-activate it it gets its chance to run amuck.

I would agree with backing up data and just do a fresh install, once you've tried everything else.

I would lookup every process on google and see if you come across anything or nothing atall. I remeber when I got infected with a trojan that just wouldnt quit, had 3 processes to keep it alive...
task manager [processes]
If you find any processess that dont have any info on the web, see what happens when u end task it. also if you do find any processes that dont have info make a note where they are located.

skype and gizmo are great voip services, skype can be a resource hog, just cause it records at such a high quality always... with gizmo u can atleast set limits.

Last edited by D.E.V.i.A.N.C.E; Oct 17, 2006 at 02:28 PM // 14:28..
D.E.V.i.A.N.C.E is offline   Reply With Quote
Old Oct 17, 2006, 11:17 PM // 23:17   #22
Krytan Explorer
 
ducktape's Avatar
 
Join Date: Jul 2005
Profession: W/R
Default

Have you turned off System Restore? I have found that many viruses/spyware manage to trick System Restore into thinking that their files are windows-related, so yes, every time you delete them they come back, even in safe mode, because System Restore puts them back. I would turn off System Restore, then boot into Safe Mode, then clear out your temp files and junk using Disk Cleanup again. After that, run AVG/Spybot/Ad-Aware/Windows Defender and let them delete everything.

If you want to manually hunt down the viral processes that are running so that you can manually delete them and their pals in the registry when you go into Safe Mode, I suggest you download Process Explorer from Sysinternals. You can launch that program and it will show every process running on your computer, you can click each and it will show you every file and registry key that a process is accessing, which really helps when manually removing spyware and viruses. If you're not sure what a process is for, you can right-click it and choose Google and it will bring up a google search result for you to dig around and find out more.

You could also create a new user account while in Safe Mode and sign on with that new account and see if all of the virus stuff comes back, sometimes if you're really luck all that is installed under HKEY_CURRENT_USER and under your user profile, so using a different account helps get the virus off of your back.

Most of this will only work if you are really lucky, unfortunately many viruses are hard to get rid of, and even after they're gone, your computer never works quite right again. You can do all this to try and get your stuff going long enough to back everything up, but either way I recommend you end up writing zeroes to your HD and then reinstall windows from scratch, just to make sure your system is totally clean before you resume normal use.
ducktape is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 01:32 PM // 13:32.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("