![]() |
|
|
|
Registered
Join Date: Aug 2004
Location: NYC
Posts: 1,859
|
Computer virus help - System Tools
No idea how I got this. Commented on a status on Facebook. Listened to my Windows Media Player and had my Picasa up.
Anyway, I now have it and it sucks. I've ran Malwarebytes & it took out 23 infected files. I rebooted & for some reason, it's still there. I'm now on my safe mode and I've done a full scan on Malwarebytes & it came up empty the 2nd time around. What's my options? |
||
![]() |
|
canna change law physics
|
Remove disk from computer, install in a USB box and connect to a clean PC and let that PC clean out the viruses.
__________________
James The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994) Red-beard for President, 2020 |
||
![]() |
|
Back in the saddle again
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,765
|
Lots of times this crap can reside in your hibernation file (hiberfil.sys). You would probably want to turn off hibernation, reboot, scan, reboot, then turn hibernation back on or something like that.
__________________
Steve '08 Boxster RS60 Spyder #0099/1960 - never named a car before, but this is Charlotte. '88 targa ![]() |
||
![]() |
|
Registered
Join Date: Aug 2004
Location: NYC
Posts: 1,859
|
Thanks for the tips...Now I just have to figure what you meant! Hahaha!
BTW, this sucks donkey balls!! |
||
![]() |
|
Navin Johnson
Join Date: Mar 2002
Location: Wantagh, NY
Posts: 8,762
|
Combofix
This is like an uber Malwarebytes.. removing the drive and scanning it as a standalone on another pc is a good idea also...
__________________
Don't feed the trolls. Don't quote the trolls ![]() http://www.southshoreperformanceny.com '69 911 GT-5 '75 914 GT-3 and others |
||
![]() |
|
Registered
|
I just had the same thing!
I logged onto in safemode w/networking and manually found the files and deleted them. Open up a browser on a different computer and follow posted instructions. I agree...it is a nasty program.
Good Luck! |
||
![]() |
|
![]() |
canna change law physics
|
Quote:
And yeah, it sucked monkey balls!
__________________
James The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994) Red-beard for President, 2020 |
||
![]() |
|
Registered
|
How do you manualy find these files. Unless it says VIRUS FILE I wouldn't know what to look for.
I've got a desk top that's infected and i just gave up on it.
__________________
Pete 79 911SC RoW "Tornadoes come out of frikkin nowhere. One minute everything is all sunshine and puppies the next thing you know you've got flying cows".- Stomachmonkey |
||
![]() |
|
Registered
Join Date: Aug 2004
Location: NYC
Posts: 1,859
|
I'm in safe mode w/ networking now and am looking for the files.
|
||
![]() |
|
Registered
|
Detailed step-by-step removal guide here: Remove System Tool and SystemTool (Uninstall Guide)
|
||
![]() |
|
Navin Johnson
Join Date: Mar 2002
Location: Wantagh, NY
Posts: 8,762
|
BTW Facebook seems to be a petri dish of virii
I help co-workers out with pc problems and one common thread was "I was on Facebook" Quote:
remove from while in safe mode...
__________________
Don't feed the trolls. Don't quote the trolls ![]() http://www.southshoreperformanceny.com '69 911 GT-5 '75 914 GT-3 and others |
||
![]() |
|
Registered
Join Date: Aug 2004
Location: NYC
Posts: 1,859
|
Success!!! Ran the RKill on regular mode since it was coming up empty on safe mode. (The RKill was found on Paul's link two posts above mine)
I got the file name. It was under c:\ProgramData\iMiAp06308\iMiAp06308.exe But anyway, I removed and promptly ran another scan. Glad that's over with! EDIT - now that I think about it, I could have contracted through a Myspace music page as I was looking up news on Cathialine Andria (French singer from Le Roi Soleil) before things started going downhill. It's a good bet since I never go on that site. EDIT 2 - that file name probably has other permutations. I only found mine by reading RKill's log (it was the only file name there). Last edited by AFC-911; 12-15-2010 at 07:06 PM.. |
||
![]() |
|
Registered
|
Those that are having problems should also turn off system restore, reboot, then turn it back on.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs. '84 Targa - Arena Red - AX #104 '07 Toyota Camry Hybrid - Yes, I'm that guy... '01 Toyota Corolla - Urban Camouflage - SOLD |
||
![]() |
|
canna change law physics
|
Yeah. I remember removing Gator from my girlfriends computer back around 2000. What a PIA. This System Tools thing is worse.
__________________
James The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994) Red-beard for President, 2020 |
||
![]() |
|
Registered
Join Date: Mar 2004
Location: Los Angeles
Posts: 17,316
|
I had it about a month ago. What a freaking b!tch. I could not get any bids out to my clients, I broke down and purchased a Mac. I am still learning how to use the freaking thing. So, they tell me there's no virus. When I have time, I will format it and start all over again.
Jeff |
||
![]() |
|
Slackerous Maximus
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,155
|
Microsoft Certified System Engineer here. MCT, MCSA, CCNA, yada yada.
My most recent solution was, 'buy a MacBook Pro, and quit ****** around with this MSFT BS'. SO sick of dealing with malware issues. When I'm running anti-virus, anti-malware, staying clear of 'naughty' sites.....and I STILL get awful virus issues, what the hell is the point? I need to work, not waste hours (days really) cleaning this crap up. As of late, I found I couldn't clean it up. 2 months in, and very happy thanks.
__________________
2022 Royal Enfield Interceptor. 2012 Harley Davidson Road King 2014 Triumph Bonneville T100. 2014 Cayman S, PDK. Mercedes E350 family truckster. |
||
![]() |
|