Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


I got a load of viruses...easy and hard to delete. HELP?
Goto page 1, 2  Next
 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
mark_the_hacker
Grandmaster Cheater Supreme
Reputation: 0

Joined: 26 Oct 2007
Posts: 1020
Location: CEF

PostPosted: Tue Aug 11, 2009 3:58 am    Post subject: I got a load of viruses...easy and hard to delete. HELP? Reply with quote

So to start it off I got AhnRpta.exe virus, which even if I delete from C:\WINDOWS\AhnRpta.exe, every time I open a process it pops out.
Now I also got the IEXPLORER.EXE virus, which is different from explorer.exe or iexplore.exe, and it pops out sometimes when AhnRpta.exe pops out. And just recently I find out that I come over the Confiker Virus. WHAT VERSION??? I don't know. it stops me from going to any microsoft website and those associated with it and some antivirus websites. Also it stops me from windows update. HELP???

btw, I got 56k modem....I know right?
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Polynomial
Grandmaster Cheater
Reputation: 5

Joined: 17 Feb 2008
Posts: 524
Location: Inside the Intel CET shadow stack

PostPosted: Tue Aug 11, 2009 4:13 am    Post subject: Reply with quote

Things to try:
1) Locate all of the virus executables and write down their locations (on paper). You can use Process Explorer and Autoruns from Microsoft Sysinternals to achieve this.
2) Go into safe mode and delete the files. Remove the registry entries that match the file locations in Autoruns.
3) Reboot - Virus should be dead.

Failing that, system restore to before you got the virus, or reformat.

My personal recommendation would be the latter - in the time it takes you to read these forum posts and download the tools and stuff to sort this problem on a 56k, yoiu may as well have gone out and got a job, worked for a month or two, used your pay to buy a new computer and then freshly installed Windows on that.

_________________
It's not fun unless every exploit mitigation is enabled.
Please do not reply to my posts with LLM-generated slop; I consider it to be an insult to my time.
Back to top
View user's profile Send private message
mark_the_hacker
Grandmaster Cheater Supreme
Reputation: 0

Joined: 26 Oct 2007
Posts: 1020
Location: CEF

PostPosted: Tue Aug 11, 2009 4:20 am    Post subject: Reply with quote

Im 15....I know right.

BTW I am in safe mode, or is. Kinda IDK. So heres the story, a year? ago, I downloaded Talix's AQ (FAKE) Gold Hack trainer by accident because of a failed noob that put up the download link in another thread. SO I runned it, and pressed the gold hack button which in turn deleted my system32 folder. So I was forced to have it fixed and when they fixed it, every time I run my computer I need to choose between two accounts, both in safe mode or IDK, and one can't work so I'm stuck with another. So yeah. Reformating is not a choice for me, and I know where 1 is, C:\WINDOWS\AhnRpta.exe. the two latter IDK.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 4:41 am    Post subject: Reply with quote

If the virus took up residence for over a year, chances are that System Restore won't even come close to the point when you were clean.

Formating and reinstalling is your best option. It's hard to imagine what kind of games you would have on a 56k connection, so I assume you don't really have much to backup.
Back to top
View user's profile Send private message
Polynomial
Grandmaster Cheater
Reputation: 5

Joined: 17 Feb 2008
Posts: 524
Location: Inside the Intel CET shadow stack

PostPosted: Tue Aug 11, 2009 4:48 am    Post subject: Reply with quote

I am beginning to suspect that mark is attempting to make a mockery of us.

Things wrong so far:
1) Nobody uses a 56k, let alone someone who has over 1000 posts on CEF.
2) There's no reason to tell us he's 15.
3) Viruses can't delete system32, it's protected by the OS. Besides, after deleting 20 or so files it'd likely cause the entire OS to crash or BSOD.
4) You don't access safe mode from an account.

I'll no longer be helping in this thread, I get the feeling that he's trolling.

_________________
It's not fun unless every exploit mitigation is enabled.
Please do not reply to my posts with LLM-generated slop; I consider it to be an insult to my time.
Back to top
View user's profile Send private message
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 5:01 am    Post subject: Reply with quote

You have a point. 56k = fail.

Reformat and reinstall, period. Requesting lock, if applicable.
Back to top
View user's profile Send private message
FullyAwesome
I post too much
Reputation: 0

Joined: 05 Apr 2007
Posts: 4438
Location: Land Down Under

PostPosted: Tue Aug 11, 2009 5:02 am    Post subject: Reply with quote

if you're not trolling, reformat, install antivirus software.
_________________
Back to top
View user's profile Send private message MSN Messenger
Thanitos
Grandmaster Cheater Supreme
Reputation: 0

Joined: 02 Mar 2007
Posts: 1588

PostPosted: Tue Aug 11, 2009 5:12 am    Post subject: Reply with quote

Burningmace wrote:
I am beginning to suspect that mark is attempting to make a mockery of us.

