Jump to content

Malwarebytes

Weirdest Virus I've ever seen

- - - - -

15 replies to this topic

#1
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
This virus/trojan/whatever pops up as soon as Windows (XP) boots and shows a bunch of multi-colored boxes in boxes and rectangles and whatever. When booting to safe mode, the screen just stays black and no safe mode is booted.

How can mbam defeat this?

Can anyone name this virus? That would be a very helpful start...

Pictures will be coming soon. Feel free to ask any questions that may help

#2
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
Attached File  Matt_s_Virus.JPG   51.11K   39 downloads

#3
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Don't know, never seen or heard of it myself but if you can't get on and run Anti-Virus tools then please start by downloading and burning this from a friends computer or work computer if you need to and then run it on the box.


Avira AntiVir Rescue System
[indent]Requires access to a working computer with a CD/DVD burner to create a bootable CD.
  • Download the Avira AntiVir Rescue System from here
  • Place a blank CD in your burner and double-click on the downloaded file.
  • The program will automatically burn the CD for you.
  • Place the burned CD into the affected computer and start the computer from this CD.
  • On the bottom left side of the screen there are 2 flags. Using your mouse click on the British flag to use English.
  • Click on the Configuration button.
    • Select Scan all files
    • Select Try to repair infected files and Rename files, if they cannot be removed
    • Select Scan for dialers
    • Select Scan for joke programs (Jokes)
    • Select Scan for games
    • Select Scan for spyware (SPR)
  • Click on Virus scanner
  • Click on Start scanner at the bottom of the screen
  • Currently the program does not support saving a log. Write down the amount of items for Records, Suspect files, and Warnings
The Avira AntiVir Rescue System is a Linux-based application that allows accessing computers that cannot be booted anymore and is updated several times a day so that the most recent security updates are always available.

Screen resolution problems
Please see the post here if you're unable to view the entire screen of Avira.[/indent]
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#4
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
Hey, I tried doing this but I was unable to boot Windows to the CD.

Could you please expand your directions as to be very detailed and include every click? I'm sorry to make it difficult on you, but I have no prior knowledge of doing this. My CD drive is the D: drive, and do I have to reformat the disk too or something?

Sorry...

#5
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
You need a blank CD that is writable/burnable and place it in your CD or CD burner. If you don't have one then it won't work.
If you're unable to run this then you'll need to see if maybe a friend can do it for you or if you can do it from a Work computer.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#6
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
Well you see, I used a DVD and told it to burn to the DVD. It said it had problems with some .key file and finished. But whenever I try to boot it to the DVD, it just boots up like regular.

Do I need to move around the files or something?

#7
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
You may have to press a key combination to get to a boot menu or go into your BIOS setup and change it so that CD is set to boot first.

Different computers use different keys to run the menu though. ESC, F1, F2, F10 are common keys to use during the bootup process to get either into the BIOS or another Start Menu.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#8
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
Well I pressed F8 on my computer and it really didn't work...I can try again but I'm not sure it will work.

Do you think that error had to do with it at all?

#9
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
NOT F8 that is for Windows menu that includes SAFE MODE.

What make and model computer do you have? Do you have a friend close by that might know a bit more about computers that could assist you.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#10
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
Well, I know a lot about computers, but my knowledge is very limited in this case of booting windows to a CD or Flash Drive.

I have a Dell Demension 8300. I've even tried going into Setup and setting the boot order to run the CD-ROM first.

I am still quite unconvinced that the problem does not lie with the error that I received while finishing the installation, or with the CD itself. Could you please verify if my suspicions are correct?

#11
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Well it very well could be the CD/DVD was not created properly as you say. If you have any other CD/DVD that are bootable to test, then if they boot you know for sure that the CD/DVD was not written properly. You may need to try to download and burn from another PC.

It should boot from it with no problems. There have been other problems due to screen resolution reported but not non booting issues.
So yes your suspicion would seem to be correct that the CD was not burned properly for some reason.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#12
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
Okay, so to troubleshoot why it is not working, I will list exactly what I did

1. Put TDK DVD+R 1-16X 4.7GB RW disk into burnable drive
2. Right click D: drive
3. Click Format (Sonic DLA)
4. Volume Label: Avira AntiVir Personal
5. Format Type Quick (erase)
6. Click Start
7. All media will be lost (clicked yes)
8. Format Complete (clicked yes)
9. Double-Click on antivir_workstation_winu_en_h.exe
10. Clicked Accept
11. Watched files extract
12. Welcome to setup (clicked next)
13. Clicked next
14. Clicked "I accept" and next
15. Clicked "I accept" and next
16. Clicked Custom and next
17. Clicked Browse
18. Clicked D: Drive and OK
19. Clicked Next
20. Clicked Next
21. Clicked Next
22. Clicked next
23. Unchecked Create a program group in the Start Menu
24. Clicked Next
25. Unchecked both yes boxes
26. Clicked Next
27. Started to Install
28. Error: The file could not be copied. Error code: 2 C:\Documents and Settings\All Users\Application

Data\Avira\AntiVir PeronsalEdition Classic\TEMP\hbedv.key
29. Clicked OK
30. Watched it install and start components and finish installation
31. Clicked Finish
32. Popup: Do you want to start an update now?
33. Clicked Yes
34. Clicked OK on ad popup
35. Free Antivirus Updater finished
36. Clicked Start>Shutdown
37. Clicked F12 rapidly
38. Navigated to IDE CD-ROM
39. Nothing happened and here I am!

#13
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Well I think that is the issue right there with the file name. That is NOT the file I asked you to download.

The file name you should be downloading and using from the link in my instruction is: rescuecd.exe

http://www.free-av.com/en/tools/12/avira_antivir_rescue_system.html


Try that one which is about 50MB in size and see how that works.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#14
Starblaster1234

    New Member

  • Members
  • Pip
  • 26 posts
That would explain a lot, thank you sir :(

I'll post back with more info.

Thanks for taking your time to help me out

#15
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Great. Let us know how it goes please.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#16
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us