VERY Weird virus..need help

Anti-Virus Discuss, VERY Weird virus..need help at Tech Zone forum; It was a file from a warez site but I scanned it with my bitdefender and jotti website both gave ...


Go Back   Gamerz Needs - For All Your Gaming Needs! > Technology Zone > Tech Zone > Anti-Virus
Forgot Password? | Sign Up!

Notices

Advertisement
   

Reply
 
Bookmark this Thread Tools Display Modes
  #1  
Old 08-13-2008, 06:42 AM
Stained's Avatar
Violet Hole
 
Last Online: 11-28-2008 02:23 PM
Join Date: Jun 2007
Location: EU
Posts: 302
Thanks: 116
Thanked 81 Times in 64 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 5
Stained is on a distinguished road
Points: 4,186.54
Bank: 7,827.58
Total Points: 12,014.12
Send a message via MSN to Stained
VERY Weird virus..need help

It was a file from a warez site but I scanned it with my bitdefender and jotti website both gave no virus reports.

so I opened the installer and It edited my registry with something called klass.exe

now in my system32 folder there are 2 files

1 is a text file which says something like thank u 4 downloading and the other is a hidden log file called log which records everything I type and do (keylogger)

I am now also experiencing disconnection problems (very frequent) and its getting annoying

I have tried: cleaning registry, deleting those files with a shredder, compacting registry, regedit and look for "klass.exe" and delete manually, running a full antivirus scan, NOTHING worked,

everytime I boot the pc those 2 files keep reappearing and that txt file opens 2-3 times as I boot my pc and my explorer.exe process wont appear so I have to create it everytime

I wanted to do a system restore but it gives me an access denied error when its about to restore my pc.

I don't know what to do, I also googled it and found nothing (in english at least)

I cant get rid of this ****

I really need help I've tried EVERYTHING I just don't know how to get rid of it
it looks like it infected a dll inside a dll in my system32 folder and somehow my antivirus cant remove it (Bitdefender 2008 total security fully updated)
  #2  
Old 08-13-2008, 07:57 AM
Registered Users +
 
Last Online: 10-15-2008 05:11 PM
Join Date: Jul 2007
Location: New York
Age: 20
Posts: 1,070
Thanks: 84
Thanked 145 Times in 78 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 6
Polychrome is on a distinguished road
Points: 797.30
Bank: 9,410.88
Total Points: 10,208.18
Black - Polychrome Black - Polychrome Black - Polychrome Black - Polychrome Black - Polychrome 
Black - Polychrome Gold - Polychrome Gold - Polychrome Gold - Polychrome Black - Polychrome 
Black - Polychrome Black - Polychrome Black - Polychrome Black - Polychrome Black - Polychrome 
Black - Polychrome 
Send a message via MSN to Polychrome Send a message via Yahoo to Polychrome
Well you're fucked.. if there are only two files in your system32, that means your computer won't function properly. Try backing up your files and formatting your computer.


Off Topic: zZzzZzz x_x your sigs are good but the text needs work.
__________________
I love GzN
  #3  
Old 08-13-2008, 08:26 AM
Beast's Avatar
I love GzN!
 
Last Online: 09-09-2008 03:57 PM
Join Date: Jul 2007
Posts: 1,672
Blog Entries: 1
Thanks: 87
Thanked 119 Times in 84 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: Oh
Rep Power: 8
Beast is on a distinguished road
Points: 1,872.90
Bank: 135.15
Total Points: 2,008.05
Black - armoballer Dark Blue - hotboy 
Only 2 files, lmao reminds me of something .. *nolan* haha,
well wait do you have restore cds.
__________________
I Love Gzn. www.iGzN.com
  #4  
Old 08-13-2008, 11:26 AM
1k Points Wasted
 
Last Online: 12-03-2008 02:08 PM
Join Date: Aug 2006
Location: over there
Posts: 2,219
Blog Entries: 6
Thanks: 48
Thanked 172 Times in 134 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: Very random blog entries (based on time)
Rep Power: 13
cosmeo3000 will become famous soon enoughcosmeo3000 will become famous soon enough
Points: 6,006.76
Bank: 89,660.72
Total Points: 95,667.48
Black - cosmeo3000 
Send a message via MSN to cosmeo3000
2 Files in system32 wouldn't be well... it'd stop everything from working. Btw, disconnect your internet first, that's the first thing you should do to stop that keylogger. Then try doing a system restore, etc. in safe mode. If it doesn't work there, then you're screwed.
__________________

Dam my other one won't animate for some reason o_O
  #5  
Old 08-13-2008, 03:29 PM
kaswar's Avatar
Registered Users +
 
