Pelican Parts
Parts Catalog Accessories Catalog How To Articles Tech Forums
Call Pelican Parts at 888-280-7799
Shopping Cart Cart | Project List | Order Status | Help



Go Back   Pelican Parts Forums > Miscellaneous and Off Topic Forums > Off Topic Discussions


Reply
 
LinkBack Thread Tools Rate Thread
Author
Thread Post New Thread    Reply
Registered
 
AFC-911's Avatar
 
Join Date: Aug 2004
Location: NYC
Posts: 1,859
Computer virus help - System Tools

No idea how I got this. Commented on a status on Facebook. Listened to my Windows Media Player and had my Picasa up.

Anyway, I now have it and it sucks. I've ran Malwarebytes & it took out 23 infected files. I rebooted & for some reason, it's still there.

I'm now on my safe mode and I've done a full scan on Malwarebytes & it came up empty the 2nd time around.

What's my options?

Old 12-15-2010, 04:23 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #1 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Remove disk from computer, install in a USB box and connect to a clean PC and let that PC clean out the viruses.
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 12-15-2010, 04:29 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #2 (permalink)
Back in the saddle again
 
masraum's Avatar
 
Join Date: Oct 2001
Location: Central TX west of Houston
Posts: 55,765
Lots of times this crap can reside in your hibernation file (hiberfil.sys). You would probably want to turn off hibernation, reboot, scan, reboot, then turn hibernation back on or something like that.
__________________
Steve
'08 Boxster RS60 Spyder #0099/1960
- never named a car before, but this is Charlotte.
'88 targa SOLD 2004 - gone but not forgotten
Old 12-15-2010, 04:30 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #3 (permalink)
Registered
 
AFC-911's Avatar
 
Join Date: Aug 2004
Location: NYC
Posts: 1,859
Thanks for the tips...Now I just have to figure what you meant! Hahaha!

BTW, this sucks donkey balls!!
Old 12-15-2010, 04:33 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #4 (permalink)
Navin Johnson
 
TimT's Avatar
 
Join Date: Mar 2002
Location: Wantagh, NY
Posts: 8,762
Combofix

This is like an uber Malwarebytes..

removing the drive and scanning it as a standalone on another pc is a good idea also...
__________________
Don't feed the trolls. Don't quote the trolls
http://www.southshoreperformanceny.com
'69 911 GT-5
'75 914 GT-3
and others
Old 12-15-2010, 04:37 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #5 (permalink)
Registered
 
Join Date: Feb 2007
Location: Stafford, VA
Posts: 95
Send a message via Yahoo to zipinitaly
I just had the same thing!

I logged onto in safemode w/networking and manually found the files and deleted them. Open up a browser on a different computer and follow posted instructions. I agree...it is a nasty program.

Good Luck!
Old 12-15-2010, 04:39 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #6 (permalink)
 
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Quote:
Originally Posted by zipinitaly View Post
I logged onto in safemode w/networking and manually found the files and deleted them. Open up a browser on a different computer and follow posted instructions. I agree...it is a nasty program.

Good Luck!
Yep, my wife did this on her PC last year and this is exactly how I fixed it.

And yeah, it sucked monkey balls!
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 12-15-2010, 04:47 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #7 (permalink)
Registered
 
pete3799's Avatar
 
Join Date: Nov 2008
Location: Vermont
Posts: 7,431
Garage
How do you manualy find these files. Unless it says VIRUS FILE I wouldn't know what to look for.
I've got a desk top that's infected and i just gave up on it.
__________________
Pete
79 911SC RoW
"Tornadoes come out of frikkin nowhere. One minute everything is all sunshine and puppies the next thing you know you've got flying cows".- Stomachmonkey
Old 12-15-2010, 04:54 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #8 (permalink)
Registered
 
AFC-911's Avatar
 
Join Date: Aug 2004
Location: NYC
Posts: 1,859
I'm in safe mode w/ networking now and am looking for the files.
Old 12-15-2010, 04:54 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #9 (permalink)
Registered
 
Paul_Heery's Avatar
 
Join Date: Dec 2001
Location: Elsewhere, CT
Posts: 2,119
Garage
Detailed step-by-step removal guide here: Remove System Tool and SystemTool (Uninstall Guide)
Old 12-15-2010, 05:19 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #10 (permalink)
Navin Johnson
 
