Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Well Now I Do Have A Problem
#1
And its called a virus the worm/alcra.b, have avg but it would do anything, this may be my problems with everything. How do I get rid of the darn thing
#2
I run avg too, and when the program itself wouldnt heal or quarentine it.. I would go into the results and click on the directory it is infected and choose myself to heal or quarentine it.. If it isnt a used program, like major one, you could delete it and redo it.. Just last weekend , our other computer had a BAD virus on it, and we couldnt heal it , but in the process of it, actually went into our windows and wouldnt let me get the desktop, had to format it completely.. So hopefully you can do it yourself and solve your problems.. Thats the only two things, set aside wiping the hard drive, to get rid of it
#3
Good luck bat, I really don't know what to tell you about this one.
Perhaps what Red said may work...
#4
how do i choose myself
#5
Do this..
1. Disable System Restore (go to start, programs, accessories, systems tools, system restore to do this.
2. Make sure your virus definitions are uptodate.

THEN

1. Reboot your computer.
2. When the computer starts booting back up keep pressing F8. This will take you to the safe mode selection screen.
3. Choose safe mode.
4. Log in under administrator.
5. Once in safe mode, Hit "Start" then "Run"
6. IN the run command Line type "regedit" (without the quotes and hit enter)
7. This pulls up the registry editor. Heres the path you will follow. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

8. ON the left hit the + sign next to HKEY LOCAL MACHINE
9. NOW UNDER HKEY LOCAL MACHINE Hit the + sign next to software
10. Now under Software Hit the + sign next to Microsoft
11. Now under Microsoft hit the + sign next to Windows
12. Now under Windows hit the + sign next Currentversion
13. Now under Currentversion double the the folder that says 'Run'
14. Now on the right you see some keys.. (viruses 90 percent of the time are planted here so they run on startup) (eg., default key and some more) Right click each key in there and delete them all except the one that references your avg. Its probably avg.exe. BTW, you cant hurt anything by deleting all the keys. So if you dont know its best to delete all them. Windows will regenerate any authenic keys it needs.
Most likely you will have a key named this.. "winupdates" = "%ProgramFiles%\winupdates\winupdates.exe /auto" <<<This is your culprit. But I suggest deleting other keys to incase you have any other viruses you may not no about.

Once you deleted those keys, close the registry editor and follow these next steps.

1. Hit Start, and go to Run.
2. In the Run box type "msconfig" without the quotes
3. press enter.. This will pull up the system configuration utility.
4. Now on the right click on start up tab. Uncheck every thing under startup except for you avg.
5. Hit Apply then OK.
6. YOur system will ask you to reboot. Tell it not right now.


Now..

1. Open up your AVG and do a full system scan while still in safe mode..
2. Once complete reboot your computer normally.
3. You will be prompted at start up that you are using a selective start. Just check never show this again.


Now Enjoy, your Virus free computer.. BTW, I suggest printing this. These steps will fix most any virus.
#6
I ran norton and it found a virus called bloodhound... i deleted it and msn started working again but my yahoo still doesn't work
#7
QQ beat me to it Sad
#8
i will give it a whirl, but yesterday it would not let me run msconfig
#9
QQ and reizvoll i did that but it tells me it cant find regedit
#10
Ok bat.. Try this.. Goto C:/Windows and rename regedit.exe to regedit.com

then go to your run line and type "regedit.com"

Sounds like the virus is intercepting regedit.exe. This will work most of time in situations like this.


However, if that doesnt work. Follow the below intructions. The program available will recreate new regedit and msconfig in new folders. But try the method I said above first. Its simpler:rock:








This small VB 6 utility will create a usable backup copy of Taskmgr.exe, MSConfig.exe and Regedit.EXE in a new folder, called C:\EmergencyUtils. The new copies will be named Copy_of_Taskmgr.exe, Copy_of_MSConfig.exe and Copy_of_Regedit.com.
These programs are extremely helpful, and usually necessary in helping to rid your computer of a viral infection. Many virus programs will intercept these programs, based on their original file name, and prevent them from running. The alternate copies will not encounter this problem. Simply navigate to the C:\EmergencyUtils folder and double click the file you need to run.

To use: Download the xp_emergencyutil.zip file and save it to your hard drive. Double-click the xp_emergencyutil.zip file and extract xp_emergencyutil.exe to your hard disk. To run the EXE just double click it, there is no installer. You will have the option of running the programs automatically, after the copies are created.

NOTE: Your antivirus software may warn of a potentially malicious script. This is normal, as the Windows Scripting Host is used to create the "copies" of these 3 utilities.