Last Online: Yesterday 07:14 PM
Join Date: Nov 2006
Location: Location:
Posts: 2,066
Thanks: 230
Thanked 222 Times in 146 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 11
kaswar will become famous soon enough
Points: 1,103.40
Bank: 110,398.61
Total Points: 111,502.01
Here ya go. Don't get drunk! O.O - joriannn Marked as kashin's property. (One of the four Mighty Titans led by sir SpaceCake) - kashin Merry christmas and seriously i couldnt find any other gift - ItsmYarD Merry Christmas N Happy New Years!!! - BiGbAnG to karwas. Bang - stormer320 
gotcha RPKMHFTAGUITALABPC - ROVE ure not drunk enough yet - swordmas754 
Gold - Wizxon Green - swordmas754 Green - swordmas754 
Send a message via MSN to kaswar
reinstall XP, like thats not hard...
__________________
Ha I'm back whatever
  #6  
Old 08-13-2008, 03:34 PM
gohan2005777's Avatar
Double Stone Axe
 
Last Online: 12-03-2008 07:21 PM
Join Date: Jun 2007
Location: Pharr, TX
Age: 15
Posts: 48
Blog Entries: 5
Thanks: 5
Thanked 20 Times in 7 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog: From 9-28-07
Rep Power: 0
gohan2005777 is on a distinguished road
Points: 2,025.00
Bank: 0.00
Total Points: 2,025.00
I had a virus similar to that. Except it would always shut down everytime I logged on. Like on XP, you have user accounts, right? Well everytime I logged into mine, or anyone else's, I would try to run a virus scan but my computer would automatically give an error say, "Windows can't run this application because it is shutting down." or something like that. I ran it in Safe Mode and tried to run a full virus scan. I would take longer than usual. When I found the virus and deleted it, I would start my computer up normally. It was still there. I tried a System Restore, but it would say "Cannot Restore to that date" and I tried every day possible. Well my dad had to BUY Windows XP Pro to restore the computer because we lost our restore disk. After we reformatted, I tried to get on the Internet but I have DSL and we needed to install a driver to get the Internet to work. That was in the morning. I had no idea how to fix it but luckily I remembered my PSP and I downloaded the drivers and I installed them after I found the wire to connect my PSP. I got my computer back.

OT: I had a dream last night that my computer got hacked and that someone else could control what went on on the screen. Sort of like TeamViewer, but atleast there you can control the mouse. In my dream, you couldn't. I would start up my computer and this wierd but awesome looking game would always pop out. It was a First Person Shooter. If you guys have ever played Soldier Front, then you might know what tapping is. If you don't, it is where you pull the ethernet cord then move somewhere and plug it back. Well I was doing that with my power cord and I would temporarily have access to my computer then like it should, turn off. in the end, I ended up shooting my computer with an M16. I don't know where it came from but yeah. Hasta la bye bye, you fucked up computer .
  #7  
Old 08-13-2008, 05:57 PM
SacredBlack's Avatar
Silver Double Sided Axe+
 
Last Online: 11-23-2008 10:42 AM
Join Date: Jul 2007
Location: Behind you when you get owned ╟↨♂¢╘♫
Posts: 205
Thanks: 64
Thanked 21 Times in 17 Posts
Nominated 0 Times in 0 Posts
TOTW/F/M Award(s): 0
Latest Blog:
Rep Power: 3
SacredBlack is on a distinguished road
Points: 2,859.33
Bank: 0.00
Total Points: 2,859.33
For me :P - SacredBlack hehe^^ - SacredBlack hehe^^ - SacredBlack e - SacredBlack c - SacredBlack 
No Message - dbballfreak 
Lavender - SacredBlack Green - SacredBlack Gold - SacredBlack 
Send a message via ICQ to SacredBlack Send a message via MSN to SacredBlack
the newest norton antivirus can restore your windows xp... but only if you got the original version from windows... that delete the virus and restore the files what it deleted^^
i bought it for 50 euro :P
__________________
4
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Advertisement
   


Main Navigation
Home
GzN Forums
GzN Games
GzN News
Top Games
GzN Cheats
GzN Articles
GzN Reviews
GzN Downloads
User Control Panel
Advertising
RSS Feed
2Moons
Adventure Quest
AirRivals
America's Army
Anarchy Online
Archlord
Audition
Battlefield Series
Cabal Online
Call Of Duty Series
Combat Arms
Conquer Online
Counter Strike
Day of Defeat
Deicide Online
Diablo Series
Doom Series
Drift City
Enemy Territory
Eudemons Online
Final Fantasy
Flyff (Fly For Fun)
General Game Discussion
Ghost Online
Granado Espada
Grand Theft Auto Series
Guild Wars
Gunbound
Gunz Online
Habbo Hotel
Half-Life 2
Hero Online
KartRider
Knights Online
Maple Story
Medal of Honor
MU Online
Neopets
Pangya
Quake Series
Ragnarok Online
Rappelz
Rakion
Red Orchestra
Rose Online
Runescape
Scions of Fate
Silkroad Online
Sims Series
Soldier Front
Starcraft
Tales of Pirates
Tibia
The Ship
Trickster Online
TS Online
Unreal Tournament
War Rock
WolfTeam
World of Warcraft & Series
Affiliates
COD4 Hacks
BF2 Hacks


All times are GMT -8. The time now is 02:18 AM.