Cheat Engine Forum Index Cheat Engine
The Official Site of Cheat Engine
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 


Urgent help needed (Virus problem)

 
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk
View previous topic :: View next topic  
Author Message
Notepad
Grandmaster Cheater
Reputation: 9

Joined: 26 Dec 2007
Posts: 722
Location: New Zealand

PostPosted: Wed Nov 18, 2009 5:33 am    Post subject: Urgent help needed (Virus problem) Reply with quote

I've got a virus which has disabled regedit and taskmanager (Yes I've tried re-enabling but it just gets disabled in 10 seconds).

I've scanned with Eset NOD32, SuperAntiSpyware and Malwarebytes but nothing has worked!

I've found a application called Sergiwa Antiviral Toolkit that finds the virus' but won't allow me to delete them because I don't have the full version (If anyone can get my a full version somehow it'd be greatly appreciated).

If anyone knows of a solution please share it as I have no clue what I should try.
Back to top
View user's profile Send private message
Jani
Grandmaster Cheater
Reputation: 2

Joined: 29 Dec 2006
Posts: 804

PostPosted: Wed Nov 18, 2009 5:54 am    Post subject: Reply with quote

Boot into safe mode and manually remove the virus.
Back to top
View user's profile Send private message
Notepad
Grandmaster Cheater
Reputation: 9

Joined: 26 Dec 2007
Posts: 722
Location: New Zealand

PostPosted: Wed Nov 18, 2009 6:22 am    Post subject: Reply with quote

I'm pretty sure that the virus is in C:\WINDOWS\system32\dllcache but I'm not sure which file is the actual virus..
Back to top
View user's profile Send private message
Benji
Random spam moderator
Reputation: 3

Joined: 31 Dec 2007
Posts: 60
Location: The Netherlands

PostPosted: Wed Nov 18, 2009 7:36 am    Post subject: Reply with quote

Antivirus programs that find viruses but you have to pay to remove them are always fake. I had one once and it even said Firefox was a virus.
_________________
Back to top
View user's profile Send private message
Strider96
Master Cheater
Reputation: 1

Joined: 20 Jan 2008
Posts: 289
Location: [email protected]

PostPosted: Wed Nov 18, 2009 12:56 pm    Post subject: This post has 1 review(s) Reply with quote

http://www.raymond.cc/blog/archives/2007/06/28/restore-task-manager-regedit-and-folder-options-disabled-by-virus/
_________________
http://forum.cheatengine.org/viewtopic.php?t=473915

*These guys are awesome for doing this for me*

If I left you off I am sorry send me a PM and ill add you Smile
Back to top
View user's profile Send private message AIM Address Yahoo Messenger MSN Messenger
Notepad
Grandmaster Cheater
Reputation: 9

Joined: 26 Dec 2007
Posts: 722
Location: New Zealand

PostPosted: Wed Nov 18, 2009 2:25 pm    Post subject: Reply with quote

Strider96 wrote:
http://www.raymond.cc/blog/archives/2007/06/28/restore-task-manager-regedit-and-folder-options-disabled-by-virus/
I've already tried that, It gets disabled again once I boot into normal mode.
Back to top
View user's profile Send private message
RealMayar
Newbie cheater
Reputation: 0

Joined: 12 Nov 2009
Posts: 24

PostPosted: Wed Nov 18, 2009 4:34 pm    Post subject: Reply with quote

Remove that fake anti-virus software (Sergiwa Antiviral Toolkit) - which is actually working as a trojan horse for the real virus - by using a real anti-virus program. You can try F-Secure Online Scanner (Google it, it will be easy to find) with IE.
_________________
RealMayar wrote:
Noko_112 wrote:
What on earth is IE 64-bit even good for?
For example downloading Firefox. Atleast IE can do that properly. Most of the time.
Back to top
View user's profile Send private message MSN Messenger
Notepad
Grandmaster Cheater
Reputation: 9

Joined: 26 Dec 2007
Posts: 722
Location: New Zealand

PostPosted: Wed Nov 18, 2009 5:19 pm    Post subject: Reply with quote

I've already Installed Eset NOD32.
The taskmanager and registry being disabled problem has been resolved (Scanned with SpyBot Search & Destroy in safe mode to find location of the virus and manually deleted it).
However, Spybot still detects that the virus is still there even though what was happening before has stopped, Could there be traces of the virus remaining?
I also don't think that Sergiwa is fake, It actually allows you to remove the restrictions (They did however get disabled 3 seconds later) but almost every fix I've looked for has told me to use Sergiwa.

