Login
Search

Welcome to the GamersHell.com forums Register today!
Reply
 
LinkBack Thread Tools Display Modes
Old 03-07-2005, 06:50 PM   #1 (permalink)
 
is on the 5th circle: Wrath & Sullenness

Join Date: Aug 2004
Location: Hellmond, Netherlands
Posts: 1,611
Hellbux: 26,609


Send a message via MSN to LoneStrider
Default

yeah guys, my sister did it again. she went whining to me, because her MSN messenger started acting strange, and it did. it was obvious she got infected with a virus. it opened up message windows and starts sending stuff around:

Fat Elvis! lol.pif
Crazy Frog getting killed by train.pif
Crazy Frog getting killed.pif
Jennifer Lopez.scr
me topless in a skirt.pif

and some more stuff. i did full virusscans, and it found one: Rbot-RY (i do think that is the one, but there is no info on how to get rid of it). it seems it got itself into the registry, and denying me access into REGEDIT! (it just gives a flash of the window, than it closes itself). also every internet page with Virus in it or any anti-virus program publisher give the same symptoms (closing it down after typing it). i don't like this one bit, cuz i had the pc formatted because of another virus. i DID found the shortcuts of the viruses. they were just before the program files map (the map after clickin on your HD). it got about 7-8 files, and all were hidden files with the MS-DOS logo, and all .pif. when i delete them, you just need to wait around 5 seconds for them to pop back in! does someone here know how to track a shortcut to its original file? and no, properties does not work, since there is no pathway or target. oh and i would like to add that when the computer starts it has a notepad file saying 'sandpaper you larissa you sandpaperkin n00b' or something.

/ranting now

:rant: :rant: goddammit those filthy sonuvvanoobs! i hate these friggin life-less bitches who think they are cool with them viruses! go sandpaper yourself you lifeless nerds!! :rant: :rant:

/rant terminated
__________________


'Because the finding of this, finds you incapacitorially finding and/or locating in your discovering the detecting of a way to save your dolly belle ol' what's her face.' - Captain Jack Sparrow
LoneStrider is offline   Reply With Quote
Old 03-07-2005, 07:21 PM   #2 (permalink)
Akherousin's Avatar
 
is on the 5th circle: Wrath & Sullenness

Join Date: Jun 2004
Location: Zurich, Switzerland
Posts: 1,927
Hellbux: 1,512


Default

Did you try Save mode?

also: http://www.trendmicro.com/vinfo/virusencyc...T%2ERY&VSect=Sn
__________________
Akherousin is offline   Reply With Quote
Old 03-07-2005, 08:14 PM   #3 (permalink)
 
is on the 1st circle: Limbo

Join Date: Aug 2004
Location: Worcestershire, England
Posts: 27
Hellbux: 928


Default

did system restore do any good ? You need a program called 'Goback' which had you got it installed could give you multilple choices to reset to times earlier
__________________
Asus A8V rev 2, AMD 64 4000+ ,2gig Corsair XMS3200XL
Gigabyte 6800GT, Raptor 74
USHER is offline   Reply With Quote
Old 03-07-2005, 08:19 PM   #4 (permalink)
Akherousin's Avatar
 
is on the 5th circle: Wrath & Sullenness

Join Date: Jun 2004
Location: Zurich, Switzerland
Posts: 1,927
Hellbux: 1,512


Default

Quote:
Originally posted by USHER@Mar 7 2005, 09:14 PM
did system restore do any good ? You need a program called 'Goback' which had you got it installed could give you multilple choices to reset to times earlier
This is a double bladed sword. System restore usually restores the virus instead of removing it.

