HELP VIRUS

Discussion in 'Computer Software and Operating Systems' started by Ace Gunman, Sep 21, 2008.

Sep 21, 2008

HELP VIRUS by Ace Gunman at 9:26 AM (3,087 Views / 0 Likes) 36 replies

  1. Ace Gunman
    OP

    Former Staff Ace Gunman ~••Lucky҉Shot••~

    Joined:
    Apr 17, 2003
    Messages:
    6,385
    Location:
    Wassamatta U
    Country:
    Canada
    I need serious help. I'll update in a moment. There's a virus on my PC and it's causing havok.
     


  2. Ace Gunman
    OP

    Former Staff Ace Gunman ~••Lucky҉Shot••~

    Joined:
    Apr 17, 2003
    Messages:
    6,385
    Location:
    Wassamatta U
    Country:
    Canada
    Okay, whatever it is had installed at least two .exe files. gNdu.exe and lWqs.exe. It keeps blue screening me, killing my antiviruses and anti-spyware programs and it has replaced my background with a fake virus message.

    EDIT: I think it's cancelling out my searches on the matter as well.
     
  3. JPH

    Banned JPH Banned

    Joined:
    Jul 11, 2006
    Messages:
    6,892
    Country:
    United States
    Assuming you're running Windows...

    Reboot your computer and run in Safe Mode or Last Known Good Configuration.
     
  4. Dominator

    Member Dominator the world end without you

    Joined:
    May 9, 2007
    Messages:
    696
    Location:
    Not on the earth
    Country:
    France
    ok ok calm down, reboot in safe mod, delete suspcious programme and restore to yesterday for example
     
  5. Ace Gunman
    OP

    Former Staff Ace Gunman ~••Lucky҉Shot••~

    Joined:
    Apr 17, 2003
    Messages:
    6,385
    Location:
    Wassamatta U
    Country:
    Canada
    Will do, one moment. I wouldn't have usually come to GBAtemp for help and would have dealt with it by myself, but, yeah. The whole search blocking thing lol
     
  6. hankchill

    Member hankchill I Pwn n00bs.

    Joined:
    Nov 5, 2005
    Messages:
    2,344
    Location:
    Outer Space
    Country:
    Canada
    You could toss it and buy a Mac? hyuk hyuk [​IMG] I kid.
     
  7. Urza

    Member Urza hi

    Joined:
    Jul 18, 2007
    Messages:
    6,493
    Country:
    United States
    He could keep it and install OSX86, saving hundreds of dollars on overpriced hardware? hyuk hyuk [​IMG] I kid.







    (not really)
     
  8. Dack

    Member Dack GBAtemp Advanced Fan

    Joined:
    Aug 26, 2007
    Messages:
    603
    Location:
    UK
    Country:
    United Kingdom
  9. Mr. Waffle

    Member Mr. Waffle A Free Waffle

    Joined:
    Jul 2, 2008
    Messages:
    250
    Country:
    Netherlands
    Try Hitman Pro?
     
  10. Ace Gunman
    OP

    Former Staff Ace Gunman ~••Lucky҉Shot••~

    Joined:
    Apr 17, 2003
    Messages:
    6,385
    Location:
    Wassamatta U
    Country:
    Canada
    Ok guys, this is bad. Very, very bad. It won't even delete it in safe mode. It blue screened me there too.

    EDIT: Oh, and there's another file. lphc395j0ee2a.exe
     
  11. Sinkhead

    Former Staff Sinkhead yay p1ngpong.

    Joined:
    Nov 22, 2006
    Messages:
    3,692
    Location:
    Across the pond
    Country:
    United Kingdom
    My mate's dad got this virus and I spent a day there (I wasn't dragging the job out so I could stay at his house for BBQ chicken tea, honestly!) and couldn't fix it. I tried literally everything, and I took my laptop as well so I could search.

    The virus in question was the 'Antivirus 2008/9' mentioned by Dack above. Have you already tried his advice?
     
  12. Trolly

    Member Trolly GBAtemp Advanced Maniac

    Joined:
    Sep 14, 2007
    Messages:
    1,720
    Location:
    Behind you! I know you looked!
    Country:
    United Kingdom
    Well, if it keeps on blue screening and doing in your anti-virus programs, just back up the safe stuff on an external hard drive or USB stick as quickly as you can, then re-format your hard drive and re-install Windows. Will save you ages of faffing about, I guarantee.
     
  13. Mazor

    Member Mazor Z80 master arch

    Joined:
    Feb 14, 2008
    Messages:
    547
    Country:
    Sweden
    Linux live cd.
     
  14. omatic

    Member omatic GBAtemp Fan

    Joined:
    Apr 25, 2007
    Messages:
    408
    Location:
    United States
    Country:
    United States
    This sounds somewhat complicated, and I don't know if you'll be able to pull it off in time, but if you download an ISO distribution of Ubuntu Linux (there is one found here), and set your BIOS to boot from CD first, you can boot in Ubuntu, access your C: drive (or whatever drive it is), and delete the files. That's how I solved my last uber-virus hostile takeover.

    Edit: Aw man, Mazor beat me to it while I was typing.
     
  15. Ace Gunman
    OP

    Former Staff Ace Gunman ~••Lucky҉Shot••~

    Joined:
    Apr 17, 2003
    Messages:
    6,385
    Location:
    Wassamatta U
    Country:
    Canada
    This isn't a possibility for me. I don't have an external drive or USB stick, I've never re-formatted my harddrive before, and I can't re-install Windows as I have no idea where the disc is (or if my PC even came with it to begin with).

    The odd thing is, I don't know how I got this. All I was doing at the time of infection was visiting IGN and talking to someone on MSN.
     
  16. Athlon-pv

    Member Athlon-pv GBAtemp Advanced Fan

    Joined:
    Feb 25, 2005
    Messages:
    621
    Country:
    United States
    sometimes renaming a virus can kill it as well usually it gets called someplace by the exact filename , the only exception is when you rename the wrong file some keep creating random filenames.

    i think you can use MSconfig to check your registry for which files are starting, i use spybot for this tho ....

    And see if you can startup from something like a floppydisk that is if you have a fat32 partition [​IMG]. If not the linux live cd makes sense....
     
  17. DarkRey

    Member DarkRey still transfoooorming.... with sum lags!

    Joined:
    Mar 9, 2007
    Messages:
    983
    Location:
    Rotating around Toni
    Country:
    Croatia
  18. Ace Gunman
    OP

    Former Staff Ace Gunman ~••Lucky҉Shot••~

    Joined:
    Apr 17, 2003
    Messages:
    6,385
    Location:
    Wassamatta U
    Country:
    Canada
    I'm off to try the malwarebytes link program. I'll be back if things continue to go down hill. Oh, question. Can this be installed in safe mode?
     
  19. Dack

    Member Dack GBAtemp Advanced Fan

    Joined:
    Aug 26, 2007
    Messages:
    603
    Location:
    UK
    Country:
    United Kingdom
    It would be a bit pointless as the virus runs in safe mode anyways. [​IMG]

    To manually remove it is a complete pain - it attaches itself to explorer.exe etc.

    The malwarebytes program will fix it.

    The way I got this virus a few weeks ago was due to a drive by download from a flash advert on a website - it's a bug in adobe thats being utilised.
     
  20. sconethief

    Member sconethief GBAtemp Regular

    Joined:
    Jul 10, 2008
    Messages:
    153
    Location:
    USA
    Country:
    United States
    NUKE IT NUKE IT NUKE IT!!!!!!!
    [​IMG] that's all i can think of, is for you to format the HDD try and get important files off your comp first D :
     

Share This Page