Antivirus XP 2008 (computer virus HELP!)

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Antivirus XP 2008 (computer virus HELP!)

Post by Shroom Man 777 »

I got infected by this virus that replaced my desktop, and made my computer unable to go to the net. It is hard to remove, and since my computer is no longer capable of using its browsers, I cannot download anything to cure it.

The virus resembles this

But I can't even run CMD to try and manually destroy it. What the hell do I do, guys?
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
User avatar
Bounty
Emperor's Hand
Posts: 10767
Joined: 2005-01-20 08:33am
Location: Belgium

Post by Bounty »

Any chance of you just reinstalling the OS? Considering how much a bitch this virus is, it may be the most efficient method, and it's the only one sure to work.

Or you can try following the guide you linked to?
User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Post by Shroom Man 777 »

My computer contains valuable files, and must be preserved. Can anyone tell me a way to destroy this horrible pox?

EDIT:

I can't even use CMD to manually remove the .dll files OR even use the internet in that computer! What the hell?!
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
User avatar
General Zod
Never Shuts Up
Posts: 29211
Joined: 2003-11-18 03:08pm
Location: The Clearance Rack
Contact:

Post by General Zod »

This utility is supposed to blast it away for good, but I nuked my hdd when I caught the fucking thing so I couldn't say for certain. It was posted as a link in the other thread discussing this virus.
"It's you Americans. There's something about nipples you hate. If this were Germany, we'd be romping around naked on the stage here."
User avatar
Bounty
Emperor's Hand
Posts: 10767
Joined: 2005-01-20 08:33am
Location: Belgium

Post by Bounty »

Shroom Man 777 wrote:My computer contains valuable files, and must be preserved.
I'd still recommend getting the files off of it and reinstalling. Also, what are you doing keeping irreplaceable files in one location?
User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Post by Shroom Man 777 »

@ General Zod:

Yeah.

The virus is deceitful, it FOOLED me into thinking that my browsers didn't work anymore. But now I'm in the middle of downloading it.

Fuck these germs!


EDIT:

@ Bounty:

Um, we transfered a lot of our files on to a new computer. But I would get into trouble if I ended up getting all the stuff on the old computer deleted, so... yeah.

Goddamn.
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
User avatar
Ariphaos
Jedi Council Member
Posts: 1739
Joined: 2005-10-21 02:48am
Location: Twin Cities, MN, USA
Contact:

Post by Ariphaos »

Boot into safemode with networking

Download the batch script from here

http://www.internetinspiration.co.uk/roguefix.htm

Kill the explorer.exe process and run the batch script. Reboot from the task manager. It will probably be gone. If not, repeat but don't reboot, run spybot in safe mode while explorer.exe is shut down, and post a hijackthis log (easier to read a shorter log).

If you don't have at least xp with sp2 installed, it may be significantly tougher, the easiest solution then is just to do a repair install with an sp2 or sp3 windows install disc.
Give fire to a man, and he will be warm for a day.
Set him on fire, and he will be warm for life.
User avatar
Edi
Dragonlord
Dragonlord
Posts: 12461
Joined: 2002-07-11 12:27am
Location: Helsinki, Finland

Post by Edi »

Warwolf Urban Combat Specialist

Why is it so goddamned hard to get little assholes like you to admit it when you fuck up? Is it pride? What gives you the right to have any pride?
–Darth Wong to vivftp

GOP message? Why don't they just come out of the closet: FASCISTS R' US –Patrick Degan

The GOP has a problem with anyone coming out of the closet. –18-till-I-die
User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Post by Shroom Man 777 »

Success! The victory of freedom!

Thanks, Xeriar! I love ya! You beautiful, beautiful man.


I HAVE PURGED MY EXCREMENTS!
Last edited by Shroom Man 777 on 2008-08-18 12:35am, edited 1 time in total.
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
User avatar
Stark
Emperor's Hand
Posts: 36169
Joined: 2002-07-03 09:56pm
Location: Brisbane, Australia

Post by Stark »

Yeah, if you don't have at least XP SP2, you're pretty much doomed with this one. Dare we ask who pressed the button? :)
User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Post by Shroom Man 777 »

I was looking at porno :oops:
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
User avatar
White Haven
Sith Acolyte
Posts: 6360
Joined: 2004-05-17 03:14pm
Location: The North Remembers, When It Can Be Bothered

Post by White Haven »

Repeat after me: Titties don't ask you to download antivirus software. Not even if you're as fucking crazy as Shroom.
Image
Image
Chronological Incontinence: Time warps around the poster. The thread topic winks out of existence and reappears in 1d10 posts.

