Staredit Network > Forums > Technology & Computers > Topic: Goddamn Stubborn Computer Virus
Goddamn Stubborn Computer Virus
Jan 12 2012, 12:08 am
By: TiKels  

Jan 12 2012, 12:08 am TiKels Post #1



There is a virus roaming around. I had kinda taken care of it before, but sadly not entirely. I had help from roy.

The effects in total, including cured and easily curable:

1. Ping.exe and ping6.exe (or was it ping9.exe?) spammed my computer with CPU usage [Fixed]
2. Any .exe I try and run gives me "Choose the program you wish to run this with" [Fixable with Malwarebytes]
3. Any google links I click send me to various ad sites and virusey sites [Still broken]
4. If I turn off the antivirus thing I downloaded (it takes up a shitton of CPU usage) for more than 5 seconds the virus comes back in its entirety except ping.exe
5. Youtube videos continue playing in the background even after I close a tab in firefox. They continue to eat up memory and I have to end the plugincontainer every now and then.

The antivirus I had to download to be able to even run programs is PC Tools Spyware Doctor. Otherwise my computer wouldn't let me do shit iirc.

When I turned off my antivirus's "Intelliguard" a second ago, the Windows XP Security 2012 virus came up again, telling me I was infected (Gasp!). I checked processes to see which one I needed to nuke. The last time the virus came it was some random 3 letter thing like nms.exe, I don't remember exactly. This time it was HGB.exe or HBG.exe. I noticed also a strange process that I hadn't seen before. Sorry I can't be more specific, but it was some BS in all caps with the letters "NOT" in it. Like "NOTTD.exe" or something. Anyway, when the windows XP security 2012 virus finally fully arrived, and I saw the HGB.exe (or HBG.exe... whichever), my antivirus was like "YO DAWG THERE BE A COMPUTER PROGRAM ACTING SUSPICIOUS IN C:\Documents and Settings\Evan\Local Settings\Application Data\HBG.exe

I went there and found it. I went to google. Looked back and the program was gone.

Halp. Roy helped me a little bit through some of this, so he could give some more details.
edat:My goal is to not wipe my computer and still get rid of the virus.

Post has been edited 3 time(s), last time on Jan 12 2012, 1:44 am by TiKels.



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Jan 12 2012, 12:19 am RIVE Post #2

Just Here For The Pie

You can do what I do, and system reset your computer.
Just be sure to back-up all your important files on discs or flashdrives first.
It feels good starting new again every once in awhile!



None.

Jan 12 2012, 12:20 am Tempz Post #3



You've either never completely gotten rid of it or you keep re-infecting yourself... so its best that you get someone better with this stuff to to help you or reboot your computer.



None.

Jan 12 2012, 12:21 am TiKels Post #4



My goal is to not wipe my computer and still get rid of the virus.

Also here's a rundown of what malware bytes just removed.

Collapse Box


Quote
You've either never completely gotten rid of it or you keep re-infecting yourself... so its best that you get someone better with this stuff to to help you or reboot your computer.
I never got rid of it entirely. I didn't say I did. What do you think I'm doing by getting on SEN? I'm getting someone better with this stuff.



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Jan 12 2012, 12:48 am lil-Inferno Post #5

Just here for the pie

Quote from RIVE
You can do what I do, and system reset your computer.
Just be sure to back-up all your important files on discs or flashdrives first.
It feels good starting new again every once in awhile!
Instead of starting completely over he could utilize a system restore point to some time prior to catching the virus.

System Restore FAQ




Jan 12 2012, 1:02 am TiKels Post #6



I did a system restore. I realized soon after that the virus had actually incubated on my computer for several days or weeks. I had ping.exe back on my computer and was almost entirely unable to delete it. I'd rather just kill the virus another way. Going back with system restore removes too much shit.



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Jan 12 2012, 1:08 am BiOAtK Post #7



...you know that malwarebytes took no action on any of those, right...?



None.

Jan 12 2012, 1:16 am TiKels Post #8



Yes, I haven't hit "remove selected" button yet on the scan.

lawl wait, i said removed didn't i
:awesome:



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Jan 12 2012, 1:19 am Mp)HellFire Post #9



I would use some NyQuil and some Norton Antiviral Flu medicine to get rid of that nasty virus you got.

Consider buying a new computer and not visiting those "porn sites" that you use to love to visit.



None.

Jan 12 2012, 1:22 am jjf28 Post #10

Cartography Artisan

I've delt with a couple of these buggers. You may have to restart your computer many times... Read through this before trying it, the key is being fast.

I'm assuming your on windows xp, and the virus has already disabled safe mode (if safe mode works, use it). I'm also assuming you're unable to pull out your harddrive and scan it as a slave drive from another computer, as that would be the elegant way to go.

1. Turn on your comp (if you have to log on, do so). Hold the windows key and hit R, type msconfig, hit enter. Select Diagnostic Startup, hit apply, as soon as the apply button unfreezes, pull out your laptops battery/your computers power cord.

2. Plug your comp back in, startup & login, first priority, get in task manager and kill any procceses except these...
Collapsable Box


3. Load up malwarebytes, don't bother updating for now.

(3.5) If you have the option, start a malwarebytes trial (under the protection tab)

4. Perform a quick scan, remove what comes up, then perform a full scan and remove what that finds.

5. Open up msconfig again, select normal startup (or if you use it, selective startup), restart, and enjoy.



TheNitesWhoSay - Clan Aura - github

Reached the top of StarCraft theory crafting 2:12 AM CST, August 2nd, 2014.

