Fox T-Bird/Cougar Forums

Computers/PCs => General Computer Forum => Topic started by: BlackCardinal on August 04, 2009, 12:44:46 AM

Title: I got hijacked!
Post by: BlackCardinal on August 04, 2009, 12:44:46 AM
:hick: Yes...hijacked...and yes, I had no protection...I had protection, but it expired and I just never got it updated. So, I humbly as for any help if possible, knowing it was my own dayum fault...

I have a gateway PC running windows xp home edition. I was on Facebook the other night and was sent a video...like an idiot, I fell for it and tried to open it, but no luck. Now, today, my computer is hijacked, by some program that wants me to purchase anti virus software. Of course, I refuse to buy from these azzhats, even if it was a legit site!

So, I can't open up any programs...especially any anti virus or anti spyware stuff...but I can surf the net. I tried the Hijack this program, tried renaming it, but no luck. Well, with my limited computer knowledge, I'm stuck. I'd appreciate any help you guys can give me!
Title: I got hijacked!
Post by: Beau on August 04, 2009, 01:51:51 AM
About the only thing I can suggest without refomatting is to find someone with a spyware removal program (I use SUPERAntiSpyware) and put it on a disc. Seems all the spyware out there now even prevents downloading a program...if it's very bad though, might be best to reformat.

Anyhow, whenever you get it sorted, make sure you get an anti-spyware AND a good anti-virus and use them, update, and all that jazz. ;)
Title: I got hijacked!
Post by: toddp on August 04, 2009, 07:53:43 AM
look into AVG they have some free virus protection,i have also run into something similar to your problem. i run AVG with no problems
Title: I got hijacked!
Post by: BlackCardinal on August 04, 2009, 09:19:28 AM
I've downloaded several anti-virus programs, but this hijack prevents me from opening anything. Not sure if I have any other options here...
Title: I got hijacked!
Post by: JeremyB on August 04, 2009, 09:28:59 AM
Have you tried killing the virus in Safe mode?
Title: I got hijacked!
Post by: BlackCardinal on August 04, 2009, 11:01:15 AM
No! I'm willing to try that...gotta figure out how to get it into safe mode...
Title: I got hijacked!
Post by: blu84302 on August 04, 2009, 01:06:36 PM
Is the virus called security suite or something?  If so I should be able to help.

http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html (http://"http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html")

That's the program I used to remove that virus.  It's called Malwarebytes.  It says it cost money but you can download it and run it without registering.  It'll be good for getting rid of this virus one time.  Other than that I recommend Avast Antivirus to keep you protected.
Title: I got hijacked!
Post by: Beau on August 04, 2009, 02:58:29 PM
Quote from: blu84302;285201
I recommend Avast Antivirus to keep you protected.


 right! :roxor:
Title: I got hijacked!
Post by: ProTouring442 on August 04, 2009, 03:34:14 PM
My parents had one of those, ended up having to reformat the hard-drive.

I've used Kaspersky now for several years with no problems.

Shiny Side Up!
Bill
Title: I got hijacked!
Post by: tireshredder on August 04, 2009, 05:45:12 PM
Try this: http://housecall.trendmicro.com/

I've heard they were good.  Never used it though...
Title: I got hijacked!
Post by: BlackCardinal on August 04, 2009, 07:19:47 PM
Quote from: tireshredder;285246
Try this: http://housecall.trendmicro.com/

I've heard they were good.  Never used it though...


Tried it...again, the virus immediately shuts down any program I try to open...I may have to reformat...:mad:
Title: I got hijacked!
Post by: Quietleaf on August 04, 2009, 07:48:24 PM
Reboot, hit F8 before Windows starts to get the menu that lets you get into Safe Mode. Then try downloading and running it.
Title: I got hijacked!
Post by: Romeo2k on August 04, 2009, 11:41:30 PM
you could do a selective startup, But thats more advanced.
Title: I got hijacked!
Post by: BlackCardinal on August 05, 2009, 12:34:38 AM
YES! I rebooted in Safe Mode and then uses Stinger to remove that ! We are once again clean and operating in a safe AVG Anti-virus environment!

Thank you all for your help!
Title: I got hijacked!
Post by: ProTouring442 on August 05, 2009, 08:14:56 AM
Quote from: BlackCardinal;285337
YES! I rebooted in Safe Mode and then uses Stinger to remove that ! We are once again clean and operating in a safe AVG Anti-virus environment!

Thank you all for your help!


Lucky!

When I had to clean my parent's computer, nothing I tried would find all the various hidden parts of the virus. Good Job!

Shiny Side Up!
Bill
Title: I got hijacked!
Post by: jcassity on August 07, 2009, 12:30:50 AM
restart in safemode and run your virus software.

malewarebytes.com is great,, running it in parallel with spybot
Title: I got hijacked!
Post by: Haystack on August 07, 2009, 04:00:30 PM
I love spybot. It doesn't get everything, but has kept the wifes laptop running with very few issues for about 2 years now. If you have it pop back up, you could always try restoring to a previous date. I would recomend a full system restore if you have any problems in the future. Do not call gateway and buy there garbage. The only thing it will do is put more  on there for you.
Title: I got hijacked!
Post by: ~AC on August 07, 2009, 05:25:30 PM
i didnt read the rest of the thread... i'd say go into MSconfig, start up tab, and see if you cant get around it starting up when windows starts.  avg is free.
Title: I got hijacked!
Post by: Ductape91 on August 07, 2009, 05:52:23 PM
out of curiousity what exactly did you do on hijackthis that didnt work?

