CNCzone.com-The Largest Machinist Community on the net!



Home Page Mark Forums Read Today's Posts My Replies Classifieds Reviews Photo Gallery Web Links Share Files Advertise With Us Ad List
Go Back   CNCzone.com-The Largest Machinist Community on the net! > Events, Product Announcements and More > CNCzone Club House


CNCzone Club House Discuss everything in between CNC. THIS IS NOT A TRASH BIN.


This forum is sponsored by:

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1  
Old 08-25-2008, 09:46 PM
Switcher's Avatar
Moderator
 
Join Date: Apr 2005
Location: Vectorink.com
Posts: 3,659
Blog Entries: 2
Switcher is on a distinguished road
Exclamation Tips on How to Remove XP-Antivirus (Virus)

It's been a long night!

I was surfing the web, came across a webpage that had the XP-Antivirus (Virus).

If you havn't had this virus yet, trust me it's one you don't want!

It's a ransom virus, it keeps hammering the heck out of your PC until you buy software to remove the virus (Scam).

Well I got some good news, after hours of scouring my PC, I found out how to get rid of the SOB!, without any other software.

I'll post more of how I saved my sanity, tomorrow, I gotta get some sleep, I'm not looking forward to the alarm at 5:00 AM.

Anyone else that has had the virus, please post...



.
__________________
Free DXF Files - Vectorink.com - myDXF.blogspot.com
Tweet this Post!Share on Facebook
Reply With Quote

  #2  
Old 08-25-2008, 11:13 PM
HuFlungDung's Avatar
Moderator
 
Join Date: Mar 2003
Location: Canada
Posts: 4,823
HuFlungDung is on a distinguished road

Sometimes I have manually killed off a virus, worm or trojan. My general procedure is try an antivirus software first of all. But suppose that does not work.

Well, then empty all temporary internet files as some bad stuff seems to want to lurk there.

Check the Startup folder to see if there is anything suspect in there that will run when windows starts up. Delete that. You may need to change your explorer view to reveal hidden files, and to show file extensions to really see everything on the drive. I do this always by default, because I don't want windows to dumb down my computer for me.

Clean out the temp folder under your username/local settings. Clean all of them if there is more than one user on the machine. There may be the odd file in there that windows is using and may not be deletable, but that is typical. You can probably look those up to see what they are.

Run task manager and read the list of processes. Compare this to a similar uninfected computer. You can use the uninfected machine to browse the internet looking up the names of some of the processes that you may not be familiar with. You don't want to kill off any essentials. Try to kill the offending processes in task manager. Keep watching to see if they come back in and start up again.

A virus scan may detect some infected files, but they may not be deletable if in use by the virus. Write down the names of these files.

Reboot in safe mode and open the registry and search for these infected file references in the registry. Delete them and also check to see if the files are where they are reported to be and delete them.

Try to reboot normally. Immediately open task manager and check the list of processes to see if the bad one(s) come back.

That's the hard way Maybe I'm lucky, but I've never hosed a windows registry yet by editing it, but I'm careful about what I do in there. If you've got a virus, there is no use setting a restore point before you edit the registry, but perhaps it would be worth a last ditch effort to restore to an earlier time when you think your computer was clean.
__________________
First you get good, then you get fast. Then grouchiness sets in.

(Note: The opinions expressed in this post are my own and are not necessarily those of CNCzone and its management)
Tweet this Post!Share on Facebook
Reply With Quote

  #3   Ban this user!
Old 08-25-2008, 11:19 PM
 
Join Date: Jul 2005
Location: Canada
Posts: 11,419
Geof will become famous soon enough

Or unplug everything, take the cpu down to your local computer whiz, pay the invoice when they give it back to you clean.

That's the easy way (for us technically incompetent Luddites).
__________________
An open mind is a virtue...so long as all the common sense has not leaked out.
Tweet this Post!Share on Facebook
Reply With Quote

  #4   Ban this user!
Old 08-26-2008, 04:20 AM
 
Join Date: May 2006
Location: Australia
Age: 40
Posts: 2,199
epineh is on a distinguished road
Buy me a Beer?

I had this one recently, I used Malwarebytes' Anti-Malware and also Smitfraud fix, this got rid of the problem, I don't have any links but they should be easy enough to find.

I got the links by trolling PC forums, using my uninfected linux PC which also happens to run my router

Russell.
Tweet this Post!Share on Facebook
Reply With Quote

  #5  
Old 08-26-2008, 04:55 PM
jgro's Avatar
Gold Member
 
Join Date: Jul 2003
Location: USA
Age: 44
Posts: 169
jgro is on a distinguished road

I got this one on both my daughter's and my computer. On my daughter's, I ended up using the restore function that Compaq had on it. On mine.....oh my what a frustrating couple of weeks. It disabled my anti-virus (couldn't get any updates), It disabled internet explorer and outlook express. I thought I would try to upgrade ie and outlook express to the latest version, but after doing that my desktop would come up with a blank screen. Luckily, I could go to my daughter's machine and copy over the important files that I needed through the network. I tried the Windows restore function, what a joke. Didn't work worth a crap. I got so pissed off at Microsoft that I put Linux Ubuntu on for a couple of weeks. That was until I couldn't get any on my cad or cam programs to work, so XP went back on (I really hated doing that).

jgro
Tweet this Post!Share on Facebook
Reply With Quote

Sponsored Links
  #6  
Old 08-26-2008, 07:48 PM
High Seas's Avatar
Gold Member
 
Join Date: Sep 2003
Location: Malaysia/Australia/NZ/USA
Age: 62
Posts: 1,124
High Seas is on a distinguished road

SWITCHER! You TEASE!! Where's the 'How-TO"?

"Well I got some good news, after hours of scouring my PC, I found out how to get rid of the SOB!, without any other software. "I'll post more of how I saved my sanity, tomorrow, I gotta get some sleep, I'm not looking forward to the alarm at 5:00 AM. "

Suppose you're at work - so waiting to hear HOW you Killed that B@ST@RD!
Jim
__________________
Experience is the BEST Teacher. Is that why it usually arrives in a shower of sparks, flash of light, loud bang, a cloud of smoke, AND -- a BILL to pay? You usually get it -- just after you need it.
Tweet this Post!Share on Facebook
Reply With Quote

  #7   Ban this user!
Old 08-27-2008, 07:18 AM
 
Join Date: Aug 2005
Location: knoxville,usa
Posts: 570
blackbeard52 is on a distinguished road

Here is the link for the program you need.

http://www.malwarebytes.org/mbam.php

Good computing
Bob
Tweet this Post!Share on Facebook
Reply With Quote

  #8   Ban this user!
Old 08-27-2008, 07:21 AM
 
Join Date: May 2006
Location: Australia
Age: 40
Posts: 2,199
epineh is on a distinguished road
Buy me a Beer?

Originally Posted by jgro View Post
I got so pissed off at Microsoft that I put Linux Ubuntu on for a couple of weeks. That was until I couldn't get any on my cad or cam programs to work, so XP went back on (I really hated doing that).

jgro
I know what you mean, I tried to get DeskCNC to work on my router linux box using WINE with no luck, apparently V Carve will work but I don't have a copy of that to try (not yet, saving for it )



Originally Posted by High Seas View Post
SWITCHER! You TEASE!! Where's the 'How-TO"?

Suppose you're at work - so waiting to hear HOW you Killed that B@ST@RD!
Jim
Maybe the virus came back and is now holding him hostage in his house so he cannot let the world know how to eradicate it...

Or maybe he is just busy

Russell.
Tweet this Post!Share on Facebook
Reply With Quote

  #9  
Old 08-29-2008, 08:50 PM
Switcher's Avatar
Moderator
 
Join Date: Apr 2005
Location: Vectorink.com
Posts: 3,659
Blog Entries: 2
Switcher is on a distinguished road

Yes the virus came back .

Anyway I think I got rid of it this time (fingers crossed).

1) Went to "C:\Program Files" on my PC, sorted everything by date, I did this because I knew I hadn't installed anything on my PC that specific day (same day I got the virus).

2) Look for & delete any file names that include j0e

Examples:

A) blphcv76j0e76a.scr

B) lphcv76j0e76a.exe

C) phcv76j0e76a.bmp

3) Got on the net, & downloaded mbam like blackbeard52 suggested, that cleaned up everything. I did the basic scan, then the whole PC scan, each time reboot the PC, cleared all my browser history.

The only way I could get mbam to download from the net was from another PC, put the install file on a thumb drive, then install mbam onto the virus PC.

On the virus PC I couldn't download anything from the net at all (IE & Firefox).



Here is the tip of the day, If you really value your PC, download mbam NOW! Don't wait until you get the XPantivirus (virus), on my PC it was blocking any & all downloads, it disabled Windows Update, it wouldn't let my browsers load the Windows Update site at all (I tried to add the Windows Update site to my trusted sites list, didn't work). I wanted to see If I could delete my browser then reinstall (didn't work).

I also did a lot of registry edits, the virus changed settings on 1/2 my PC (Ughhh...).

After all this mess, so far everything is running good.


.
__________________
Free DXF Files - Vectorink.com - myDXF.blogspot.com
Tweet this Post!Share on Facebook
Reply With Quote

  #10   Ban this user!
Old 08-29-2008, 08:55 PM
 
Join Date: Aug 2005
Location: knoxville,usa
Posts: 570
blackbeard52 is on a distinguished road

Switcher

I have removed a lot of this virus from users computers. there are several versions of the same virus. Malwarebytes mbam is the tool to do it....it should not reinfect but if it does just run it again... of course update it before the scan so it will detect and remove new stuff.... Good luck and glad it worked. Cant have our DXF guru down after all!!!


Bob
Tweet this Post!Share on Facebook
Reply With Quote

Sponsored Links
  #11  
Old 08-29-2008, 09:28 PM
Switcher's Avatar
Moderator
 
Join Date: Apr 2005
Location: Vectorink.com
Posts: 3,659
Blog Entries: 2
Switcher is on a distinguished road

blackbeard52,

Thanks for the help.

Maybe now, I can get a few more DXF files posted.


.
__________________
Free DXF Files - Vectorink.com - myDXF.blogspot.com
Tweet this Post!Share on Facebook
Reply With Quote

Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
anybody compare HT finecut tips to TD 1Torch tips for dross? Knut CNC Plasma and Waterjet Machines 0 09-29-2006 02:17 PM
Drafts: Tips for vendors and tips for RFQ writers... InspirationTool Employment Opportunity 3 12-20-2005 09:44 PM
A New victim of the CNC virus...... lurch CNC Wood Router Project Log 14 05-20-2005 10:30 PM
Is it a virus? turmite Computers and Networking 3 07-02-2004 01:01 AM
Probably a new virus NeoMoses CNCzone Club House 6 03-05-2004 08:52 PM




All times are GMT -5. The time now is 08:55 AM.





Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Content Relevant URLs by vBSEO
Template-Modifications by TMS

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353