Jan 12 2012, 1:43 am TiKels Post #11



I was able to nip the program a long time ago with some lucky process ending. I can run malwarebytes and can do scans. It fails to find the program, it has spread somewhere where it doesn't find it. Oh I just remembered a 5th symptom of the virus, updating OP.

Essentially, my computer is functional, but slowed down and infected.



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Jan 12 2012, 1:47 am jjf28 Post #12

Cartography Artisan

I consider malwarebytes the best free scanner, but you can try kaspersky or one of these av's



TheNitesWhoSay - Clan Aura - github

Reached the top of StarCraft theory crafting 2:12 AM CST, August 2nd, 2014.

Jan 12 2012, 1:56 am Aristocrat Post #13



Kaspersky got its source code stolen a while back. :P

TiKels: Just nuke your computer. Being lazy will leave you with a computer that's still as slow as before.



None.

Jan 12 2012, 2:00 am DevliN Post #14

OVERWATCH STATUS GO

I had something similar occur. In my Windows folder, I found a few exe files with 4 random letters for names. They would periodically attempt to connect to files on various web addresses, but my NOD32 would block it. I also had an issue where I couldn't open exe files, but I just fixed that with regedit. Ultimately I found and deleted all the 4-letter named files and the issue went away. I have since reformatted my computer and started over, though, so that's helped a lot as well.

I agree wholeheartedly with RIVE on this one. It does feel good starting fresh.



\:devlin\: Currently Working On: \:devlin\:
My Overwatch addiction.

Jan 12 2012, 2:15 am Lanthanide Post #15



Yes, unless you can find instructions on the net somewhere for removing the *specific* virus that you have, you can't ever be sure that you've gotten rid of it completely. It could potentially have a keylogger in there as well and steal your passwords/bank accounts etc.

So unless you can find out the name of this virus and specific tools for removing it, I'd just reformat and start again.



None.

Jan 12 2012, 2:56 am l)ark_ssj9kevin Post #16

Just here for the activity... well not really

I did some speed googling. You should download and use Combofix, perferably in Safe Mode if you can.
(source: http://www.bleepingcomputer.com/forums/topic435494.html note that the person in that thread fixed it January 8, so this guide/virus is pretty recent.)

Or you can just reinstall Windows XP, but that's not fun at all. You'd be surrendering to the virus. You can't let it win.



guy lifting weight (animated smiley):

O-IC
OI-C

"Oh, I see it"


Jan 12 2012, 3:33 am Aristocrat Post #17



Don't run combofix unless someone who knows their shit is helping you as you are running it. ComboFix has the potential to break way more things than it fixes and should be used as a last resort.



None.

Jan 12 2012, 4:26 am TiKels Post #18



The virus is Windows XP Security 2012

I've heard of at least two other people getting the same virus. Random lady in a computer shop and my mother. Do you guys want me to re-get the virus again and just like... zip it and send it to you? Does anyone know how to do anything with it?



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Jan 12 2012, 4:29 am Lanthanide Post #19



You're asking if we want a computer virus. Um, no.



None.

Jan 12 2012, 4:34 am TiKels Post #20



I'd imagine someone on here has a computer that has no files of value on it and could do some sorcery and figure out what it does.



"If a topic that clearly interest noone needs to be closed to underline the "we don't want this here" message, is up to debate."

-NudeRaider

Options
  Back to forum
Please log in to reply to this topic or to report it.
Members in this topic: None.
[01:53 am]
Ultraviolet -- :lol:
[06:51 pm]
Vrael -- It is, and I could definitely use a company with a commitment to flexibility, quality, and customer satisfaction to provide effective solutions to dampness and humidity in my urban environment.
[06:50 pm]
NudeRaider -- Vrael
Vrael shouted: Idk, I was looking more for a dehumidifer company which maybe stands out as a beacon of relief amidst damp and unpredictable climates of bustling metropolises. Not sure Amazon qualifies
sounds like moisture control is often a pressing concern in your city
[06:50 pm]
Vrael -- Maybe here on the StarEdit Network I could look through the Forums for some Introductions to people who care about the Topics of Dehumidifiers and Carpet Cleaning?
[06:49 pm]
Vrael -- Perhaps even here I on the StarEdit Network I could look for some Introductions.
[06:48 pm]
Vrael -- On this Topic, I could definitely use some Introductions.
[06:48 pm]
Vrael -- Perhaps that utilizes cutting-edge technology and eco-friendly cleaning products?
[06:47 pm]
Vrael -- Do you know anyone with a deep understanding of the unique characteristics of your carpets, ensuring they receive the specialized care they deserve?
[06:45 pm]
NudeRaider -- Vrael
Vrael shouted: I've also recently becoming interested in Carpet Cleaning, but I'd like to find someone with a reputation for unparalleled quality and attention to detail.
beats me, but I'd make sure to pick the epitome of excellence and nothing less.
[06:41 pm]
Vrael -- It seems like I may need Introductions to multiple companies for the Topics that I care deeply about, even as early as Today, 6:03 am.
Please log in to shout.


Members Online: Ultraviolet, RIVE