The usual steps for taking care of viruses are:

1. DISABLE system restore
2. reboot and start in Save Mode
3. disable all startup entries (with msconfig)
4. running an antivirus program

Works with most viruses.
__________________
Akherousin is offline   Reply With Quote
Old 03-07-2005, 08:44 PM   #5 (permalink)
 
is on the 5th circle: Wrath & Sullenness

Join Date: Aug 2004
Location: Hellmond, Netherlands
Posts: 1,611
Hellbux: 26,609


Send a message via MSN to LoneStrider
Default

i could try that. thanks, will update soon.
__________________


'Because the finding of this, finds you incapacitorially finding and/or locating in your discovering the detecting of a way to save your dolly belle ol' what's her face.' - Captain Jack Sparrow
LoneStrider is offline   Reply With Quote
Old 03-07-2005, 08:48 PM   #6 (permalink)
 
is on the 5th circle: Wrath & Sullenness

Join Date: Oct 2003
Location: North Carolina
Posts: 1,152
Hellbux: 17,361


Send a message via AIM to Rhett Send a message via MSN to Rhett
Default

hmmm I see.. one of my friends constantly messaged me to send me pics and stuff like that.. dang
__________________
Ex Gamer's Hell Staff


My HL2 Console Spawning Guide UPDATED 26/02/05
Rhett is offline   Reply With Quote
Old 03-07-2005, 09:06 PM   #7 (permalink)
 
is on the 6th circle: Heresy

Join Date: Jan 2004
Location: Östersund - Sweden
Posts: 2,900
Hellbux: 33,751


Default

Me and Ullved got it to. Running virus scan in normal mode now and if that doesn't work then I will try safe mode. Btw why does it work better in safe mode??
__________________
Hasse is offline   Reply With Quote
Old 03-07-2005, 09:09 PM   #8 (permalink)
 
is on the 5th circle: Wrath & Sullenness

Join Date: Oct 2003
Location: North Carolina
Posts: 1,152
Hellbux: 17,361


Send a message via AIM to Rhett Send a message via MSN to Rhett
Default

Quote:
Originally posted by Hasse@Mar 7 2005, 04:06 PM
Me and Ullved got it to. Running virus scan in normal mode now and if that doesn't work then I will try safe mode. Btw why does it work better in safe mode??
because sometimes windows has specific files in use that cannot be scanned or removed, so safe mode removes most of that problem.
__________________
Ex Gamer's Hell Staff


My HL2 Console Spawning Guide UPDATED 26/02/05
Rhett is offline   Reply With Quote
Old 03-07-2005, 09:15 PM   #9 (permalink)
Akherousin's Avatar
 
is on the 5th circle: Wrath & Sullenness

Join Date: Jun 2004
Location: Zurich, Switzerland
Posts: 1,927
Hellbux: 1,512


Default

Quote:
Originally posted by Rhett+Mar 7 2005, 10:09 PM--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (Rhett @ Mar 7 2005, 10:09 PM)</td></tr><tr><td id='QUOTE'> <!--QuoteBegin--Hasse@Mar 7 2005, 04:06 PM
Me and Ullved got it to. Running virus scan in normal mode now and if that doesn't work then I will try safe mode. Btw why does it work better in safe mode??
because sometimes windows has specific files in use that cannot be scanned or removed, so safe mode removes most of that problem. [/b][/quote]
Exactly. Plus Windows doesn't load any startup entries or processes other than the windows default ones.

(To boot in safe mode, press F8 constantly during startup til the menu shows up (after the POST process )
__________________
Akherousin is offline   Reply With Quote
Old 03-07-2005, 09:32 PM   #10 (permalink)
 
is on the 6th circle: Heresy

Join Date: Jan 2004
Location: Östersund - Sweden
Posts: 2,900
Hellbux: 33,751


Default

Quote:
Originally posted by Akherousin+Mar 7 2005, 11:15 PM--></span><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (Akherousin @ Mar 7 2005, 11:15 PM)</td></tr><tr><td id='QUOTE'>
Quote:
Originally posted by -Rhett@Mar 7 2005, 10:09 PM
<!--QuoteBegin--Hasse
Quote:
@Mar 7 2005, 04:06 PM
Me and Ullved got it to. Running virus scan in normal mode now and if that doesn't work then I will try safe mode. Btw why does it work better in safe mode??

because sometimes windows has specific files in use that cannot be scanned or removed, so safe mode removes most of that problem.
Exactly. Plus Windows doesn't load any startup entries or processes other than the windows default ones.

(To boot in safe mode, press F8 constantly during startup til the menu shows up (after the POST process ) [/b][/quote]
I know how to enter safe mode :P I'm not a n00b :P
__________________
Hasse is offline   Reply With Quote
Reply



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT. The time now is 10:46 AM.

Search Engine Optimization by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77