Post: Help removing viruses/worms
12-21-2014, 09:53 AM #1
Xavier Hidden
Are you high?
(adsbygoogle = window.adsbygoogle || []).push({}); I downloaded a self propagating exe file. Deleting file from the hidden temp folder it propagates in did nothing, it self replicated and came back. My AV was acting up. The worm is a Trojan horse. It seams that system restore may have done the trick. No more worm detected notifications but my pc is now even slower on start ups. Any idea what can be the problem? The worm is the crypter download on this site. It's a virus they host:

I'm hoping maybe some1 skilled with computers can run this in there VMware if they have one and find out for me exactly what folder the root of this evil installs itself in if possible. I should probably use VMware next time when dealing with this stuff.
Edit: AV is still acting up the worm is still active i'm fucked.
Last edited by Oneup ; 12-23-2014 at 12:07 AM. Reason: link removed
12-21-2014, 11:15 PM #2
Dan
I'm a god.
Originally posted by Xavier
snip


Did you do a full system restore?
12-22-2014, 11:53 PM #3
Xavier Hidden
Are you high?
Originally posted by Dan View Post
Did you do a full system restore?


Full restore and everything. The worm is very severe. Someone tried logging into my Microsoft account yesterday from the US and now my best course of action is to change my account password on every site. the worm was a password stealer. I'm still doing scans to make sure it's completely gone. Now I understand the importance of virus total for all the posted RTM tools on this site.
12-23-2014, 12:07 AM #4
Default Avatar
Oneup
Guest
Originally posted by Xavier
I downloaded a self propagating exe file. Deleting file from the hidden temp folder it propagates in did nothing, it self replicated and came back. My AV was acting up. The worm is a Trojan horse. It seams that system restore may have done the trick. No more worm detected notifications but my pc is now even slower on start ups. Any idea what can be the problem? The worm is the crypter download on this site. It's a virus they host:

I'm hoping maybe some1 skilled with computers can run this in there VMware if they have one and find out for me exactly what folder the root of this evil installs itself in if possible. I should probably use VMware next time when dealing with this stuff.
Edit: AV is still acting up the worm is still active i'm fucked.

Removed the link. Don't need skids making the problem even worse now do we?
12-23-2014, 05:17 AM #5
Dan
I'm a god.
Originally posted by Xavier
Full restore and everything. The worm is very severe. Someone tried logging into my Microsoft account yesterday from the US and now my best course of action is to change my account password on every site. the worm was a password stealer. I'm still doing scans to make sure it's completely gone. Now I understand the importance of virus total for all the posted RTM tools on this site.


Use DBAN, read up on it first.

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo