Solved

How to get rid of a virus, without internet.

Posted on 2004-04-02
87
882 Views
Last Modified: 2012-06-21
Im on my brother's computer right now. My own computer is infected with a virus. Even though I have internet, it says I dont. When I try to log onto chat programs, it says I do not have internet. And when I try to open files on my computer, it goes blank, and all you can see is my desktop background. After 3 seconds or so, it goes back, without ever openin the requested file. I can not open internet explorer either. I dont want to go out and buy a program, but is there any other way to get rid of the virus?
0
Comment
Question by:whatever427
  • 29
  • 28
  • 24
  • +1
87 Comments
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10745726
Any specifics can you give us on how do you know you have a virus ?

0
 
LVL 40

Accepted Solution

by:
Fatal_Exception earned 63 total points
ID: 10745733
Dnload and burn to a cd the AVG Free edition AV solution...

http://www.grisoft.com/us/us_dwnl_free.php

Also, while you are there, dnload the update file:

http://www.grisoft.com/us/us_updt7.php

It will install even though you have a virus..  After installation, you can use the update feature to install the updates..  run it and kill the virus..

Fe
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10745742
Whatever427,

You have to make use of someone's computer to download and burn what Fatal has said , ofcourse if it is possible
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745744
Also, another way, and what I would do in this instance, is to take your hard drive out of the infected computer and install it as a slave in your known good system...  DO NOT OPEN ANY FILES ON THE DRIVE..  Do the virus scan with the known good computer's AV solution...  Make sure the AV Definition files are up to date before you do..   This will take care of anything infected on the hard drive..

FE
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745749
Evening Ashwin..!!  TGIF...!!
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10745758
Fatal_Exception,


Good evening to you too.
0
 

Author Comment

by:whatever427
ID: 10745766
Fatal, thx, I want to go try it, but Im not sure if this computer can burn. Its pretty new, but all I know is he uses it usually to burn songs onto a cd. So would that be the same?
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745772
BTW:  regardless of whatever you decide, you NEED an AV solution on your system..!!!   I do use AVG on several of my home systems, and even on my Home Server, and I recommend it highly, as the price is right...  :)

And just in case your system is just being hijacked by spyware, you might try cleaning the junk out of it...

Spyware/Adware removal tools
------------------------------

What is spyware : http://www.spychecker.com/spyware.html

SpyBot-S&D : http://www.webattack.com/download/dlspybot.shtml

Ad-aware : http://www.webattack.com/download/dladaware.shtml

CWShredder (hijack removal):  http://www.spywareinfo.com/~merijn/downloads.html


If you are still having problems..  run the System File Checker..

System File Checker  

Start > Run > type "sfc /purgecache" {enter}

Start > Run > type "sfc /scannow" {enter}

Have your OS cd in your cdrom drive.

(You can also run these commands from the Command Shell – dos prompt)


0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745777
Correct..  a burner is a burner..  If he has XP or any burning software, that will work just fine..
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10745822
Here's a way to prevent it from running until you get it resolved...

Click Start->Run->MSCONFIG
Remove all checked items from the startup tab and reboot.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745827
Darn..!!  I knew I missed something..!!  :)
0
 
LVL 67

Assisted Solution

by:sirbounty
sirbounty earned 62 total points
ID: 10745830
Also - if you can do the following and post the results, we may be able to identify the virus and help you remove it...

  Click Start->Run->Regedit
  *Be careful when editing the registry as an accidental deletion can render your system inoperable.
  First navigate to the following key in the registry:
   HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
   *You might also find RunOnce, RunOnceEx, RunServices, RunServiceOnce or any of these with a trailing dash (-)

  Once found, click File, Export to save a copy of the key.

  Now find the next startup key:
   HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
   *You might also find RunOnce, RunServices, RunServiceOnce or any of these with a trailing dash (-)
  Follow the previous procedures to export a copy.

Now open the reg files with notepad (right click and edit should do it).
Post the results here (You can email them to the machine you're using for instance)...
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10745831
LOL
0
 

Author Comment

by:whatever427
ID: 10745857
Thanks everyone for helping, Im tryin the burning stuff, and then if it works, Ill accept. If it doesnt, then its the other solutions, and so on. Bleh.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745884
No problem.. you are in good hands here..

