We're aware that some users are experiencing technical issues which the team are working to resolve. See the Community Noticeboard for more info. Thank you for your patience.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Virus on Computer

Options
123457

Comments

  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ok ive downloaded F-Secure virus checker and it seems to be throwing up things left right and centre so far its found:

    Trojan.win32.bho.bb

    Risktool.win32.pskill

    and it hasnt even finished its scan yet :eek:

    Although happily it has dealt with those two so far :)
    Savings Total so far for 2023: £8,062.58
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    skiddy2k wrote: »
    try to download Kaspersky v7 (unreleased), hopefully the malware on your PC wont detect it... ftp://kav2006:Fynb02dbhec60@data.kaspersky.com/7.0.0.125/KIS/English/2007_06_28_12_33/kis.en.msi
    also make sure "enable self-defense before instalation" is enabled/ticked... do an update, restart PC into SafeMode and scan from there. Set the Scan level of the MyComputer scan to "Max" and in the HeuristicAnalyzer tab, tick all the boxes and set heuristic scan level to "Detail"

    (also remember to run the Trial Version)


    Thanks skiddy2k im going to let the F-secure can run through and then give urs a go to double check that theres nothing left on there :)

    there may be light at the end of the tunnel !! :T :j:j:j
    Savings Total so far for 2023: £8,062.58
  • skiddy2k
    skiddy2k Posts: 1,627 Forumite
    Also try to download the Avenger: http://swandog46.geekstogo.com/avenger.exe
    save & run it. choose "input script manually", click on the Magnifier and input the following:
    Files to delete:
    C:\HIBERFIL.SYS
    C:\PAGEFILE.SYS
    C:\WINDOWS\SYSTEM32\SYSDRV0.EXE
    C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
    C:\DOCUMENTS AND SETTINGS\COMPAQ_OWNER\WN0008.EXE
    C:\DOCUMENTS AND SETTINGS\COMPAQ_OWNER\LOCAL SETTINGS\TEMP\US0008.EXE
    C:\WINDOWS\system32\erhecwjrbgbv.dll
    C:\WINDOWS\system32\prmgkujwhutt.dll
    press Done, and then click the green traffic light, confirm the reboot
  • skiddy2k
    skiddy2k Posts: 1,627 Forumite
    James240 wrote: »
    Thanks skiddy2k im going to let the F-secure can run through and then give urs a go to double check that theres nothing left on there :)

    there may be light at the end of the tunnel !! :T :j:j:j

    Yeh, just take it one step at a time... no point trying all at the same time.
    Looks like a Rootkit you got on the PC, thats why its proving so difficult to remove. Good luck! ;)
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    cheers mate much appreciated :) must admit ive never seen such a hard virus(es) to get rid of :(

    cross fingers F-secure will do the job as well as what you have suggested as well :)
    Savings Total so far for 2023: £8,062.58
  • Rikki
    Rikki Posts: 21,625 Forumite
    Hi James :hello:

    I've been following this thread and I must say I admire your patience. I would have done badday.gif this by now.

    No advice :o , just moral support :cool: and something to briefly make you and your Mum smile. :D

    Hope you get it sorted soon. :)

    .
    £2 Coins Savings Club 2012 is £4 :).............................NCFC member No: 00005.........

    ......................................................................TCNC member No: 00008
    NPFM 21
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    believe me Rikki its come close to it hun lol

    Ive spent sooooo much time looking into this and trying to find out bits myself but as Browntoa pointed out it looks like it may be a newer virus lol

    Im interested in this kinda stuff and how it works and how to remove it but i must admit even this has tested my patient lol
    Savings Total so far for 2023: £8,062.58
  • skiddy2k
    skiddy2k Posts: 1,627 Forumite
    Look on the bright side, you learn about how to remove malicious files this way and can help out people with similar problems in the future. :)... (if you manage to remove it):eek:
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    skiddy2k wrote: »
    Look on the bright side, you learn about how to remove malicious files this way and can help out people with similar problems in the future. :)... (if you manage to remove it):eek:


    yep tis true :)

    I do look at it as a learning curve cos i like to keep me IT knowledge as up to date as poss, and learning how to deal with this would certainly help doing that :)
    Savings Total so far for 2023: £8,062.58
  • James240
    James240 Posts: 16,391 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    just attempting to run Kaspersky v7 now :) it installed this morning ok without anything being shut down so hopefully i will be able to get it to run when :)

    Once its finished ill post the result tos let you know what happened, although i hope it gets solved today cos im not down at me mums for at least another week lol (fingers crossed lol)
    Savings Total so far for 2023: £8,062.58
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351K Banking & Borrowing
  • 253.1K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244K Work, Benefits & Business
  • 598.9K Mortgages, Homes & Bills
  • 176.9K Life & Family
  • 257.3K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.