TimT's Avatar
 
Join Date: Mar 2002
Location: Wantagh, NY
Posts: 8,762
BTW Facebook seems to be a petri dish of virii

I help co-workers out with pc problems and one common thread was "I was on Facebook"

Quote:
How do you manually find these files.
Helps to find a how-to-guide that has all the names and pseudonyms for the files..

remove from while in safe mode...
__________________
Don't feed the trolls. Don't quote the trolls
http://www.southshoreperformanceny.com
'69 911 GT-5
'75 914 GT-3
and others
Old 12-15-2010, 05:32 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #11 (permalink)
Registered
 
AFC-911's Avatar
 
Join Date: Aug 2004
Location: NYC
Posts: 1,859
Success!!! Ran the RKill on regular mode since it was coming up empty on safe mode. (The RKill was found on Paul's link two posts above mine)

I got the file name. It was under c:\ProgramData\iMiAp06308\iMiAp06308.exe

But anyway, I removed and promptly ran another scan.

Glad that's over with!



EDIT - now that I think about it, I could have contracted through a Myspace music page as I was looking up news on Cathialine Andria (French singer from Le Roi Soleil) before things started going downhill. It's a good bet since I never go on that site.


EDIT 2 - that file name probably has other permutations. I only found mine by reading RKill's log (it was the only file name there).

Last edited by AFC-911; 12-15-2010 at 07:06 PM..
Old 12-15-2010, 06:38 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #12 (permalink)
 
Registered
 
slodave's Avatar
 
Join Date: Sep 2005
Location: Encino Man
Posts: 22,394
Garage
Send a message via Skype™ to slodave
Those that are having problems should also turn off system restore, reboot, then turn it back on.
__________________
Make sure to check out my balls in the Pelican Parts Catalog! 917 inspired shift knobs.

'84 Targa - Arena Red - AX #104
'07 Toyota Camry Hybrid - Yes, I'm that guy...
'01 Toyota Corolla - Urban Camouflage - SOLD
Old 12-15-2010, 06:52 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #13 (permalink)
canna change law physics
 
red-beard's Avatar
 
Join Date: Jul 2000
Location: Houston, Tejas
Posts: 43,366
Garage
Quote:
Originally Posted by TimT View Post
BTW Facebook seems to be a petri dish of virii

I help co-workers out with pc problems and one common thread was "I was on Facebook"



Helps to find a how-to-guide that has all the names and pseudonyms for the files..

remove from while in safe mode...
Yeah. I remember removing Gator from my girlfriends computer back around 2000. What a PIA. This System Tools thing is worse.
__________________
James
The pessimist complains about the wind; the optimist expects it to change; the engineer adjusts the sails.- William Arthur Ward (1921-1994)
Red-beard for President, 2020
Old 12-15-2010, 07:54 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #14 (permalink)
Registered
 
Join Date: Mar 2004
Location: Los Angeles
Posts: 17,315
I had it about a month ago. What a freaking b!tch. I could not get any bids out to my clients, I broke down and purchased a Mac. I am still learning how to use the freaking thing. So, they tell me there's no virus. When I have time, I will format it and start all over again.

Jeff
Old 12-15-2010, 09:13 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #15 (permalink)
Slackerous Maximus
 
HardDrive's Avatar
 
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,155
Microsoft Certified System Engineer here. MCT, MCSA, CCNA, yada yada.

My most recent solution was, 'buy a MacBook Pro, and quit ****** around with this MSFT BS'. SO sick of dealing with malware issues. When I'm running anti-virus, anti-malware, staying clear of 'naughty' sites.....and I STILL get awful virus issues, what the hell is the point? I need to work, not waste hours (days really) cleaning this crap up. As of late, I found I couldn't clean it up.

2 months in, and very happy thanks.

__________________
2022 Royal Enfield Interceptor.
2012 Harley Davidson Road King
2014 Triumph Bonneville T100.
2014 Cayman S, PDK.
Mercedes E350 family truckster.
Old 12-15-2010, 09:25 PM
  Pelican Parts Catalog | Tech Articles | Promos & Specials    Reply With Quote #16 (permalink)
Reply

Thread Tools
Rate This Thread
Rate This Thread:

 


All times are GMT -8. The time now is 11:14 PM.


 
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website -    DMCA Registered Agent Contact Page
 

DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.