Virus help

The machines we love to hate

Moderator: Wiz Feinberg

Charles French
Posts: 394
Joined: 9 Jun 2003 12:01 am
Location: Ms.

Virus help

Post by Charles French »

Housecall found these 2 - TROJ_APROPO.B - TROJ_AGENT.BE. They are in my "Restore/Temp files"

The instructions were to disable system restore and restart in safe mode and then run scan again. My problem is my computer locks up when the desktop loads.

This is driving me crazy. How can I get rid of these pesk?
Charles French
Posts: 394
Joined: 9 Jun 2003 12:01 am
Location: Ms.

Post by Charles French »

These are very nasty!! I did try to restore my system to an earlier date but I noticed I have no restore points . I checked the size of my restore and it was at maximum. I reduced it to 200mb the minimum and now I'm just trying to run a thorough disc scan. I tried to run disc scan over the weekend but it would not run. I got a message saying it had restarted 10 times. I found this article on microsoft about the problem. http://support.microsoft.com/kb/q263455/

Housecall showed me where the virus were located. I disabled System restore and rescanned but in doing this it dosen't scan the Restore/Temp files. There should be a way to manually delete these. If I could only find someone to walk me through the process.

We have only one computer tech in our town and I've had bad experiences with them. I was hoping to avoid taking the computer to them.

I've been wanting to change my OS. What's weird is I can buy a whole new computer for almost what it will cost to backup my files and upgrade my OS.
Ron !
Posts: 3860
Joined: 11 Aug 2004 12:01 am

Post by Ron ! »

Charles.

What scanner do you have?
I run my system with AVG and Bullguard.Also a nice scanner thats free and finds many Trojans is Panda.
I would look on the internet and find these three and run them on your system.I think that at least one of them will help you with this problem.

Ron

------------------
Nikaro SD10 4x6 ,Nikaro SD10 4x5,2 Peavey Ultratube 112

European Steel Guitar Forum

Charles French
Posts: 394
Joined: 9 Jun 2003 12:01 am
Location: Ms.

Post by Charles French »

I use Trend Micro, but the problem isn't with the scanner. No scanner will remove viruses in the Restore/Temp files. There's a work around by disabling System Restore but I can't seem to get this to work.
Ray Riley
Posts: 589
Joined: 17 Dec 2004 1:01 am
Location: Des Moines, Iowa, USA

Post by Ray Riley »

Charles, Try this. Go to start menu, go to run, type in temporary files. It should get you there to delete them. Be careful cause some could be your operating files. Ray I'm no expert, I usually call the wife!!!!!!!!!!!!!!!
User avatar
Mark Ardito
Posts: 899
Joined: 9 Aug 1999 12:01 am
Location: Chicago, IL, USA

Post by Mark Ardito »

Charles,

Do you have Windows XP or Windows ME? The system restore was only offered on those two Operating Systems.

I have no idea what this virus is, but here is how I would go about this.

Windows XP:
1. Right-Click your "My Computer" icon and scroll down to PROPERTIES.
2. Click on the "System Restore" tab.
3. Put the check mark in the box "Turn off system restore".


Windows ME:
1. Start Menu -> Settings -> Control Panel
2. Double click the "SYSTEM" icon.
3. Click on the "PERFORMANCE" tab
4. Click on the FILE SYSTEM button near the bottom of dialog box.
5. Click on the "TROUBLESHOOTING" tab (the last one)
6. Put the check mark in the box "Disable System Restore".

OK....now that you have disabled your system restore, I would reboot Windows.

*** IMPORTANT ***
HOLD DOWN THE SHIFT KEY WHILE WINDOWS IS LOADING

Holding down the shift key will terminate any application that is trying to run during Windows boot. If the virus is trying to run on boot up you will never remove it because it is always running.

OK...now with system restore disabled and a reboot of windows with the shift key held down....go ahead and run a virus scan.

DELETE or QUARENTINE all instances of your virus.

Then reboot and rescan.

If no sign of virus, then turn back on your system restore.

Please let me know if you need any additional help and I will be glad to help out. However, I must warn you that I am super busy and only check into the forum every couple of days. So if you post a question for me I may not see it for a day or two. You can also try emailing me directly if you like.

Cheers!
Mark


------------------
Sho~Bud Pro I, Fender D-8 (C6&E13) http://www.darkmagneto.com
http://www.arditotech.com

Charles French
Posts: 394
Joined: 9 Jun 2003 12:01 am
Location: Ms.

Post by Charles French »

Thanks Mark, I had already tried your suggestion beforehand. Here's what I've done.

"ME" is my cursed OS.

The fix according to Microsoft & MajorGeeks was disable system restore and restart in safe mode and then run virus scan again and I would be able to clean and delete the virus. My problem is my computer locks up when the desktop loads in safe mode. So I tried the above without starting in safe mode. The next problem is the virus scan dosen't scan my RESTORE/TEMP Files, when I disable system restore, thus it finds no viruses.

I was using AVG when I got infected. In an effort to find an AV that would remove these viruses, I downloaded several trial AV's. Bit-Defender, Pc-cillin and lastly Norton which has turned out to be worse than the virus's I'm infected with.

I tried to uninstall Norton and could not uninstall all the components. So next I tried to search and manually remove anything associated with Norton. I found a few Norton files & deleted these, but I know there's many I'm not finding that show up if I run Trend Micro Housecall scan.

Final Chapter---> Since I've deleted all my trial AV's. I decided to give Panda a try. Panda won't install because it says the Norton files on my computer are conflicting and to remove these.

So I check my Add/Remove files in the control Panel and there's no Norton program there. So I searched files again and found 4 Norton files and manually deleted with the exception of One that wouldn't delete. Recycle bin says the file cannot be deleted. I restart my computer and go back to Recycle bin and this time it deleted the file.

Here's the good part. I click on Control Panel and everything has disappered, gone, nothing there. It says 33 objects at the bottom of the screen but I have only a blank page. Now I can't access my system setting, Add/Remove or anything else. Panda still won't install, it says to remove Norton. I can't remove something I can't find or see. I have no Restore Points in system restore.

Any suggestions, or would this computer make a good boat anchor at this point?

One more question. Could I do a clean install and upgrade to XP Professional.Would the current virus's conflict with this?
User avatar
Mark Ardito
Posts: 899
Joined: 9 Aug 1999 12:01 am
Location: Chicago, IL, USA

Post by Mark Ardito »

Charles,

At this point I would go ahead and do a "clean" install of Windows XP. There are so many things that need to be fixed with your machine right now that it would be just easier to backup and grab everything you need off your current ME operating system and then do the upgrade. However, when you do the upgrade, please choose the "clean instal" and have it format your machine.

WARNING..this clean install/format will wipe out your machine. This means ALL programs will need to be installed again. So before doing this, make sure you have all of your CD's for the applications. Also this will wipe out all of your files (ie pictures, mp3's, Word documents, Excel spreadsheet and etc.) Make sure you have saved on a CD or floppy disk all of the files you want to keep.

Best of luck!

Cheers!
Mark



------------------
Sho~Bud Pro I, Fender D-8 (C6&E13) http://www.darkmagneto.com
http://www.arditotech.com

Charles French
Posts: 394
Joined: 9 Jun 2003 12:01 am
Location: Ms.

Post by Charles French »

K, I solved my problem. I'm getting a new machine, cleaning the old one out and giving it to my son.


Dimension 8400 Series, Intel Pentium 4 Processor 640 (3.20GHz 800 FSB)w/HT Technology and 2MB cache

1GB DDR2 SDRAM at 533MHz

17 in (17.0 in viewable) 1704FPt Digital Flat Panel Display

128MB PCI Express x16 (DVI/VGA/TV-out) ATI Radeon X300 SE

160GB NCQ Serial ATA Hard Drive (7200 RPM)

Microsoft Windows XP Media Center Edition 2005

16X DVD+/-RW Drive w/dbl layer write

Sound Blaster Audigy 2 ZS, PCIw/Dolby Digital EX, IEEE1394, 7.1 channel, THX cert

Dell 5650 5.1 Surround Sound Speakers System with Subwoofer.

I just wish they offered the Audigy Platinum sound card and I could have afforded more memory, like 2GB!
User avatar
Mark Ardito
Posts: 899
Joined: 9 Aug 1999 12:01 am
Location: Chicago, IL, USA

Post by Mark Ardito »

Charles,

Your new machine sounds great! I just purchased all of my parts and have started putting together my new PC. I have found this place called Tiger Direct http://www.tigerdirect.com that has just about THE best prices on computer parts. I purchased all of my parts for a SMOKIN' pc for just under $400. Can't beat that!

Cheers!
Mark


------------------
Sho~Bud Pro I, Fender D-8 (C6&E13) http://www.darkmagneto.com
http://www.arditotech.com

<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Mark Ardito on 03 March 2005 at 07:04 AM.]</p></FONT><FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Mark Ardito on 03 March 2005 at 07:05 AM.]</p></FONT>
Charles French
Posts: 394
Joined: 9 Jun 2003 12:01 am
Location: Ms.

Post by Charles French »

Mark, I kept saying I was going to do that myself, but! Low funds! So I charged it. I'm sure you can piece together a monster machine for 1/3 of the cost of buying. Plus get exactly the components you want. As in my case, Dell didn't have an option for the sound card I wanted. Had to cut back on my processor to get the 1GB. They are targeting the gamers and have no option for home recording.

Maybe one day I can build a system exclusively for video editing and home recording. Yeah that would be great.