when mad viruses attack!

For general computer discussion & help, come here

Moderators: Bakhtosh, EvilHomer3k

Post Reply
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

when mad viruses attack!

Post by Daehawk »

Man I played that Navy Field game today then got a nasty ass virus. Not sure if its related or not. Ive been cleaning this system for 5 hours now and im still infected . I have Norton installed and it still got through. Ive run my anti virus in normal mode and safe mode. Each time it says i have backdoor.haxdoor trojan and its been deleted...but it sticks around. It changed my homepage, uses its own search engine when I try to use google or yahoo, its mass emailing people a bunch of crap that I CANNOT STOP.. It mails so much my isp starts blocking the attemps as spam but it just continues..even after Ive deleted all the addresses in my contacts list.

I reboot and its all back...popups, ads, I still cant fix my homepage ..........it just wont die ...Ive also ran 3 spyware killers. Ive manually deleted 4 programs in my programs list..2 of those made me fill oujt a fucking survey before it would even delete them.

While I type this Im having to close error windows from my isp cause of the mass mailing.....all I can do is turn off my modem but then I cant get any virus updates ....not much help anyways since all the search engiensare wonked and the shit keeps coming back

Im worried about all these 100s of emails its sending to who knows who now that my contact list is empty.
User avatar
EvilHomer3k
Forum Moderator
Posts: 7924
Joined: Tue Oct 12, 2004 10:45 pm
Location: Cedar Rapids, IA

Post by EvilHomer3k »

http://securityresponse.symantec.com/av ... xdoor.html

Scroll down for removal instructions. You might also try AVG. It's free and works well. Finds stuff that Norton doesn't.
User avatar
JSHAW
Posts: 4514
Joined: Wed Oct 20, 2004 2:03 pm

Post by JSHAW »

NUKE IT from orbit, it's the only way to be sure.
User avatar
Greggy_D
Posts: 1654
Joined: Wed Nov 03, 2004 3:58 pm
Location: Michigan

Post by Greggy_D »

Boot into Safe Mode and run all your programs (antivirus and spyware). Check the startup tab in MSCONFIG and get rid of all the BS that doesn't belong.

Reboot and you should be good.
"Whoaaaaaa man. You're totally covered in glass salad." .....Smooth B's stoned neighbor
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

Well ive ran every program 5 or 6 times in and out of safe mode. One scanner will say a file is ok and another will say its a virus so I manually went in and deleted every file that was suspect no matter what it was. Ive deleted all wierd programs and edited my registry and also run msconfig and cleaned up startup.

But I still get a warning that norton has found and deleted backdoor.haxdoor virus everytime I reboot and I STILL cant change my homepage to what it used to be...all that is greyed out. And Im getting pops on my desktop even with IE shutdown.

Also its still sending out tons of email..Im gonna have to just shut it down. Most likely have to format. May just give up on computers for a while. Doubt it but Im tempted.
User avatar
Greggy_D
Posts: 1654
Joined: Wed Nov 03, 2004 3:58 pm
Location: Michigan

Post by Greggy_D »

Wow, that sounds like a nasty bitch.

You're right, a reformat may be in your near future.
"Whoaaaaaa man. You're totally covered in glass salad." .....Smooth B's stoned neighbor
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

Id just get it again. I got it this time will virus scanner and all running. And no i did'nt open any emails. I dont know where it came from. Like I said I was playing that open beta for Navy Fields and after i exited I had it. Mighta been in the new patch or something completely different.
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

Ive installed AVG and it found 4 viruses that Norton did'nt..I cleaned them, rebooted, and backdoor.haxdoor is detected yet again..it wont go away. Ive manually done everything on every site Ive found concerning this trojan. I can never find anything it says to look for and my virus scanners dont get it except on reboot but its alwayus back. Im sick of this.
I still cant change my startpage either.
User avatar
Ranulf
Posts: 1432
Joined: Thu Oct 14, 2004 1:07 am
Location: The Barrens

Post by Ranulf »

You also might try Avast AV and I think Panda Software has an online scanner. Trend Micro might have one too. Good luck, sounds like a nasty bastard. Prolly makes one want to switch to a mac. :lol:
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

Hehe..Heres the latest....I think Ive beaten it. After 1 and 1/2 days. This latest round was a pain. It killed my sound. After working for 3 hours I had to just remove my USB hub and my sound card then kill all my drivers and files and reinstall the sound card abd drivers. Ive left the USB hub out cause its a hassle all on it's own. I now have sound and there are no popups appearing. Also I dont see any outgoing email at this time but I cant be sure on that until some of it gets blocked as spam and it shows me a warning. AVG killed the last virus alert about 7 reboots ago so thats a good sign.

I now only have 2 problems left over...performance seems sluggish and I cannot change my startpage in IE. No idea on that.For now Im gonna keep 2 virus scanners running instead of just one.
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

Well Im running that free online scanner from Panda now...its found 23 infected files and its not done. I hope it will clean them because my other 2 says there are no infections.
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

Now Im down to not able to change my startpage and my IE icon on my desktop is gone.
User avatar
Rip
Posts: 26891
Joined: Tue Oct 12, 2004 9:34 pm
Location: Cajun Country!
Contact:

Post by Rip »

Daehawk wrote:Now Im down to not able to change my startpage and my IE icon on my desktop is gone.
Get hijackthis and post the logfile.
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

I think I got it all finally. What I did was manually go in and edited my registry. I basically reset my homepage value so I could set it in IE. It worked. I hope Im good to go now.
User avatar
Ranulf
Posts: 1432
Joined: Thu Oct 14, 2004 1:07 am
Location: The Barrens

Post by Ranulf »

Perhaps you should try Firefox instead of using IE? :wink: Be careful with running two AV aps on your machine. That can cause problems. At least only have one of them doing the real time monitoring crap if you use it.
User avatar
Daehawk
Posts: 63785
Joined: Sat Jan 01, 2005 1:11 am

Post by Daehawk »

ugh Greggy what a disgusting avatar! eww lol
User avatar
Greggy_D
Posts: 1654
Joined: Wed Nov 03, 2004 3:58 pm
Location: Michigan

Post by Greggy_D »

Daehawk wrote:ugh Greggy what a disgusting avatar! eww lol
LOL...obviously you saw that post in EBG. :lol:
"Whoaaaaaa man. You're totally covered in glass salad." .....Smooth B's stoned neighbor
Post Reply