#11
well i went there and there is not one there at all that is even regedit.exe at all
#12
Well i also did the 2nd part and of course the copy_of_regedit.com is missing but the other two are there
#13
well the problem is worm / alcra.b, i have done everything but i cant get into the regedit in order to remoce it, even did a search on the net and they are saying the same thing as you QQ, but they are saying to run nortons and ofcourse i dont have it.
#14
ok bat..

try this..

go to your command line and type in this

" Regedt32 " without the quotes.. note there is not letter I in this one and has 32 on end.
#15
btw, thats a 32 bit version of regedit. Should be on your machine unless its intercepted as well.
#16
ok i did that in safe mode and all it did was bring back up the c prompt and went to start and the run and did it all it did was just take me back out
#17
bat,, go to this link and download this registry editor and run it instead..

http://www.sharewareconnection.com/downl...recon.html
#18
it does the same thing as the regedit does.. (edits reg files)
#19
well i downloaded it but what do i do now?
#20
Ok, Bat.. You must have forgot a step or your file was corrupt.

Follow these intructions.

1. Download the xp_emergencyutil.zip file and save it to your hard drive
2. Double-click the xp_emergencyutil.zip file and extract xp_emergencyutil.exe to your hard disk.
3. Doublle click the xp_emergencyutil.exe it will create a directory on you C drive called C:\EmergencyUtils
4. Now go to your C drive and click the folder EmergencyUtils.
5. You will see this when you open it. Double click the copy_of_regedit.com file. This will pull up your registry editor.
6. After you click that and it pulls up the regedit program. See the next thread for instructions on removing. For best results do these steps in safe mode.

#21
Do this..
1. Disable System Restore (go to start, programs, accessories, systems tools, system restore to do this.
2. Make sure your virus definitions are uptodate.

THEN

1. Reboot your computer.
2. When the computer starts booting back up keep pressing F8. This will take you to the safe mode selection screen.
3. Choose safe mode.
4. Log in under administrator.
5. Once in safe mode, Go to C:\EmergencyUtils
6. Now double click on the copy_of_regedit like demonstrated in the picture.
7. This pulls up the registry editor. Heres the path you will follow. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

8. ON the left hit the + sign next to HKEY LOCAL MACHINE
9. NOW UNDER HKEY LOCAL MACHINE Hit the + sign next to software
10. Now under Software Hit the + sign next to Microsoft
11. Now under Microsoft hit the + sign next to Windows
12. Now under Windows hit the + sign next Currentversion
13. Now under Currentversion double the the folder that says 'Run'
14. Now on the right you see some keys.. (viruses 90 percent of the time are planted here so they run on startup) (eg., default key and some more) Right click each key in there and delete them all except the one that references your avg. Its probably avg.exe. BTW, you cant hurt anything by deleting all the keys. So if you dont know its best to delete all them. Windows will regenerate any authenic keys it needs.
Most likely you will have a key named this.. "winupdates" = "%ProgramFiles%\winupdates\winupdates.exe /auto" <<<This is your culprit. But I suggest deleting other keys to incase you have any other viruses you may not no about.

Once you deleted those keys, close the registry editor and follow these next steps.

1. Go to C:\EmergencyUtils
2. Double click the copy_of_msconfig
3. This will pull up the system configuration utility.
4. Now on the right click on start up tab. Uncheck every thing under startup except for you avg.
5. Hit Apply then OK.
6. YOur system will ask you to reboot. Tell it not right now.


Now..

1. Open up your AVG and do a full system scan while still in safe mode..
2. Once complete reboot your computer normally.
3. You will be prompted at start up that you are using a selective start. Just check never show this again.
#22
QQ i have tried thid about 4 times and it does not install copy of regedit at all it installs the other two but not that one.
#23
thats strange.. I will upload regedit to my server so you can download it.

http://www.bluegrassrivals.com/clickme.exe


i renamed it to clickme.exe just incase the virus is scanning for files named with regedit. Just save that clickme.exe to your hard drive and then double click it.
#24
ok i got it that time, so do i just follw the instructions you gave from earlier.
#25
Well i did what you told me and when i ran virus scan 81 alerts in archive files that they say cant be deleted.
#26
can you post me a screen shot?
#27
QQ i went ahead and did a full system recovery, i couldnt get a screen shot, because avg was only telling me 81 infected files, will i have to worry about the worm anymore, i am able to type regedit now and it brings it up. running nortons on it and so far only 2 infected files.

Forum Jump:

Users browsing this thread: 1 Guest(s)