Out of Context Theatre, this week starring Darth Nostril.
-'If you really want to fuck with these idiots tell them that there is a vaccine for chemtrails.'

Fiction!: The Final War (Bolo/Lovecraft) (Ch 7 9/15/11), Living (D&D, Complete)Image
User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Post by Shroom Man 777 »

It just happened, okay! Suddenly this bubble (that looked like normal Windows 'info' bubbles from the lower right corner) appeared telling me I had one thousand viruses, and the Antivirus XP thing just came up and I ignored it.

I am an idiot.

But since the mistake was rectified, I guess it's perfectly alright :)
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
User avatar
Einhander Sn0m4n
Insane Railgunner
Posts: 18630
Joined: 2002-10-01 05:51am
Location: Louisiana... or Dagobah. You know, where Yoda lives.

Post by Einhander Sn0m4n »

Get off IE. It's that simple.
Image Image
User avatar
Stark
Emperor's Hand
Posts: 36169
Joined: 2002-07-03 09:56pm
Location: Brisbane, Australia

Post by Stark »

Shroom Man 777 wrote:It just happened, okay! Suddenly this bubble (that looked like normal Windows 'info' bubbles from the lower right corner) appeared telling me I had one thousand viruses, and the Antivirus XP thing just came up and I ignored it.

I am an idiot.

But since the mistake was rectified, I guess it's perfectly alright :)
This reflects the critical computer use issue of 'trust'. :)
User avatar
Ariphaos
Jedi Council Member
Posts: 1739
Joined: 2005-10-21 02:48am
Location: Twin Cities, MN, USA
Contact:

Post by Ariphaos »

Stark wrote:Yeah, if you don't have at least XP SP2, you're pretty much doomed with this one. Dare we ask who pressed the button? :)
It's not impossible, it just hooks into various system processes that it can't stick to in sp2, and you have to be a lot sneakier about killing it.

I do prefer Firefox over IE/Opera/Safari, almost entirely because of Noscript. I'm not aware of any other browser having a similarly flexible plugin, anyway.

Also, get Antivir, or if you feel like paying, Nod32, if you don't have one them already. Just about everything else is either insanely processor intensive or is a joke about protecting you. Or both.

With Noscript and a good antivirus, clicking on boobies is a good deal safer.

Edit: The last bits are for Shroomie
Give fire to a man, and he will be warm for a day.
Set him on fire, and he will be warm for life.
User avatar
Glocksman
Emperor's Hand
Posts: 7233
Joined: 2002-09-03 06:43pm
Location: Mr. Five by Five

Post by Glocksman »

NOD32 for the win.
I managed to snag my copy of 3.0 for $19 from Newegg.
Sure beats the shit out of Norton's bloatware.
"You say that it is your custom to burn widows. Very well. We also have a custom: when men burn a woman alive, we tie a rope around their necks and we hang them. Build your funeral pyre; beside it, my carpenters will build a gallows. You may follow your custom. And then we will follow ours."- General Sir Charles Napier

Oderint dum metuant
User avatar
atg
Jedi Master
Posts: 1418
Joined: 2005-04-20 09:23pm
Location: Adelaide, Australia

Post by atg »

Destructionator XIII wrote:EDIT: I can't resist.
Damm you! I can't get that tune out of my head now :evil:
User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Post by Shroom Man 777 »

Einhander Sn0m4n wrote:Get off IE. It's that simple.
I use Firefox, mang.
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
User avatar
Tsyroc
Emperor's Hand
Posts: 13748
Joined: 2002-07-29 08:35am
Location: Tucson, Arizona

Post by Tsyroc »

I had part of AntivirusXp08 at the end of July from clicking on something to download a video codec supposedly necessary to watch a video sex tape! of someone I didn't even know who they were. :oops:

Anyway, McAfee notified me right away and killed part of it but because I had decided to run the install instead of downloading it first before running it I got hit with the part where my desktop picture got replaced and I couldn't change it using the usual control panel functions because a couple of the tabs had been removed (suppressed) by the virus.

Luckily for me I did this first thing that day so I was able to hunt down and delete virus files manually based on the time/date and that they were total crap. I did have to edit some stuff in the registry so the Windows control panel would work right again.