FE
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10745898
Allstate!  Am I right?  Am I right?
I love riddles...
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745917
Lowery's Law of Home Repair: If it jams, force it. If it  
breaks, it needed replacing anyway  

:)
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10745921
Myrtle's Funeral Parlor:
"We'll be the LAST ones to let you down!"
0
 

Author Comment

by:whatever427
ID: 10745925
Ok, I offically quit tryin to burn something. It wont let me, but songs. Sooo, Ill try findin the virus now. Here we go.
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10745932
Rah Rah Ree - Kick 'em in the knee!
Rah Rah Rass - kick 'em in ... the other knee!
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745949
Is the system you are on running XP..??  If so, just open up your Cdrom drive window and drag the AVG exe file into it, along with the Def file..  Put a bland Cd in the drive, go to File > Write to CD..  It should burn just fine that way..

Still think you should pull the hard drive out and slave it to the other system...  But stay on course and let us know what you find..

FE

Lorenz's Law of Mechanical Repair: After your hands become  
coated with grease, your nose will begin to itch.
0
 

Author Comment

by:whatever427
ID: 10745977
Yea, Ill burn if this doesnt work. I guess theres nothing to lose now, lol.

I cant do that just because my brother will kill me risking a virus onto his computer.

Heres what each reg file said. (My net wont work cause of this virus on my other computer, so I wrote it down on a piece of paper, *shrug*)

For the HKEY_CURRENT_USER one:

Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER/Software/Microsoft/Windows/CurrentVersion/Run]

For the HKEY_LOCAL_MACHINE one:

[HKEY_LOCAL_MACHINE/Software/Mircosoft/Windows/CurrentVersion/Run]

"MSConfig"=C://Windows//PCHealth//Hephctr//Binaries//MsConfig.ece/ auto"

[HKEY_LOCAL_MACHINE/Software/Mircosoft/Windows/CurrentVersion/Run/OptionalComponents]

[HKEY_LOCAL_MACHINE/Software/Mircosoft/Windows/CurrentVersion/Run/OptionalComponents/IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE/Software/Mircosoft/Windows/CurrentVersion/Run/OptionalComponents/Mapi]
"Installed"="1"
"Nochange"="1"

[HKEY_LOCAL_MACHINE/Software/Mircosoft/Windows/CurrentVersion/Run/OptionalComponents/Msfs]
0
 

Author Comment

by:whatever427
ID: 10745980
OOPS! Messed up. For the last one, its suppose to go like this.

[HKEY_LOCAL_MACHINE/Software/Mircosoft/Windows/CurrentVersion/Run/OptionalComponents/MSFS]
"Installed"="1"
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10745986
Can you start your system in Safe Mode..  (F8 at startup)..??

If so, then reboot and try starting it in Safe Mode with Networking..

If it starts with Networking, try to access the Net now..  If so, then dnload the AVG and run the tests..!!

FE
0
 

Author Comment

by:whatever427
ID: 10745992
F8 at startup, hmmm, lets try that, so Ill brb.
0
 

Author Comment

by:whatever427
ID: 10745997
I tried pressin f8 when I restarted, didnt work.. Nothing happened.
0
 

Author Comment

by:whatever427
ID: 10746013
I tried again, and it worked. Its on safe mode, networking. Actually, I can even open files up, and everything. But theres still no net.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746056
Safe mode with Networking still can not get out, eh..??   lets see if you even got a proper IP address then..

Start > Run > cmd (ok)

Then type in:  ipconfig /all

What do you get..??   In fact why don't we just throw it in a text file on your desktop...

type in:  ipconfig /all > ip.txt

You will find the text file on your desktop..  copy it and put in on a floppy..  paste it here for us to look at..

FE

0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746077
You might try resetting your TCP/IP stack:
 Click Start->Run->CMD <enter>
 at the prompt, type:

 netsh int ip reset c:\resetlog.txt <enter>

Also - navigate to these keys in the registry (start->run->Regedit <enter>)

  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock
  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock2

Repeat the following procedures on both:
Highlight the key, by clicking on it once.
Click File/Export - save it as the key's name (winsock.reg and winsock2.reg)
Now right-click it and click delete.

when you've done that on both - exit the registry and reboot...
0
 

Author Comment

by:whatever427
ID: 10746123
Sirbounty-

The CMD, Netsh int ip reset c:/resetlog.txt didnt work. It came up with a error message.

Warning: Could not obtain host information from machine. Some commands may not be available.

Bleh bleh bleh.

