Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
11/26/2008 1:44:43 PM EDT
I have been jacked by a virus.  It has disabled my ability to edit the registry, open task manager, or do anything to manually locate it.  It also thoughfully turns off the installation of anything to remove it.  It blocks me from loading any anti-virus website.  What do I do now?  Format?  This sux.
11/26/2008 1:48:03 PM EDT
[#1]
Safe mode.
11/26/2008 1:51:21 PM EDT
[#2]
Tannerite.

Apply liberally to hard drive, purchase new hard drive, and pull up your backups.

You DO have backups, don't you?

11/26/2008 1:54:39 PM EDT
[#3]
Quoted:
Tannerite.

Apply liberally to hard drive, purchase new hard drive, and pull up your backups.

You DO have backups, don't you?



Obviously, in a perfect world.  Sadly, I live in one not so awesome.

11/26/2008 1:56:53 PM EDT
[#4]
You can load an AV app in a USB memory stick and run it from the stick.  ClamWin

Try running this from the Web:  Kapersky AntiVirus



11/26/2008 1:59:17 PM EDT
[#5]
Find SDFix It works great.
And easy to.
11/26/2008 2:33:53 PM EDT
[#6]
Safe mode will not load.  Partially loads then reboots.

AV apps WILL NOT INSTALL.  They start, then get interrupted.  

This thing is good.  I am really looking for options besides going nuclear.  I HATE the xp installation process, and in a way it feels like the easy way out.

ETA: everything else runs normally.  No performance issues at all.  I would have had no idea if I had not gone to task manager and been denied.
11/26/2008 2:34:36 PM EDT
[#7]
format c:
11/26/2008 2:38:38 PM EDT
[#8]
Quoted:
Safe mode will not load.  Partially loads then reboots.

AV apps WILL NOT INSTALL.  They start, then get interrupted.  

This thing is good.  I am really looking for options besides going nuclear.  I HATE the xp installation process, and in a way it feels like the easy way out.

ETA: everything else runs normally.  No performance issues at all.  I would have had no idea if I had not gone to task manager and been denied.


Seriously:   Get an app from the MS "Sysinternals" site called "autoruns" –– it may let you disable whatever startup object is catching the virus.   Since the virus is trying to keep you from the registry ( a pretty blunt hack), that must mean that it is starting as a "run" item under the startups.    And while it may be capturing MSCONFIG runs, you may be able to use the Autoruns app as its less likely to be testing for it.

11/26/2008 2:41:00 PM EDT
[#9]
Quoted:
I have been jacked by a virus.  It has disabled my ability to edit the registry, open task manager, or do anything to manually locate it.  It also thoughfully turns off the installation of anything to remove it.  It blocks me from loading any anti-virus website.  What do I do now?  Format?  This sux.



You know you're truly fucked when it turns off system restore points.
That one go me earlier this year.
If I ever catch one of these virus writing mother fuckers you'll see me in cuffs on National news.

11/26/2008 2:41:32 PM EDT
[#10]
Quoted:
Quoted:
Safe mode will not load.  Partially loads then reboots.

AV apps WILL NOT INSTALL.  They start, then get interrupted.  

This thing is good.  I am really looking for options besides going nuclear.  I HATE the xp installation process, and in a way it feels like the easy way out.

ETA: everything else runs normally.  No performance issues at all.  I would have had no idea if I had not gone to task manager and been denied.


Seriously:   Get an app from the MS "Sysinternals" site called "autoruns" –– it may let you disable whatever startup object is catching the virus.   Since the virus is trying to keep you from the registry ( a pretty blunt hack), that must mean that it is starting as a "run" item under the startups.    And while it may be capturing MSCONFIG runs, you may be able to use the Autoruns app as its less likely to be testing for it.



Good idea. thanks.