954,229 Members — Technology Publication meets Social Media
Username:
Password:
Lost login information?
Have something to say? Contribute New Article Reply to this Article

Really bad virus, cant run anything

Hi,

I recently got a virus which will not let me run any of my programs. I read the sticky thread about what to do before you post, but I cannot access the internet. I do however, have a USB which I can transfer over the programs requested, however, I will not be able to run any of those. My computer will not even let me use Ctrl+Alt+Del to view the processes. I have another laptop handy to download any files and transfer the via USB to my laptop. I have no idea what to do and would greatly appriciate some help. Everytime I try to access anyprogram (I have been trying to run Malwarebytes) a pop up appears and says something is broken and to go to this site and download an antivirus (which is obviously a scam). I cannot access the internet from the infected computer anyother way. Please advise. Thanks!

kettennis
Newbie Poster
1 post since Dec 2010
Reputation Points: 10
Solved Threads: 0
 
I recently got a virus which will not let me run any of my programs.


-- What rogue product are you asked to install?

-- What is your OS on infected compy?

-- Are you able to boot to Safe Mode? (tap F8 at startup)
-- If so, do you have the option for Safe Mode with Networking?

-- Are you able to get a command prompt (START > RUN > Typecmd ENTER)
-- If that is blocked, try (START > RUN > Type command.com ENTER)

Let us know and we'll have a whack at this.

Cheers :)
PP

PhilliePhan
Central Scrutinizer
Moderator
1,942 posts since Dec 2006
Reputation Points: 184
Solved Threads: 110
 

I also have a problem like this....i can see my desktop and transfer my files (except outlook) over to my flashdrive, so i got my files...for the most part...saved. Whenever I try and click on ANY program, it says "Application cannot be exeduted. The file (insert file name here).exe is infected. Do you want to activate your antivirus software now?" No matter what I hit yes or no, the same thing pops up and the my (or so it like like my) antivirus "ATTENTION! SPYWARE ALERT...Vulnerailites found"

Any suggestions??

Thanks in advance :)
e

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

I also have a problem like this....i can see my desktop and transfer my files (except outlook) over to my flashdrive, so i got my files...for the most part...saved. Whenever I try and click on ANY program, it says "Application cannot be exeduted. The file (insert file name here).exe is infected. Do you want to activate your antivirus software now?" No matter what I hit yes or no, the same thing pops up and the my (or so it like like my) antivirus "ATTENTION! SPYWARE ALERT...Vulnerailites found"

Any suggestions??

Thanks in advance :)
e




Oh and I have no idea what you are talking about doing with the first 2 things you suggested. Once I boot in safe mode (if I can) what do I do from there?

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

Follow the steps here and post back with the requested logs

http://www.daniweb.com/forums/thread134865.html

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

I would love to be able to do any of that, but I cant do anything on my laptop. I am on my work laptop right now. I can't get to anything to download anything and my work computer will not allow me to download, so I can't transfer anything from my flashdrive to my 'bad' laptop.

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

even when i reboot in safe mode with networking, it still does not let me on the internet.. "The proxy server is refusing connections"

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

Unless you have access to another computer that can get online to get these needed tools then there isn't much that can be done.

ARE you actually using a proxy server? If not these may have been changed by the infection.
Check these settings on the infected computer, go to Control Panel, Internet Options, Connection Tab, LAN button. Make sure there is NO check mark in Use Proxy Server. Then try to get online.

I also have some advice concerning that flash drive you have used to move items from the infected computer, there would be a very good chance that you have also moved infected files to that flash drive so don't insert it into any other computer without fully scanning it or else you could likely infect another computer.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

OH NO!! I didnt even think about my flash drive!!!!! IF I can get back on my computer (it is running a virus scan now) and do the provided steps, will it just walk me through what I need to do? OR if I can get to a computer and go to the provided steps, what do I do? Just dowload it on my flash and then when I get back to my infected computer insert the flash and then what?

Sorry to be so unknowledgeable when it comes to this stuff....I am just WAY out of my element!!!