And when you said Delete It, I hope you meant the files I just saved? Right?

Fatal -

I dont have a floppy disk, so I dont know?
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746129
Which files you just saved? From the registry?
No - the File/Export is to make a backup.
You are going to delete the Winsock keys in the registry.
If you're not certain - post back - I'm here for a while...
0
 

Author Comment

by:whatever427
ID: 10746132
LoL, thanks for your help. Th Winsock keys? Oh.. Ok, misunderstood. Im go try it, thanks.
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746136
Okay - just make sure you export the keys first...(as a backup)
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746140
<I hope you heard me...maybe he hasn't left his brothers computer - or his brother will yell at him "Hey whatever-your-name-is - you got another one of those blasted emails from Experts-Exchange.  Sheesh!  What are they - spamming you or something?">
0
 

Author Comment

by:whatever427
ID: 10746156
Yea, it didnt work, lol.
0
 

Author Comment

by:whatever427
ID: 10746161
I dont know why, everytime I try to open a picture file or something, it'll just go..Blank, all you can see is my desktop picture, and then, after 3 seconds, it comes back. My internet is plugged in, and it works and everything, so...
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746170
*grin*   Ok...  back, but see we are still having issues...  :)

why don't we just delete the network stack and start over..??  YOu can go into your Device Manager and Uninstall the Network Card..  Reboot, and it should find it..  ck the properties then to make sure that the proper protocols have been installed..

What do you think..??

FE
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746176
You are saying that your NIC is working now and you can get out..??

If so, run the System File Checker commands I gave you in the comment above..

0
 

Author Comment

by:whatever427
ID: 10746182
No, lol, sorry, I meant that the net works on my bro's comp. But not on mine o.0 What do you mean start over??
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746184
<ahem>
"The long and winding road...that leads to your door..."
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746186
Oh.. just thinking that if we uninstall the NIC and force a reset of the stack, we might discover something...  Just a way I would start troubleshooting if I were there..
0
 

Author Comment

by:whatever427
ID: 10746187
Hi Sirbounty =D Your tips, as much as I wish to say, didnt work =( Still no net, and crap.
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746188
Should be able to download HJT, you think FE?

Not start over - Start->Run->SFC /Scannow
0
Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746190
Ok.. we got SB singing now..  ahem...
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746193
Well - you started it with your "TGIF"...
LOL

Crap you say?  Crap? What's this crap you speak of man?
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746194
yea.. definitely need to check those system files..

Run the sfc command first..
0
 

Author Comment

by:whatever427
ID: 10746196
Girl, mind you, psh.

Like the files not workin, and yea. YEA, not crap, so dont question my bad use of vocab now.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746197
Think he is getting frustrated, SB  :)

Never happened to us before, right..??
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746203
>>The CMD, Netsh int ip reset c:/resetlog.txt didnt work. It came up with a error message.

Warning: Could not obtain host information from machine. Some commands may not be available.<<

I see the problem there...
should read:

netsh int ip reset > C:\ipreset.txt

Please try this again...
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746206
So, do this now....

System File Checker  

Start > Run > type "sfc /purgecache" {enter}

Start > Run > type "sfc /scannow" {enter}

Have your OS cd in your cdrom drive.

(You can also run these commands from the Command Shell – dos prompt)
0
 

Author Comment

by:whatever427
ID: 10746207
The sfc didnt work. It started to pop up, then disappeared.. That was a joke, the vocab part, forgot to put a lol at the end ^_^
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746211
ooo  did not catch that..  would make a difference, eh..??
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746217
I believe you have some serious problems to deal with here...   If you don't have serious data to keep, I would wipe that drive in a heartbeat and resinstall the OS...    Of course, we experts don't like to suggest this, but I don't mind saying it..

:)
0
 

Author Comment

by:whatever427
ID: 10746219
Didnt work. netsh int ip reset c:/ipreset.txt

I memorized it now, with all the times I tried.
0
 

Author Comment

by:whatever427
ID: 10746224
Ok, I think I dont care anymore. Im just gonna reformat. And split the points, that work?
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746226
You still typing it wrong?
Try it line by line...

Start->Run->CMD

netsh<enter>
int <enter>
ip <enter>
reset <enter>

FE - don't give up yet man!  This ship's not sunk!
0
 

Author Comment

by:whatever427
ID: 10746227
I mean, would reformattin kill the virus?
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746228
Oh - and type "bye" to exit that console...
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746233
Like I said above...  a great idea...  I really like to do this every 4-6 months anyway..  keeps your system running smoothly..

