| Author |
Message |
|
miles724
Alpha
Joined: Wed Nov 25, 2009 4:23 am Posts: 35
|
 windows 7 virus
the other day i was looking through my registry cuz my computer was acting funny and i noteced one registry that said "IToolBarUrlSearchHook". then i went through my mom vista home premium computer and i just came up with a regular binary code. and i was wondering how to change it. it also takes about 15 to 20 minuites o find a wireless signal. i have ran malware bires super anti spyware windows defender norton 360 and avira anti vir and all but noton come up that i has a virus but none will remove it and i dont have money to bay 90 bucks for a clean up.
_________________ If you can touch my doberman you can have her.
|
| Sat Jan 23, 2010 6:03 pm |
|
 |
|
Ap0stle
Alpha
Joined: Thu Mar 27, 2008 7:00 pm Posts: 46 Location: USA
|
This may help. http://vil.nai.com/vil/content/v_196772.htmOr try Google. Or try punctuating posts.
|
| Sun Jan 24, 2010 7:42 pm |
|
 |
|
Psychoticus
Chi
Joined: Thu Oct 09, 2008 8:59 pm Posts: 388 Location: Dubbo, NSW, Australia
|
Checked out a couple of forums and talked with some friends of mine and basically the conclusion is that the easiest path is to just format, it's a trojan and used to gain access to and user your computer as a zombie, you can try to remove it manually (dont think any AV can completely remove it), from what i can see it normally refers to the programs c:\windows\inf\other.exe and c:\windows\system32\config\win.exe, remove them and find where in the registry they're being called from and that should start to clean the problem http://www.malwarebytes.org/forums/inde ... topic=9260http://www.bleepingcomputer.com/forums/ ... 34287.html
|
| Mon Jan 25, 2010 1:18 am |
|
 |
|
miles724
Alpha
Joined: Wed Nov 25, 2009 4:23 am Posts: 35
|
well. that is some plain shitty news! but thank you for all the help. once i can get some of the win 7 disk i will reformat my drive and reinstall windows.
|
| Sat Jan 30, 2010 12:18 am |
|
 |
|
LostBrilliance
Moderator
Joined: Mon Jul 09, 2007 8:35 pm Posts: 816 Location: Obscure locale.
|
The string "IToolBarUrlSearchHook" according to ThreatExpert belongs to a type of adware referred to as "Maxifiles" or by Symantec as "MaxSearch". You can find detailed removal instructions for that particular infection here: http://www.symantec.com/security_respon ... 99&tabid=3This is likely the least of your concerns by now though. If you'd prefer avoiding reformatting (shit lazy solution!), I'd recommend running a comprehensive set of tools to ensure there are no other infections. Starting from usermode, I'd suggest tools like Spybot Search & Destroy, Malwarebytes Anti-Malware, Hijack-This, a thorough scan with a reputable AntiVirus application (Antivir or Avast work just fine) and the installation of a decent firewall (Comodo Personal Firewall works great). Once you've gone through that hassle, I'd recommend running a kernelmode rootkit detection tool; I've been having a lot of fun with RootRepeal lately. You can often google the results given from any of these programs and find forum threads, blogs or articles explaining what they are and whether or not you should do something about them. Or, you know, you could just reformat.
|
| Sat Jan 30, 2010 2:36 am |
|
 |
|
Psychoticus
Chi
Joined: Thu Oct 09, 2008 8:59 pm Posts: 388 Location: Dubbo, NSW, Australia
|
LostBrilliance wrote: If you'd prefer avoiding reformatting (shit lazy solution!) I only suggested because i wasn't sure on what level miles is on and i did give him a start point to work from if he wanted to remove them manually, also just to let miles and anyone else who wants to know, one of your best friends while removing virii and malware from your machine is process explorer, seriously it helps remove those that for example malware cant remove because the process is currently open (a lot use svchost as a mask) If anyone would like my process for removing just let me know and i'll post but each and every virii is different and will require a slightly different method
|
| Sun Jan 31, 2010 7:37 pm |
|
 |
|
LostBrilliance
Moderator
Joined: Mon Jul 09, 2007 8:35 pm Posts: 816 Location: Obscure locale.
|
ProcessExplorer is another tool from SysInternals and is indeed an excellent alternative to TaskManager. It does have shortcomings however. A proper rootkit detection tool is a must.
You're absolutely right that each infection takes different steps to remove. I didn't mean to step on your toes by calling the solution lazy. ;D
|
| Sun Jan 31, 2010 9:45 pm |
|
 |
|
Psychoticus
Chi
Joined: Thu Oct 09, 2008 8:59 pm Posts: 388 Location: Dubbo, NSW, Australia
|
Nah all good mate, being in the computer repair business though it's just not economically viable to remove every virii from every machine
Last edited by Psychoticus on Mon Feb 01, 2010 2:30 am, edited 1 time in total.
|
| Mon Feb 01, 2010 12:18 am |
|
 |
|
LostBrilliance
Moderator
Joined: Mon Jul 09, 2007 8:35 pm Posts: 816 Location: Obscure locale.
|
At the rates you people charge?! ;D
Also, wut @ quote?
|
| Mon Feb 01, 2010 1:21 am |
|
 |
|
Psychoticus
Chi
Joined: Thu Oct 09, 2008 8:59 pm Posts: 388 Location: Dubbo, NSW, Australia
|
 Re:
LostBrilliance wrote: At the rates you people charge?! ;D
Also, wut @ quote? Haha yeah must have pasted the wrong thing XD Yeah about $130p/h, that would soon run up a bit of a bill
_________________ Sine labore nihil There's nothing exciting about anti-virus software, but just like toilet paper it's extremely useful. When I'm Sad I Just Stop Being Sad And Be Awesome Instead. True Story!
|
| Mon Feb 01, 2010 2:27 am |
|
 |
|
miles724
Alpha
Joined: Wed Nov 25, 2009 4:23 am Posts: 35
|
well im not that great with computers yet. i can do some things. but im going to do some programming and coding classes.
|
| Mon Feb 01, 2010 3:26 pm |
|
|