even though you put a bandaid on it with your antivirus you should run a destructive recovery to completely remove it and all the other  you downloaded to try and get rid of it.

and fyi if your not sure how to get into safe mode type msconfig into your run command window (win+r), go to boot.ini tab and click on safe boot option. apply and when it asks to restart do so.
once your done toying around there to go back to the standard windows open msconfig again and click in the general tab normal start up.
your done.
Title: I got hijacked!
Post by: BlackCardinal on August 07, 2009, 06:42:01 PM
Quote from: Ductape91;285713
out of curiousity what exactly did you do on hijackthis that didnt work?

even though you put a bandaid on it with your antivirus you should run a destructive recovery to completely remove it and all the other  you downloaded to try and get rid of it.

and fyi if your not sure how to get into safe mode type msconfig into your run command window (win+r), go to boot.ini tab and click on safe boot option. apply and when it asks to restart do so.
once your done toying around there to go back to the standard windows open msconfig again and click in the general tab normal start up.
your done.


Are you asking me? If so, the issue was that whatever took over the computer would not allow me to open any programs. Anything that had a .exe file to start was blocked. I tried renaming it but no luck. If there was a way to run the progam remotely I didn't know what that was.

A destructive recovery? I'm not sure what that is... you mean run the recovery disc? Will I have to re-load everything? I did remove all of the stuff I downloaded to combat the virus though.
Title: I got hijacked!
Post by: Ductape91 on August 07, 2009, 11:25:49 PM
i went and re-read the thread and i missed that part (about the .exe thing) sorry about that i thought it was something you tried on it that didnt work.
ive never had an issue with using hijackthis when ive had to use it i mean.

as for destructive recovery, it is what it sounds like so yes you would basically be setting the computer back to the way you bought it and would lose what is on it that you didnt back up onto something. if you computer doesnt have a recovery partition then you would need the CDs that came with it for that.
if your computer works fine now and your happy with it then disreguard what ive typed here, its irrelevant then.
if your computer was hijacked and even though you use antivirus or whatever its still there, they dont remove them jand ust bandaid your computer around them or quarenteen them. thats not effective enough for me.

and for the ones that recommend programs they never used, dont.
Title: I got hijacked!
Post by: Haystack on August 08, 2009, 12:22:07 AM
Wow what makes you such an authority on what programs to use and what to do? None of what was listed was bad information.
Title: I got hijacked!
Post by: Ductape91 on August 08, 2009, 01:26:38 AM
authority? what little authority i have is the programs that i would recommend "I" actually use. i use 2 simple programs and thats hijackthis and unlocker, thats it. no antivirus,spyware,bloatware or whatever name i feel like calling it and its been working fine for me for many years, works even better on my new computer. its all i would recommend and didnt waste a post recommending something i dont use.
what good would that advice be if "you" had no experiance with it?
 
relax:bowdown:. dont take my ignorance for being pen 15y, what i dont know about computers could fill a warehouse but my computers all work like the day i got them so i gotta be doing something right.
Title: I got hijacked!
Post by: Masejoer on August 08, 2009, 02:10:24 AM
When things come to this, without having to spend hours doing things manually, installing malewarebytes, renaming the executable, and launching the application can many times fix these problems. Rootkits can be more severe but someone DID make some "program"/script that takes a couple hours to dig through the system and find signs of a rootkit camouflaging itself. Of course, they are above the operating system and can hide from any software if they are programmed well enough. I'll try to remember the name of the only decent rootkit removal utility (only one I've found to actually work now days) for future reference. The program had no GUI - it ran everything in a command prompt window and used vbscript iirc.

It is my experience that normally antivirus programs are useless now days, especially with rootkit malware out there. Spybot and AdAware haven't been helpful in a few years now.

Lastly, system restores, especially those in the more effective Windows Vista and Windows 7, can restore prior to these infections but you may also lose any files that were changed since the restore point.
Title: I got hijacked!
Post by: shame302 on August 08, 2009, 02:28:22 AM
malewarebytes.com is good but i recommend a sweep of :

Microsoft Windows Malicious Software Removal Tool.

I run AVG every night.

Another tool that is great if you can locate the vicious program but can't get rid of it is:

RemoveOnReboot

GOOGLE them
Title: I got hijacked!
Post by: Cougar5.0 on August 08, 2009, 09:52:46 AM
Quote from: Seek;285802
When things come to this, without having to spend hours doing things manually, installing malewarebytes, renaming the executable, and launching the application can many times fix these problems. Rootkits can be more severe but someone DID make some "program"/script that takes a couple hours to dig through the system and find signs of a rootkit camouflaging itself. Of course, they are above the operating system and can hide from any software if they are programmed well enough. I'll try to remember the name of the only decent rootkit removal utility (only one I've found to actually work now days) for future reference. The program had no GUI - it ran everything in a command prompt window and used vbscript iirc.

It is my experience that normally antivirus programs are useless now days, especially with rootkit malware out there. Spybot and AdAware haven't been helpful in a few years now.

Lastly, system restores, especially those in the more effective Windows Vista and Windows 7, can restore prior to these infections but you may also lose any files that were changed since the restore point.


Good info. The one on my ex's machine even prevented system restore from operating (XP though).

I had to do safe mode w/ SuperAntiSpyware, then malwarebytes, then went to Hijackthis! to ensure that it was gone, though they claimed that rootkit stuff is virtually impossible to remove without starting over (reformat, reinstall Windows.)
Title: I got hijacked!
Post by: Haystack on August 09, 2009, 08:15:54 PM
Sorry I didn't mean to sound that harsh. There was sarcasum intended, but doesn't go well online. I was more or less messing with you.