Link to home
Start Free TrialLog in
Avatar of otyew
otyewFlag for Malaysia

asked on

Remove virus and reset all windows setting

My client laptop was infected with virus. The virus does not let the antivirus to be loaded, does not let the msconfig to be opened, taskmanager is not able to run and etc.

1- does anyone knew anything about this kind of virus? pls explain on how to remove it. I had successfully remove it but there are other virus with this similar behaviour but some are hard to remove.

2- any website to download files to reset the window system registry (display and etc).

3- any tips on how to remove virus and restore the OS back to normal (Win XP)
SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Or you could straightaway run these, I have the feeling it might be the Alcan worm:

1. Please download Brute Force Uninstaller to your desktop.
http://www.merijn.org/files/bfu.zip
Right click the BFU folder on your desktop, and choose Extract All
Click "Next"
In the box to choose where to extract the files to,
Click "Browse"
Click on the + sign next to "My Computer"
Click on "Local Disk (C:) or whatever your primary drive is
Click "Make New Folder"
Type in BFU
Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".

2. Download Alcra PLUS Remover.
http://metallica.geekstogo.com/alcanshorty.bfu 
Save it in the same folder you made earlier (c:\BFU).

Reboot to Safe Mode.
Then, please go to Start > My Computer and navigate to the C:\BFU folder.
Start the Brute Force Uninstaller by doubleclicking BFU.exe
Behind the "scriptline to execute" field click the "folder icon"  and select alcanshorty.bfu
Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
Wait for the complete script execution box to pop up and press OK.
Press exit to terminate the BFU program.
Reboot into normal windows



Avatar of Angry_Beaver
Angry_Beaver

Are u sure that this is virus? may be it's Spyware... can you install/load any software? If you can install, try to install  Ad-Aware Personall (http://www.lavasoft.de/) and try to scan your Laptop for Spyware Software.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hijackthis is a very good diagnostic tool, it can tell us what kind of malware etc is present in your system, it will then make it easier for us to pick the right tool for instead of trying many different scanners to see which one  works.

Most of the time hijackthis handles baddies by just fixing the bad entries.
Avatar of otyew

ASKER

does anyone has the url where i can download all the default registries for windows?
I don't know of any url where you can download windows default registry. Even if there were how can it work when the registry are not synchronized with what programs are installed in your system?
Importing a registry from somewhere would be a bigger problem than what you have now which is cleaning up the aftermath of the virus and removing leftovers.

What you can do is try and roll back your system to the way it was before you were infected.
Try System Restore;
Start > All Programs > Accessories > System Tools > System Restore >
then pick a date before you were infected.
Bear in mind that any program you installed, drivers and updates you've installed after the chosen date will need to be reinstalled.

By the way, have you tried any of the above suggestions, like letting us see your hijackthis log etc.
Avatar of otyew

ASKER

system restore is basically useless most of the time, it was obvious tat the system was changed but after using system restore, it didnt detect any changes.

ok, one last question. if i run the hijackthis program n the list of process are out. if i found some suspicious process, what should i do?

anyway thanks for the answer
I'd rather look at the hijackthis log myself if that's okay, any bad entries there could point to a specific malware/virus that needs a particular tool to get rid of.

Hijackthis is not a standalone tool, sometimes it needs other tools like for example if look2me is showing in your log, then it needed a look2me tool, if an alcan worm show up in the log then it needs the tool specially created for Alcan worm etc.

But mostly, "Fix Checked" in hijackthis removes the relevant bad registry entries.

So I would like to ask you to just post the entire log at the sites I mentioned in my post.
paste the notepad contents to either these sites:
http://www.rafb.net/paste/
then at the bottom left corner click "paste"
Copy the address/url and post it here:

Or paste the log at --> http://www.hijackthis.de/ 
and click "Analyse", click "Save".  Post the link to the saved list here.
Avatar of otyew

ASKER

yeah, hope to do so but it totally block my access to any website. i can connect to the internet, even do the vnc and ftp but not web browsing
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Have you tried the safe mode and then activate your antivirus?