Things wrong so far:
1) Nobody uses a 56k, let alone someone who has over 1000 posts on CEF.
2) There's no reason to tell us he's 15.
3) Viruses can't delete system32, it's protected by the OS. Besides, after deleting 20 or so files it'd likely cause the entire OS to crash or BSOD.
4) You don't access safe mode from an account.

I'll no longer be helping in this thread, I get the feeling that he's trolling.


He said he ran a gold "hack" software, cant the run button be coded in .exe format to delete system 32?

_________________



Back to top
View user's profile Send private message Send e-mail
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 5:15 am    Post subject: Reply with quote

No, because Windows is using the processes in system32. If the program somehow manages to kill all the processes without Windows displaying the BSOD and/or shutting down immediately and remove system32, he shouldn't even be able to reboot.

So, format and reinstall.
Back to top
View user's profile Send private message
Thanitos
Grandmaster Cheater Supreme
Reputation: 0

Joined: 02 Mar 2007
Posts: 1588

PostPosted: Tue Aug 11, 2009 5:17 am    Post subject: Reply with quote

Ahhhh ok, that makes seance.
_________________



Back to top
View user's profile Send private message Send e-mail
Polynomial
Grandmaster Cheater
Reputation: 5

Joined: 17 Feb 2008
Posts: 524
Location: Inside the Intel CET shadow stack

PostPosted: Tue Aug 11, 2009 5:20 am    Post subject: Reply with quote

Indeed. Furthermore, Windows puts extra protection on files like ntoskrnl and the core system services (winlogon, lsass, crss, etc). Simply using rmdir /S /Q C:\Windows\system32 doesn't cut it, nor does del /F /S /Q C:\Windows\system32\*.*

He has his answer, requesting lock from nearest moderator.

_________________
It's not fun unless every exploit mitigation is enabled.
Please do not reply to my posts with LLM-generated slop; I consider it to be an insult to my time.
Back to top
View user's profile Send private message
mark_the_hacker
Grandmaster Cheater Supreme
Reputation: 0

Joined: 26 Oct 2007
Posts: 1020
Location: CEF

PostPosted: Tue Aug 11, 2009 8:00 am    Post subject: Reply with quote

Burningmace wrote:
I am beginning to suspect that mark is attempting to make a mockery of us.

Things wrong so far:
1) Nobody uses a 56k, let alone someone who has over 1000 posts on CEF.
2) There's no reason to tell us he's 15.
3) Viruses can't delete system32, it's protected by the OS. Besides, after deleting 20 or so files it'd likely cause the entire OS to crash or BSOD.
4) You don't access safe mode from an account.

I'll no longer be helping in this thread, I get the feeling that he's trolling.


1.) I do use a 56k modem, too lazy to ask my parents to pay for dsl or whatnot. Cuz theres a computer cafe.
2.) The reason was that the person that said for me to work assumed I was over 16 or 18 to work.
3.)it either deleted the system32 folder or a key component that caused my computer to not boot up one of my drives thus making it broken.
4) I said it was like picking an account, like picking which drive to come on from.

and also, you don't read every post do you? just the first and make your assumptive statement from that.

Anyways, if reformating is your best answer, at least find ways for me to delete Confiker,AhnRpta,and IEXPLORER.exe virus, by ways of putting antivirus in an portable storage device like a flashdrive or mp3 player.

Rather than thinking I am a troll or a person who makes a mockery of CEF, which by far I haven't done in all this time I was here.
Back to top
View user's profile Send private message AIM Address Yahoo Messenger
Haswell
Grandmaster Cheater
Reputation: 10

Joined: 24 Nov 2007
Posts: 703

PostPosted: Tue Aug 11, 2009 8:08 am    Post subject: Reply with quote

Burn an AV (actually, multiple AVs, to be on the safe side) and stuff like MalwareBytes, Spyware: Search and Destroy, etc... into a CD, run it from there.

Best option is still a reinstallation of your OS.
Back to top
View user's profile Send private message
Luigi
Grandmaster Cheater Supreme
Reputation: 1

Joined: 24 Mar 2008
Posts: 1082

PostPosted: Tue Aug 11, 2009 9:50 am    Post subject: Reply with quote

Yeah, the best is to reformat, but if you must and are sure it's conficker, there are a few conficker removers that are portable, but conficker might infect it by time you plug in the USB drive.
I recommend http://www.ubcd4win.com/
I believe it has the CrapAffee stinger, which is supposed to work.
Back to top
View user's profile Send private message
Polynomial
Grandmaster Cheater
Reputation: 5

Joined: 17 Feb 2008
Posts: 524
Location: Inside the Intel CET shadow stack

PostPosted: Tue Aug 11, 2009 10:01 am    Post subject: Reply with quote

Fine, if you're not trolling, post your HJT log and let us have a look.
_________________
It's not fun unless every exploit mitigation is enabled.
Please do not reply to my posts with LLM-generated slop; I consider it to be an insult to my time.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Goto page 1, 2  Next
Page 1 of 2

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites