Guru3D.com Forums

Go Back   Guru3D.com Forums > General > General Software and Applications
General Software and Applications Trouble with software/DirectX or other programs like Detonator Destroyer.


Reply
 
Thread Tools Display Modes
Virus: PC stuck on the page that asks for money
Old
  (#1)
Robox1
Member Guru
 
Videocard: HD6970
Processor: I7 920
Mainboard: Rampage II Gene
Memory: 4GB DDR3 1600
Soundcard:
PSU: HX520
Default Virus: PC stuck on the page that asks for money - 06-05-2012, 14:45 | posts: 52

Browsing the net I untapped popup on various casino and poker that I think have infected my PC because all of a sudden you are stuck on a page that asks for payment $ 100 to avoid penalties because on my pc there are files protected by copyright blah blah blah .....

At each reboot I find this screen where you quit (doing ctrl alt del) and also by starting in safe mode.

Tips on how to solve the problem without a format?

[I tried with kaspersky rescue disk 10 but I had the same problem described here:

http://forum.kaspersky.com/index.php?showtopic=236625

I booted an OS from another hd but unfortunately ComboFix (from what I understand the only remedy with kaspersky windows unloker rtipo to solve this problem) scans only the operating system started, not even another disc and it does not seem to be configurable in this sense]

Last edited by Robox1; 06-05-2012 at 15:21.
   
Reply With Quote
 
Old
  (#2)
h9dlb
Newbie
 
Videocard: Geforce gtx660ti
Processor: i5-750
Mainboard: Gigabyte P35-DS3L
Memory: 8gb Corsair
Soundcard: Creative X-Fi XtremeMusic
PSU: Coolermaster 650w
Default 06-05-2012, 15:54 | posts: 26 | Location: Leeds England

I had this too - use system restore to a date before it happened and the problem is gone
   
Reply With Quote
Old
  (#3)
Phragmeister
Maha Guru
 
Phragmeister's Avatar
 
Videocard: MSI 560-Ti
Processor: i7 920 @ 3.8GHz
Mainboard: Asus P6TD V2
Memory: Corsair Dom 12GB
Soundcard: X-Fi Fatal1ty
PSU: Corsair HX850
Default 06-05-2012, 16:21 | posts: 1,161 | Location: UK

Try a scan with Malwarebytes and Trojan Remover.

Then purge all your temp files and such using CCleaner.

I also recommend installing Ad Muncher too, best ad remover on the net.
   
Reply With Quote
Old
  (#4)
Watcher
Maha Guru
 
Watcher's Avatar
 
Videocard: MSI 6850 OC CYCLONE 1 GB
Processor: Phenom II X6 1090T BE
Mainboard: ASUS M5A99FX PRO R2.0
Memory: G.SKILL 4 GB DDR3 1600
Soundcard: X-Fi Xtreme Gamer
PSU: OCZ StealthXStream 2 600W
Default 06-06-2012, 01:08 | posts: 1,989 | Location: Canada

Not sure if you have the issue below? You can try Kaspersky Xorist Decryptor :

http://www.majorgeeks.com/Kaspersky_...tor_d7732.html

Quote:
Malware of the family Trojan-Ransom.Win32.Xorist is designed for unauthorized modification of data on a victim computer. It makes computers uncontrollable or blocks its normal performance. After taking the data as a “hostage” (blocking it), a ransom is demanded from the user.

The victim is supposed to deliver the ransom to the pirate, who is promising to send in return a program which would release the data or restore normal performance of the computer.
   
Reply With Quote
 
Old
  (#5)
EpicLoss
Maha Guru
 
Videocard: ASUS GTX560Ti DirectCU II
Processor: Q6600 @ 3.4Ghz 1.4125v
Mainboard: Gigabyte P43 DS3R
Memory: 4gb ddr2 kingston hyperX
Soundcard: Onboard Realtek HD
PSU: Cooler master GX 550
Default 06-06-2012, 07:52 | posts: 831 | Location: Midlands/UK

firefox+noscript+adblockPLUS = clean and safe browsing
   
Reply With Quote
Old
  (#6)
k1net1cs
Ancient Guru
 
Videocard: Radeon HD 5650m (550/800)
Processor: Intel Core i5-520M 2.4GHz
Mainboard: Sony VAIO VPCEA16FG
Memory: 2x4GB CMSO4GX3M1A1333C9
Soundcard: ASUS Xonar U3
PSU: n/a
Default 06-06-2012, 17:38 | posts: 3,328

Quote:
Originally Posted by AlcapwN View Post
firefox+noscript+adblockPLUS = clean and safe browsing
You forgot Ghostery in that equation.




Interested in folding with fellow gurus? Click here to get you started!
   
Reply With Quote
Old
  (#7)
Supatitanman
Ancient Guru
 
Supatitanman's Avatar
 
Videocard: GTX 660ti
Processor: i7 3770k @ 3.5Ghz Ivy
Mainboard: MSI Z77 MPower
Memory: Corsair 8G DDR3 @ 893MHz
Soundcard:
PSU: 750W Corsair
Default 06-06-2012, 19:37 | posts: 2,863 | Location: Buffalo, NY

download this first:
http://support.kaspersky.com/faq/?qid=208282173

burn that to a CD-R using a tool like IMGBURN *DO A FULL SCAN NOT JUST BOOT SECTOR*

- reboot to safemode after that is run and done

then install malwarebytes and do a full scan and it should be taken care of. Also I like to clear the cache before I use malwarebytes full scan and take care of unnecessary startup items as well. PM me if you have any issues


EDIT: to be more technical you could also boot in to the OS using hirens mini XP and delete the .exe of the virus usually in your appdata or programdata folders.

this is risky but the most efficient way is to also redo your MBR depending on what OS you have there are dozens of tools that can do that for you.

Last edited by Supatitanman; 06-06-2012 at 19:41.
   
Reply With Quote
Old
  (#8)
Robox1
Member Guru
 
Videocard: HD6970
Processor: I7 920
Mainboard: Rampage II Gene
Memory: 4GB DDR3 1600
Soundcard:
PSU: HX520
Default 06-07-2012, 12:22 | posts: 52

I managed to boot into Safe Mode with Command Prompt and I started from the command line ComboFix I had moved to c: and I solved the problem .... then I did a scan with malwarebite, Emsisoft malware, superantispyware, antivir (tomorrow and do another session another 3-4 programs) and strangely none of these I found nothing (except a few false positive that I have always been detected and I know for sure it's clean)

But now there's a problem: the screen of your desktop background but has no files and folders (if you go looking in the desktop folder in Windows Explorer the files are present) ..... you know how I can fix?


I also tried:

- Use a rescue of the arrangement of icons with icon restoreer
- Delete iconcache.db
- Replace explorer.exe with a downloaded

but nothing ...: tips on how to solve?
   
Reply With Quote
Old
  (#9)
Phragmeister
Maha Guru
 
Phragmeister's Avatar
 
Videocard: MSI 560-Ti
Processor: i7 920 @ 3.8GHz
Mainboard: Asus P6TD V2
Memory: Corsair Dom 12GB
Soundcard: X-Fi Fatal1ty
PSU: Corsair HX850
Default 06-07-2012, 15:04 | posts: 1,161 | Location: UK

You may have accidentally unchecked this setting -

*On desktop* Right-Click > View > Show Desktop Icons

If it's already checked, uncheck it, then check again.

"Check-ch-check-check-check-ch-check it out. What-wha-what-what-what's it all about ..."
   
Reply With Quote
Old
  (#10)
Pill Monster
Ancient Guru
 
Pill Monster's Avatar
 
Videocard: 7950 Vapor-X 1150/1550
Processor: AMD FX-8320 @4.8
Mainboard: ASUS Sabertooth 990FX R2
Memory: 8GB Kingston HyperX 2400
Soundcard: Audigy 2 Platinum Ex 5.1
PSU: AcBel M8 750
Default 06-09-2012, 06:17 | posts: 20,519 | Location: NZ

Quote:
Originally Posted by Robox1 View Post
I managed to boot into Safe Mode with Command Prompt and I started from the command line ComboFix I had moved to c: and I solved the problem .... then I did a scan with malwarebite, Emsisoft malware, superantispyware, antivir (tomorrow and do another session another 3-4 programs) and strangely none of these I found nothing (except a few false positive that I have always been detected and I know for sure it's clean)

But now there's a problem: the screen of your desktop background but has no files and folders (if you go looking in the desktop folder in Windows Explorer the files are present) ..... you know how I can fix?


I also tried:

- Use a rescue of the arrangement of icons with icon restoreer
- Delete iconcache.db
- Replace explorer.exe with a downloaded

but nothing ...: tips on how to solve?
It's been ages since I used it so I could be wrong. but I think that's a side effect of running Combofix.
Pretty sure it says something about that when the program runs....
   
Reply With Quote
 
Old
  (#11)
jbmcmillan
Maha Guru
 
jbmcmillan's Avatar
 
Videocard: Gigabyte 7870 OC 2 GB
Processor: i5 2500k@4.4 GHZ.
Mainboard: MSI P67A-GD53
Memory: Gskill 2x4GB 1600 DDR3
Soundcard: Onboard realtek
PSU: OCZ 1000 watt Z series
Default 06-09-2012, 15:12 | posts: 822 | Location: Langley,B.C. Canada

This thread describes how to use unhide.exe for a similar problem.
http://www.bleepingcomputer.com/forums/topic404928.html
   
Reply With Quote
Old
  (#12)
soldier1st
Master Guru
 
Videocard: ATI Radeon HD 4250
Processor: AMD Phenom Triple Core
Mainboard: AMD Based
Memory: 4GB DDR3
Soundcard: ATI High Definition
PSU: 500Watt Generic
Default 06-16-2012, 10:07 | posts: 196 | Location: Enterprise NX01

Quote:
Originally Posted by k1net1cs View Post
You forgot Ghostery in that equation.
Ghostery slows down browsing so not usin it for that reason. do not track plus/adblock plus/better privacy/adblock popup addon/element hiding helper is what i would use.
   
Reply With Quote
Old
  (#13)
Mufflore
Ancient Guru
 
Mufflore's Avatar
 
Videocard: KFA2 Anarchy 580@930/4650
Processor: 2500K @ 4.5GHz - blew it!
Mainboard: Gigabyte P67 UD4 B3
Memory: 8G Kngston 2.2GHz CL11 1T
Soundcard: Minimax+ & Dexa Opamps !!
PSU: Corsair Pro AX750
Default 06-16-2012, 22:07 | posts: 9,554 | Location: UK

Strange, Ghostery causes no browsing speed issues here.
CPU use spikes to around 10 to 15% momentarily when loading a webpage.
You may have another issue.
   
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



Powered by vBulletin®
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
vBulletin Skin developed by: vBStyles.com
Copyright (c) 1995-2012, All Rights Reserved. The Guru of 3D, the Hardware Guru, and 3D Guru are trademarks owned by Hilbert Hagedoorn.