But get that AVG on there as soon as you get her up and running..  Update your system with all the patches..   And if you need any help, let us know..

FE
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746235
Unless it's a boot sector virus...which I doubt.
But just use setup from the XP disk to wipe the partition first.

You've got a backup of your data?
0
 

Author Comment

by:whatever427
ID: 10746238
LOL, ok. Im gonna reformat. And get that avg. Thanks for hte help, both. Ill split the pts, whtaever they do.
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10746239
omg. 1 hr of studies has left my inbox filled ... wow this is incredible.

i guess i have nothing to say except to watch
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746241
yea..  make sure you hit enter after each command...  works better that way..:)
0
 

Author Comment

by:whatever427
ID: 10746243
My data is nothing but games and image files. Took a crap load of time to create, but nothing important. So, Im just gonna reformat it.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746245
You missed a good one Sunray..  :)  Pretty slow on EE tonight, so we have been hanging out here..
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746247
Hey - wouldn't it be cool, if EE turned into a real-time chat forum instead of this web-posting and emailing?
Like IM...That'd be kewl...
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746249
Sure you don't want to try a repair install first?
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746250
What about email?  Got that saved?  IE favorites?
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746251
A chat room has been suggested, but I think they believe it would interfere with the format...   Would be nice as long as it was not abused..

0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746253
"She was a working girl - north of England way...
Now she's hit the big time!  In the U.S.A"...
:D
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746255
What, like I'm not abusing this thread?  LOL
It's Friday - I'm bored...
Hey Sunray -how'd you force yourself to study...that's what I need to do...
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746257
Ok..  On that note, I think it is time for a snack..   :)
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746262
Hey - what are you having?
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746263
Get your case of Peaberry yet?
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746269
Ya know whatever - one thing that confused me about your registry Run entries - there wasn't anything there...
Can we try that route again, or are you really just going to format?

Open up those keys and look in the right pane (the subkeys don't matter (Optional Components)) - you should see a list in at least one of these - but it'll be on the right...
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10746338
>> Hey Sunray -how'd you force yourself to study...that's what I need to do...

well what can i say. i know u r simply asking . I wud the say that u said to me the other day

uninstall Quickpost .. LOL !!!
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 10746346
Fatal,

YOu should surely come on MSN chat . I and SB are online all the time and having more fun there..

0
 

Author Comment

by:whatever427
ID: 10746400
Sorry took so long, it wont let me split the points. It says I need 2 answers, but it wont let me click 2. So...
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10746404
You select one as the accepted and enter the points.
Then simply enter points on any other Assists...
0
 

Author Comment

by:whatever427
ID: 10746411
Split Points for How to get rid of a virus, without internet.
At least 2 Answers are required
Points must total 125 (you have allocated 0)
0
 

Author Comment

by:whatever427
ID: 10746413
And...I tried reformattin my computer, it wont work. The virus is keeping the cd from working.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746540
Talk your bro into letting you put that drive in as a slave..  as long as you run the AV solution and don't open any files you will be just fine..  Do it all the time..

FE
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10746545
I will have to join you guys on IM later..  time for bed..  you know, old age...!!  :)
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10747394
What does that say about me that went to bed an hour earlier?  :P
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10747401
whatever427 - to split, you click the radio button (/option button) next to the comment you want to accept as an answer - then place the # of points to designate to that option in the box next to it.
For any assists - you would repeat the points step, but not the option button step...

Afraid you'll have to do the math on splitting 125 - you'll probably need to bump one up 1 more point than the other...
0
 
LVL 67

Expert Comment

by:sirbounty
ID: 10748425
Thanx.
0
 
LVL 40

Expert Comment

by:Fatal_Exception
ID: 10748657
Ditto..

FE
0

Featured Post

Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

Join & Write a Comment

If your system is showing symptoms of browser hijacks or 'google search redirects' check out my other article (http://rdsrc.us/u3GP7A) first and run the tool TDSSKiller (http://rdsrc.us/GDBBs4) to get rid of the infection. Once done, and if the …
We have adopted the strategy to use Computers in Student Labs as the bulletin boards. The same target can be achieved by using a Login Notice feature in Group policy but it’s not as attractive as graphical wallpapers with message which grabs the att…
In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now