Help... i have been infected with some internet virus thing

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • thatgoofytroll
    cake... or death?
    • Jul 2003
    • 26

    #1

    Help... i have been infected with some internet virus thing

    hey,
    yesterday i saw a link in someones AIM profile.... it was LIKE www.relphx.com (thats not the real thing... i dont want anyone clicking on it and getting infected).... [if you want the real address PM me]... so i clicked on it because i thouth it was one of my friend's jokes, anyway... now my homepage is permanently set to it (no mattter if i change it to yahoo or whatever.. it goes to www.relphx.com (misspelled again) and my AIM profile almost permanently shows it... and a few of my friensd have already been infected.

    if anyone has any ideas on how to fix this or anything please help.


    stuff i've tried.. checking out msconfig and killing all strange programs.... there werent any but i cut it down even more to steam [half life multiplayer] and aim.
    Jtramodude from PBR

    b2k3 w/ mad ups
    looking to trade for a cocker
  • robertjuric
    agg
    • Jun 2003
    • 1126

    #2
    Check your add/remove programs for anything that shouldnt be there. You might could try to use Ad-Aware, that might help.

    If not you could always completely uninstall both of the programs and reinstall.

    Is it just AIM and IE?
    "LoadSM5: I smells funny"
    Load SM5 Fan Club
    Member #2
    Vice-President

    My Webpage
    Feedback

    Comment

    • thatgoofytroll
      cake... or death?
      • Jul 2003
      • 26

      #3
      nope nothing in add/remove..
      im gonna try ad aware.

      and yes to the best of my knowledge its just IE and AIM
      Jtramodude from PBR

      b2k3 w/ mad ups
      looking to trade for a cocker

      Comment

      • thatgoofytroll
        cake... or death?
        • Jul 2003
        • 26

        #4
        ok... a friend said they killed it by deleteing files mshta.exe and av.exe
        ill come back when i found out if they worked

        (ad-aware did NOT work)
        Jtramodude from PBR

        b2k3 w/ mad ups
        looking to trade for a cocker

        Comment

        • thatgoofytroll
          cake... or death?
          • Jul 2003
          • 26

          #5
          well i thnk i got it....

          i deleted the files, then restarted... and did this about 3 times... when mshta.exe wudnt go away i just took it off archive and put it as read only....

          its working so far...
          Jtramodude from PBR

          b2k3 w/ mad ups
          looking to trade for a cocker

          Comment

          • OfficerGoat
            My Liver! My Liver!
            • May 2003
            • 532

            #6
            To get rid of that file boot the machine in safe mode.... (F8 during boot up and select safe mode) This will unlock the files. Blow it away and that will kill that part. You may have to tweak the registry to fully remove that from I.E.
            Sig image must be under 20k

            Comment

            • CoFFeY[NiTrO]
              battle royale
              • Sep 2001
              • 3222

              #7
              How would I get rid of these two processes that start up whenever I log into WindowsXP?

              They are called
              DownloadPlus.exe
              realsched.exe or something like that.

              Ad-Aware can't find it, and theres nothing in the Add/Remove thing. Also the LogiTech keyboard I have doesn't 'turn on' until I'm at the user log-in screen.

              Instant Message Me
              ~3rd-Party Trades~

              Comment

              • PyRo
                President Bioloaf inc.
                • Dec 2000
                • 10186

                #8
                Have you tried add/remove programs and seeing if they are in the list? Or just search for the files on your computer?

                Comment

                • mikey101
                  aka murdoc
                  • Jun 2001
                  • 790

                  #9
                  try going to start-run then type in msconfig and go to startup. see if the files are in there, if so, uncheck the box next to them.

                  Comment

                  • thatgoofytroll
                    cake... or death?
                    • Jul 2003
                    • 26

                    #10
                    yeah msconfig is where to go, especially if you dont know how to delete the files themselves.
                    Jtramodude from PBR

                    b2k3 w/ mad ups
                    looking to trade for a cocker

                    Comment

                    • dave_p

                      #11
                      the internet is the modern equivelent of the wild west. to travel it unarmed is very unwise. heres a few places to arm yourself:


                      Steve Gibson's and Gibson Research Corporation's Web homepage.

                      Comment

                      • AFRaven
                        Member
                        • May 2002
                        • 255

                        #12
                        I got this today also. I also fixed it today. Here's how:

                        1. Restart your computer

                        2. Before Windows loads, hit F8 and boot in Safe Mode.

                        3. Click: Start/Search/For Files or Folders

                        4. Type in "av" and press search

                        5. Delete and files named "av.exe" or "av". You are done the first part.

                        6. Click: Start/Run

                        7. Type "Regedit"

                        8. Browse to "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Cur rentVersion\Run"

                        9. Delete the "Antivirus" key with a value of "c:\av.exe"

                        10. Browse to "HKEY_CURRENT)USER\Software\Microsoft\Internet Explorer\Explorer Bars\[Random Numbers]\FilesNamedMRU"

                        11. Delete the "000" Key with a value of "av.exe"

                        12. Close "Regedit"

                        13. Click: Start/Settings/Control Panels/Internet Options

                        14. Change your default homepage to www.yahoo.com (or whatever you want it to be)

                        15. Restart your computer, this time NOT in Safe Mode.

                        16. Log on to AIM, and change your profile.

                        That should be it. I hope this works for you, and tell your friends to do the same thing.

                        Edit: Forgot to mention, Spybot and Ad-Aware won't work. Also, virus scanners won't pick it up.

                        Comment

                        Working...