Page 1 of 1

Stupid computer viruses...

Posted: Wed Jan 10, 2007 3:35 pm
by Azazel
Hey y'all

I know that this isn't quite the type of forum to be posting this, but maybe someone's encountered the same problems I'm having and is willing to lend a helping hand.
My computer here at work's gone nuts with what I assume to be a trojan. The IT guys are telling me that the only solution to it is to format the HDDs to get rid of it, but I don't want to lose all of my data in there. I do back-up my work on a regular basis, but re-installing the multitude of programs I have in there all over again isn't something even remotely appealing to me.

I first noticed something to be wrong when Windows created a .exe file inside every folder, named the same as the folder itself. Fearing a backdoor, I turned to deleting every single one of those .exe files.
That done, I ran AdAware, and it got rid of 46 'threats' (tracking cookies, mostly).
I then proceeded to go to Symantec's Norton AV webpage so I could download the trial version, but the Explorer window closed automatically as soon as the webpage opened. Same went for Panda, PCCilin and every AV program I could think of. It was the only time at which I re-activated the workstation's LAN connection.
So I downloaded the trial version through another computer in the network and tried installing it, but it didn't work. The trojan (or backdoor virus, I don't know), closes all Explorer windows that are directed to any pages related to anti-virus software.

Something I noticed while doing so is that, whenever I tried to change the hidden files configuration, Internet Explorer tried to access an unknown webpage. When I did manage to turn all hidden files visible, there was a file on C:, named 'Baka'...something. I deleted it.

I know that this info isn't really specific as to the nature of the problem I have at the time, but any help will be really appreciated.

- A.

Posted: Wed Jan 10, 2007 3:52 pm
by Skadi
Your at work, it's the work computer... do what the IT guys tell you. You don't want to be messing with company property on your own. If you break it, they may require you to buy it.

Posted: Wed Jan 10, 2007 11:55 pm
by Thorn
There are a couple worms going around right now. I may have access to something that can help, maybe not. Let me check.

Posted: Thu Jan 11, 2007 3:15 pm
by Azazel
Thank you for the fast replies. After an afternoon/evening of cursing, anger and plain despair at times, I managed to restore my computer back to last Friday's checkpoint, access the registry, and remove the virus's registry values completely.

It wasn't simple, but all my data's here with me still. :)

Thanks again.

- A.

Posted: Thu Jan 11, 2007 3:38 pm
by Sabre
Have you tried using a different browser program for the time being, such as Firefox??

Posted: Thu Jan 11, 2007 10:02 pm
by Azazel
I've considered it, yes, but I've stayed with IE out of familiarity, I think.

Right now it seems that my computer wasn't the source of the infection, since its tracks throughout the studio's network pre-date my computer's getting infected.
It sure was weird to stand-in for an IT guy today as I told folks how to get rid of the damn thing... :D

I'll try and convince my boss of switching to Firefox.

- A.

Posted: Fri Jan 12, 2007 10:54 am
by Thorn
Agreed, go with Firefox. Though I haven't convinced my wife that tabs are a good thing yet.

Posted: Fri Jan 12, 2007 7:54 pm
by Lt Col Andy Reddson, REF
Nice. Some *** wad with no life managed to **** up everyone elses.
¿Why can’t virals and spammers just get JOBS like the rest of us have to?

And just imagine if I were ANGRY about it… Though some of you don’t have to…