Hi there people,
Seen as to how I cant reply to the mail I got through this site, i'm hoping to do that here..
I received some questions as to how to reach the search option when this virus is active..
I have to warn you though.. this particular bug downloads other viruses that change more stuff on reboot.. thats why it is VERY VERY important to remove the network cable, and not reboot unless its impossible to continue working before a reboot.
If you have done all the steps that Ebomb and I have provided (or cannot do some of the steps since it hijacked your explorer) and still have problems, here are some more tips.
Don't pin me down on this though, I don't know whether this helps.
Do NOT use your computer like normal when the virus is still there, you risk infecting other people and even being shut down by your ISP, and in the worst cases you risk being prosecuted for spreading spam/malware
Never download an "antivirus program" or "malware remover" unless you know it works (or one of the following: NOD32, Kaspersky, Norton/symantec, AVG and some other premium brands)
you MUST boot in safe mode (press f8 a couple of times right after you turn on your computer and get the black screen with the text stuff, that means BEFORE the windows logo with the moving bars) when youre in safe mode, you'll get a message about system restore.. this cannot be used since the virus could have infected a restore point.
When Safe Mode fully loaded, you should not get the warning message and blue/white background, if you do, press ctrl+alt+del, do task manager and look in your process list.
- If you see any weird processes in there, try to end them manually, but dont try too hard cause theyll probably stay.
Write the names of the processes (all that you dont trust) and look them up in google on a comp that is not infected, here you should eb able to find the meaning of most of them.. if not, its probably a virus, or a program you dont need.
- If you dont see a start bar, or icons: Try to manually start Explorer by doing CTRL+ALT+DEL, task manager, File > New task> explorer [enter]
If you cant get task manager to work, you have a problem that surpasses my knowledge, and its time to either use a recovery disk, re-install windows, or bring the computer to a specialist.
- If you cant start Explorer (the start bar and icons), theres another method to get it to work. Which requires some extra labour:
Go on a computer that is not infected and follow this link:
https://download.cnet.com/Trend-Micro-HijackThis/3001-8022_4-10781312.html?spi=a9bfc7c9b036de3f980fb8a30b2ee5ad (if possible)
Or look for hijackthis.
You can then put it on a usb stick or CD/DVD and open it in the infected computer by inserting it and browsing to the drive through CTRL+ALT+DEL, task manager, File > New task>[drive letter]:\hijackthis
This program helps you opening an alternative task manager and file explorer/basic scanner
With this program you can analyze the startup sequence and save a logfile to show other people, do this, and post the logfile on this forum (or multiple to get quicker help)
You can also use this program to open your task manager list in case you can't, or dont trust the windows one (some viruses have been known to alter it)
This "manual" has become quite a mess now, but if you go over it a couple times, I hope you get what I mean...
So here's what I expect you to do:
- Follow all the instructions (Ebomb and mine, and read the other people's too ofcourse)
- If these dont work, get Hijackthis
- FIRST follow your own intuition, find all processes on google, try to manually remove stuff with hijackthis after researching them
- Try premium antivirus trial packages
- Post your Hijackthis log on this forum and tell us your symptoms in one message, if we can help, we will!
- If all else fails (and I mean everything) Think about re-installing windows over this infected one.
Then back up everything on a dvd or usb stick (documents, pictures, saved games, every important possession)
IMPORTANT: Take your time for backing up, the windows that is installed now will not have the virus installed but your harddrive will be a mess (imagine post-apocalyptic new york on rush hour) and it still does contain the virus file on it.
When youre absolutely positive that you backed up every valuable file, it is time to do a system format.
You can do this by letting the windows installation make a new file system (theres plenty of tutorials about this and im not going in-depth on this)
Do know that upon doing a format, you will delete everything on the computer, and you will not be able to recover anything after the format.