View previous topic :: View next topic |
Author |
Message |
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 7:25 am Post subject: VIRUS HELP!! |
|
|
Ok, I tried downloading the Guitar Hero PC Clone (found here). I got the program, but I also got a nasty little surprise with it. Mr. JeefoGUI, which just so happens to be a virus.
(Yes, I am aware that the site warned about it. However, the site also used the warning in a past tense, meaning that common sense would show that the threat was over.)
I tried running the Resolve program that the site suggested, but it's not picking it up. I know exactly where the virus is at (on my Desktop) but I can't seem to delete it, since it's write-protected. I haven't opened it up obviously, but I'm afraid that since this is a very public computer in my house that it'll be accidentally opened eventually.
Any help as to fixing this would be GREATLY appreciated. _________________
|
|
Back to top |
|
|
joker
Joined: 13 Jul 2006 Posts: 199 Location: Beneath the tree of heaven
|
Posted: Sun Jul 30, 2006 7:29 am Post subject: |
|
|
if you're feelin risky, you could go into regedit and remove it
if you're not familiar with regedit, i wouldn't suggest it
do you have ANY virus software on your pc? _________________
|
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 7:32 am Post subject: |
|
|
Agh...no.
We had a ton of virus software, but it was mostly free trials that expired a really long time ago and deleted shortly after.
Just out of curiousity, what would I have to do in regedit to get rid of it? _________________
|
|
Back to top |
|
|
discgolferpro
Joined: 05 Feb 2006 Posts: 861 Location: Kansas City, Mo
|
Posted: Sun Jul 30, 2006 7:35 am Post subject: |
|
|
HylianHero wrote: | Agh...no.
We had a ton of virus software, but it was mostly free trials that expired a really long time ago and deleted shortly after.
Just out of curiousity, what would I have to do in regedit to get rid of it? |
Install this first... http://free.grisoft.com/doc/2/lng/us/tpl/v5
1. Let AVG scan all your drives.
2. Don't muck around the registry until then. Post here if AVG gets rid of it.
3. If it doesn't find it, single-click the file to rename it to <original_name>.txt so that it is inoffensive. Attach the infected file to an email (but don't open it... d'uh) and send it to me and tell me what the original extension was (discgolferpro@yahoo.com). _________________
Last edited by discgolferpro on Sun Jul 30, 2006 7:47 am; edited 1 time in total |
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 7:38 am Post subject: |
|
|
I didn't really plan on doing anything related to the registry at all, since I'm not terribly good with computers. However, if worst comes to worst, I think I may be able to do it.
I'm downloading AVG right now and will post the results when it installs and does its scan. _________________
|
|
Back to top |
|
|
joker
Joined: 13 Jul 2006 Posts: 199 Location: Beneath the tree of heaven
|
Posted: Sun Jul 30, 2006 7:44 am Post subject: |
|
|
heh heh heh
if you have to ask, you might not want to know
if you use the "Run" function from your start menu
(you're using a Windows OS right??? please, God, tell me its not a Mac!)
type regedit in the prompt. once you get it open, find the file under HKEY_CLASSES_ROOT, and delete it. if it isn't gone from your desktop, try and manually delete it.
BE EXTREMELY CAREFUL NOT TO FUCK WITH ANYTHING ELSE BECAUSE THE HKEY_LOCAL_MACHINE IS A SINGLE POINT OF FAILURE AND ANY ALTERATION COULD CAUSE YOUR PC TO BECOME "WINDOWS UNBOOTABLE" AND YOU'LL HAVE TO COMPLETELY REINSTALL WINDOWS AND ALL COMPONENT SOFTWARE!!!! _________________
|
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 7:50 am Post subject: |
|
|
discgolferpro wrote: | HylianHero wrote: | Agh...no.
We had a ton of virus software, but it was mostly free trials that expired a really long time ago and deleted shortly after.
Just out of curiousity, what would I have to do in regedit to get rid of it? |
Install this first... http://free.grisoft.com/doc/2/lng/us/tpl/v5
1. Let AVG scan all your drives.
2. Don't muck around the registry until then. Post here if AVG gets rid of it.
3. If it doesn't find it, single-click the file to rename it to <original_name>.txt so that it is inoffensive. Attach the infected file to an email (but don't open it... d'uh) and send it to me and tell me what the original extension was (discgolferpro@yahoo.com). |
All right, it doesn't look like it picked it up on its first sweep, so I'm gonna e-mail it to you. Quick n00b question: What exactly is the original extension? _________________
|
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 7:52 am Post subject: |
|
|
All right, and because of Matt I can't edit my post in this forum.
The virus isn't a .txt file like you had it in the instructions. It's a MS-DOS application. _________________
|
|
Back to top |
|
|
dspoonrt
Joined: 20 Feb 2006 Posts: 2449 Location: Columbus, OH
|
Posted: Sun Jul 30, 2006 7:54 am Post subject: |
|
|
It's probably an .exe. That's what he wanted to know. He just wanted you to rename it as a text file so it could get through by email. _________________
Check out my songs on GHTunes for GH:WT (Xbox 360):
"Power Surge," "Funk You," "Grindsaw Groove," and "DisorderlyConduct"
- all charted by dspoonrt
|
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 7:55 am Post subject: |
|
|
Ah, I see. That makes a little bit more sense.
All right, I'm e-mailing it to you now. _________________
|
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 7:57 am Post subject: |
|
|
Man, I don't like not being able to edit.
Ok, everything seems to be good to go now. I left AVG running in the background and 20 minutes into the hunt it picked it up. I'll let it grab everything and delete it.
Thanks for the help everybody. _________________
|
|
Back to top |
|
|
dspoonrt
Joined: 20 Feb 2006 Posts: 2449 Location: Columbus, OH
|
Posted: Sun Jul 30, 2006 7:58 am Post subject: |
|
|
Hope it's all worked out. Viruses suck. _________________
Check out my songs on GHTunes for GH:WT (Xbox 360):
"Power Surge," "Funk You," "Grindsaw Groove," and "DisorderlyConduct"
- all charted by dspoonrt
|
|
Back to top |
|
|
joker
Joined: 13 Jul 2006 Posts: 199 Location: Beneath the tree of heaven
|
Posted: Sun Jul 30, 2006 8:00 am Post subject: |
|
|
sorry i wasn't any more help than i was. i'm old school...
...like apple IIe old school _________________
|
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 8:00 am Post subject: |
|
|
Yeah, it looks like it picked it all up.
I guess it was just a small one though. It seemed to be geared more towards pop-ups than actually destroying anything, judging off of all the .zip files AVG picked up that have movie title names, so it wouldn't have been too bad. _________________
|
|
Back to top |
|
|
HylianHero
Joined: 22 Feb 2006 Posts: 4673 Location: Santa Cruz, CA
|
Posted: Sun Jul 30, 2006 8:01 am Post subject: |
|
|
joker wrote: | sorry i wasn't any more help than i was. i'm old school...
...like apple IIe old school |
Hey, it's cool. If I would've had to go into the regedit I would've followed your instructions anyways.
Lucky for me I didn't have to do that, since I was about 99% sure I was gonna screw somethin up. _________________
|
|
Back to top |
|
|
|