The main reason I'm mentioning what happened to me is because supposedly telling people they need to download such and such codec is a very common way for this and several related viruses to get people.

I also find it kind of funny that the virus often tries to get people to buy a bogus antivirus program but if you search the internet for information on these viruses there are tons of people selling you programs to get rid of this virus.

One of the annoying features of this virus is that AntivirusXp08 shows up as a regular program and on the Add/Delete Program portion of the control panel. However, you can't actually uninstall it using the control panel or the supposed uninstall function in its own folder. It's also set up to reinstall itself every time you restart Windows so you have to be thorough in getting rid of all its crap. :)
By the pricking of my thumb,
Something wicked this way comes.
Open, locks,
Whoever knocks.
User avatar
Ariphaos
Jedi Council Member
Posts: 1739
Joined: 2005-10-21 02:48am
Location: Twin Cities, MN, USA
Contact:

Post by Ariphaos »

If it's not in the k-lite mega codec pack, you don't need it (usually)
Give fire to a man, and he will be warm for a day.
Set him on fire, and he will be warm for life.
User avatar
KhyronTheBackstabber
Jedi Council Member
Posts: 1673
Joined: 2002-09-06 03:52am
Location: your Mama's house

Post by KhyronTheBackstabber »

My sister got hit with this last month. Tricky little son of a bitch. I found this, Malwarebytes' Anti-Malware, for her and it got rid of it.
Image
MM's Zentraedi Warlord/CF's Original Predacon/JL's Mad Titan
User avatar
Haruko
Jedi Master
Posts: 1114
Joined: 2005-03-12 04:14am
Location: California
Contact:

Post by Haruko »

KhyronTheBackstabber wrote:My sister got hit with this last month. Tricky little son of a bitch. I found this, Malwarebytes' Anti-Malware, for her and it got rid of it.
I can vouch for the use of that software. When I had hijacker trojans disable my Start Menu and task-bar and continually display false security warnings, I tried a removal tool in safe mode to no avail, but Malwarebytes took care of the problem easily, and I didn't have to go to safe mode. I still use it along with the several other softwares (Avira, Zonealarm, Spybot S&D, Adaware, and Spywareblaster) without any trouble.
If The Infinity Program were not a forum, it would be a pie-in-the-sky project.
Faith is both the prison and the open hand.”— Vienna Teng, "Augustine."
User avatar
Glocksman
Emperor's Hand
Posts: 7233
Joined: 2002-09-03 06:43pm
Location: Mr. Five by Five

Post by Glocksman »

Einhander Sn0m4n wrote:Get off IE. It's that simple.
Just this morning I had 'Antivirus 2008' pop ups in Firefox 3.0.
I hit 'Alt-F4' to close them because I remembered someone (Shep?) saying that all of the buttons in the popup itself are mapped to install the damn thing including the 'cancel' button.
"You say that it is your custom to burn widows. Very well. We also have a custom: when men burn a woman alive, we tie a rope around their necks and we hang them. Build your funeral pyre; beside it, my carpenters will build a gallows. You may follow your custom. And then we will follow ours."- General Sir Charles Napier

Oderint dum metuant
User avatar
Shroom Man 777
FUCKING DICK-STABBER!
Posts: 21222
Joined: 2003-05-11 08:39am
Location: Bleeding breasts and stabbing dicks since 2003
Contact:

Post by Shroom Man 777 »

Glocksman, if you're infected, then just do this:
Xeriar wrote:Boot into safemode with networking

Download the batch script from here

http://www.internetinspiration.co.uk/roguefix.htm

Kill the explorer.exe process and run the batch script. Reboot from the task manager. It will probably be gone. If not, repeat but don't reboot, run spybot in safe mode while explorer.exe is shut down, and post a hijackthis log (easier to read a shorter log).

If you don't have at least xp with sp2 installed, it may be significantly tougher, the easiest solution then is just to do a repair install with an sp2 or sp3 windows install disc.
Worked for me, mang.
Image "DO YOU WORSHIP HOMOSEXUALS?" - Curtis Saxton (source)
shroom is a lovely boy and i wont hear a bad word against him - LUSY-CHAN!
Shit! Man, I didn't think of that! It took Shroom to properly interpret the screams of dying people :D - PeZook
Shroom, I read out the stuff you write about us. You are an endless supply of morale down here. :p - an OWS street medic
Pink Sugar Heart Attack!
Post Reply