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

Calm down, the steps are easy to do. They are all very simple as long as you take your time and read everything. Be sure to scan that flash drive before using it again. OR get another clean one to use for the removal programs and worry about the infected one later. Just don't use it until you are 100% certain that it is completely free of any infected files, chances are that it is NOT clean.

The tools, steps and how to do each are listing in full on the sticky. The programs themselves do no walk you through the steps, they are on the sticky so print it out if needed.Or read it from another computer as you do the steps on the infected one.

http://www.daniweb.com/forums/thread134865.html

You download the tools and save them to the flash drive. Then insert the flash drive into the infected computer. Open the flash drive and move the tools from the flash drive to the computer. Install and run each tool. Save each log. Post back here with the logs.

With MBA-M it will need to be updated if possible. Then when you run the scan run a Full Scan. When it's finished it will show you in a box every bad file found in red. Make sure there are check marks next to each and then click the Clean/Quarantine box. Reboot the computer, that is very important.

Then go to the MBA-M program, click the Logs tab and open that bottom log. Copy/Paste it back here along with all the other logs.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

shewww! okay, that sounds easy enough. I will try to get on my internet after the scan finishes...which btw it is at 95% and still has not found anything. I have McAfee and I did the "run through every file" option. But I will say that the entire time, the same boxes keep popping up saying that "Application cannot be executed. The file werfault.exe is infected. Do you want to activate your antivirus software now?" I click no and there is the box behind it saying "ATTENTION! SPYWARE ALERT" and then 2 options at the bottom saying "Activate your spwyare software now" and "Stay unprotected". I have had to click the "stay unprotected" a few times to see if my scan was still running and where it was.

Thanks again JHolland :)

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

werfault.exe is the Windows Error Reporting. Allow this scan to finish and then try the other steps. There may be one additional file you will need but try the steps I gave first about the flash drive and see if you can do them. If you can't let me know.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

okay, it is in the process right now...as soon as it finishes, I will let you know :)

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

oh and i didn't do anything with the first step...maybe i should have asked about this first before continuing on. But i have no idea with a peer 2 peer program is....what is a p2p or how can i find if i have them?

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

P2P are file sharing programs like Limewire, iTorrent, BitTorrent, Frostwire. Anything like those, there are many of them, too many to list here. They are used to usually download music illegally instead of paying for it from a legitimate site like iTunes. With P2P programs you get these types of things from a person you don't know and those very often contain infections.
If you have downloaded music from anywhere without paying for it, these would be current songs, then delete the songs.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

it's doing the step 5 right now....Microsoft® Windows® Malicious Software Removal Tool

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

oh okay...i don't have any of those :)

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

okay it wouldnt let me do the GMER rootkit scanner...my screen went blue and shut down. I continued on to the MBA and it is working on it, so far 2 files found.

I have my DDS and the attach files, they are so huge, do i need to put them both on here?

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

Don't worry about the GMER problem. Many people have difficulties with it. Just continue on.
Add this to your list to do after the MBA-M scan is complete and you have it remove all and reboot:

IF you can get online with the infected computer. If not then that's fine.
Run the ESET Online Scanner

http://www.eset.com/onlinescan/scanner.php?i_agree=14
* You will need to allow an Active X to be installed in order to run it so be sure to do that.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt.
Once that is finished then post back here with all the logs.

jholland1964
Posting Expert
Moderator
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
 

YAY!!! I think everything has worked so far :) After I rebooted from the last step, my computer started up just fine and got on the internet and everything!!!!!!!!!!!!!! I am running the ESET download now. With everything working correctly do I need to still post all the files or can I just leave you alone now ;)

I do have a question about my flash drive though...do I need to just chunk it? Although I might have a file that I need on one of them...how do I get this off without infecting my computer again? I know you have said to run a scan before, but how do I do that if it doesn't give me that option when I insert it?

jholland...thank you so much! I wish I had your address so I could send you a thank you card and cookies :)

eharv
Junior Poster in Training
71 posts since Dec 2010
Reputation Points: 10
Solved Threads: 0
 

This article has been dead for over three months

Post: Markdown Syntax: Formatting Help
You
View similar articles that have also been tagged: