View Full Version : Uh oh. I need virus removal help...
Stuck in Seattle
01-15-2010, 11:01 AM
Any help would be appreciated. I'm down to reinstalling the operating system as my last idea on a fix.
Using my sister's crappy second computer I picked up a trojan yesterday. It's one of those fake securty/antivirus programs. I was using Firefox. I also get "Google Installer encountered a problem" warnings when I start Firefox.
It won't let me run Malwarebytes,
it won't let my antivirus software run,
it allows Adaware and Adaware removes a few components but it won't remove it all (and I think it actually has been hijacked as well as it didn't seem to run the right amount of time or check the right number of files). Then it just reinstalls the components (if they were actually removed by Adaware).
I tried restoring the computer to an earlier date...I click "next" when I get to the restore point and nothing happens.
I tried starting in Safe Mode and the screen is blank, so no go.
There's some process called "aoltbhelper.exe" that has dozens of listings when I look at the task manager.
The internet works but I don't know what this thing can be doing in the background.
By the way I'm certain I got the virus at "TheChive.com" or one of the pictures or links from the site. I've been going there for months and not had any problem until now.
Blueblood
01-15-2010, 11:38 AM
I'm not an expert but I've ran into this problem several times with a couple of my computers. I'd recommend downloading HiJackThis (http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html), run it, and copy and paste the results as well as the problems that you're having on the Geeks to Go (http://www.geekstogo.com/forum/forums.html) forum. Sometimes it takes a couple days for somebody to get back to you but they're very knowledgeable and I've had good results with them - and it's free.
Stuck in Seattle
01-15-2010, 11:50 AM
I'm not an expert but I've ran into this problem several times with a couple of my computers. I'd recommend downloading HiJackThis (http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html), run it, and copy and paste the results as well as the problems that you're having on the Geeks to Go (http://www.geekstogo.com/forum/forums.html) forum. Sometimes it takes a couple days for somebody to get back to you but they're very knowledgeable and I've had good results with them - and it's free.
Nope. It redirects the browser when I try to go to the download site. This thing is nasty!
Blueblood
01-15-2010, 11:54 AM
Nope. It redirects the browser when I try to go to the download site. This thing is nasty!
Have you tried using a different browser? Sometimes it only affects the main browser. Or do you have another computer you can use to download the app, put it on a flash drive, then run it on the infected computer?
Stuck in Seattle
01-15-2010, 12:09 PM
Have you tried using a different browser? Sometimes it only affects the main browser. Or do you have another computer you can use to download the app, put it on a flash drive, then run it on the infected computer?
IE runs but redirects me to garbage sites after it's been open for a few minutes. Right now I'm going through a process from a site that helps you work through this stuff...I hope. Hmmm. Now the computer froze as I was doing a search to check the site with the instructions. This virus has a buttload of defenses.
Nevadan
01-15-2010, 03:18 PM
I'm not an expert but I've ran into this problem several times with a couple of my computers. I'd recommend downloading HiJackThis (http://download.cnet.com/Trend-Micro-HijackThis/3000-8022_4-10227353.html), run it, and copy and paste the results as well as the problems that you're having on the Geeks to Go (http://www.geekstogo.com/forum/forums.html) forum. Sometimes it takes a couple days for somebody to get back to you but they're very knowledgeable and I've had good results with them - and it's free.
I would concur, mostly, with Blueblood's recommendation on HiJackThis. Here is a link (http://www.aumha.org/a/hjttutor.php) to a good tutorial for using HiJackThis.yourself and aoviding some of the hoop jumping that the folks on the GeekstoGo/CastleCops/etc. sites will have you go through. I have done a fair amount of malware cleaning and I can generally get through most problems by running my resident virus scanner and having HiJackThis fix things, based on the tutorial. Sometimes what seems insidious isn't quite as bas as it appears. However, there are times when you get into something really bad and then the exact fixes can often be researched directly through Google. What I've found is that what the mods (volunteers really) on the support sites often do is have you run this cleaner and that scanner and do this to the registry and that to the services and then reboot and run that other cleaner, then stand on your head and swear incantations.....you get the idea. Generally the prescription takes hours to do, on top of the time waiting for someone to respond to your posted HijackThis log and the approach is sort of a scattergun shot, rather than a direct fix, based on what is going on. When troubleshooting, start with the easiest, most likely fixes first, which is what my earlier suggestion is, then branch out if things don't clear up.
Good luck!
BustNChops
01-15-2010, 03:35 PM
Oh wow... I was prepared for you to talk further about that "big bald guy" that you had on your man-date at Thursday pre-game dinner. Man... that was uncomfortable, but like a train wreck I had to come in and check out the thread.
I didn't read through the whole thread, but if those that know better than I above don't get your system fixed, there is a PC store called "The Computer Guy" located in the shopping center over by Reno High. We used them a few years ago at their last location and were very reasonable and only charged me 1/2 as I already had done most of the basics that they were going to do.
tahoe84
01-16-2010, 04:37 PM
Hey SIS, hit me up at jeff.rogers@gmail.com if you haven't got your problem resolved. I have plenty of experience with removing that sort of crap. I'm getting ready to head out the door to pizza and then the game, but I'll be available in the afternoon tomorrow (flag football in the morning).
vBulletin® v3.8.4, Copyright ©2000-2012, Jelsoft Enterprises Ltd.