So I'm not sure if I'm safe or not because Spybot still detects that the virus/spyware is still there even though I've deleted it manually.
Back to top
View user's profile Send private message
RealMayar
Newbie cheater
Reputation: 0

Joined: 12 Nov 2009
Posts: 24

PostPosted: Wed Nov 18, 2009 6:32 pm    Post subject: Reply with quote

Maybe it is just a registry entry (startup or a service) that wasn't removed. Give the F-Secure Online Scanner a shot, perform a full scan, it won't hurt.

And that Sergiwa s**t IS a fake anti-virus software. These type of viruses have two components. The first one is not really a virus, it just makes you belive that your computer is infected and it may disable some functions (like the ones you mentioned) and keeps sending ballon messages saying that your computer infected (someteimes the message says Microsoft detected the infection to make it seem more authentic) and a cheap, but brand new super-professional anti-virus software can remove the infection. Then if you fall for it you'll download the second component. Because you believe that it is an anti-virus software the programmer of this virus don't have to care about the size of the software, so it can be a highly sophisticated and advanced virus. When you install it (usually these viruses have installers like an ordinary program) the outcome is worse then the begginning. Much worse.

Download things only from trustable sources or install a sandbox (which let's you run a program without letting it to access to anything on your computer) or a virtual pc (M$ Virtual PC or VMWare Workstation) to be able to test the downloaded materials in a safe enviroment.

_________________
RealMayar wrote:
Noko_112 wrote:
What on earth is IE 64-bit even good for?
For example downloading Firefox. Atleast IE can do that properly. Most of the time.
Back to top
View user's profile Send private message MSN Messenger
Notepad
Grandmaster Cheater
Reputation: 9

Joined: 26 Dec 2007
Posts: 722
Location: New Zealand

PostPosted: Wed Nov 18, 2009 6:55 pm    Post subject: Reply with quote

Here's the thing..
I had the virus before I even downloaded Segiwa, I got it because my brother plugged in his Flash Drive which had a virus in it, The computer was brand new and I was just about to install Eset NOD32 when it attacked.

I've also deleted Sergiwa because the disabling stopped and there was no need to keep it.
However SpyBot Search & Destroy, SuperAntiSpyware, Malwarebytes all detect a virus, I try deleting the virus through the AV but it won't work, I've tried manually removing it and they still detect it even though the .dat file which contained the virus is full removed.

I've run a full system scan with Eset NOD32 and it picks up nothing even though the other AntiSpyware/AntiMalware scanners have detected problems.
Back to top
View user's profile Send private message
PUSHEAX_PUSHEAX
Grandmaster Cheater
Reputation: 72

Joined: 13 Apr 2009
Posts: 969

PostPosted: Wed Nov 18, 2009 7:12 pm    Post subject: Reply with quote

Boiwonder wrote:
Here's the thing..
I had the virus before I even downloaded Segiwa, I got it because my brother plugged in his Flash Drive which had a virus in it, The computer was brand new and I was just about to install Eset NOD32 when it attacked.

I've also deleted Sergiwa because the disabling stopped and there was no need to keep it.
However SpyBot Search & Destroy, SuperAntiSpyware, Malwarebytes all detect a virus, I try deleting the virus through the AV but it won't work, I've tried manually removing it and they still detect it even though the .dat file which contained the virus is full removed.

I've run a full system scan with Eset NOD32 and it picks up nothing even though the other AntiSpyware/AntiMalware scanners have detected problems.
If it's a new computer then why not just do a sytem restore? restore it to factory settings.
Back to top
View user's profile Send private message
Notepad
Grandmaster Cheater
Reputation: 9

Joined: 26 Dec 2007
Posts: 722
Location: New Zealand

PostPosted: Wed Nov 18, 2009 7:31 pm    Post subject: Reply with quote

Because I've already installed all my applications such as Photoshop CS4, Adobe After Effects, Sony Vegas Pro and so on..
If I restored it to factory settings then I'd lose all of them and the Flash Drive they were on has a virus on it so I'm not going to be plugging that thing back in my computer.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Cheat Engine Forum Index -> Computer Talk All times are GMT - 6 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001, 2005 phpBB Group

CE Wiki   IRC (#CEF)   Twitter
Third party websites