• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Computer's ****ed, help!

Status
Not open for further replies.

Mama Smurf

My penis is still intact.
A couple of days ago, my computer stared getting all these Chinese (I think) sites popping up randomly. Soon after, my toolbar has a little message thing pop-up telling me my computer's infected with a virus and it'll now download the latest virus killer. I think fair enough, i have after all just had these sites pop up, I probably have a virus.

It downloads a programme called BraveSentry. Now I don't know what it was which made me suspicious of this, but somehow it didn't seem legit. Lo and behold, I look it up and it's a programme which reports supposed threats which don't actually exist to try and tempt you into buying the full version.

So I look up how to remove it and follow some online instructions (I forget where). It seemed to work, I stopped getting the annoying toolbar message telling me my computer was infected and I couldn't find any BraveSentry stuff anywhere.

Now maybe I did get rid of BraveSentry. When looking up how to remove it one site warned that it was unusual to only download BraveSentry when your PC's attacked. Whether I got rid of it or not, something's making my PC go wrong still.

So I get a crapload of free anti-virus programmes and run them all (in safe mode and normal). AVG (which I had anyway), Spyware Blaster, Ad-Aware, Spybot, cwshredder, Avast...I run them all. They seem to find quite a lot of things, so I heal or quarantine or delete them or whatever.

Didn't help. I'm still getting the Chinese pop ups (though now the sites won't load, I just see it trying to get to some random address and failing. In fact, I can't load anything in IE). My PC's resources are, apparently, always right around the limit as frequently if I open a browser and My Computer and winamp at once, it won't let me open anything else. At first it wouldn't let me do ctrl alt delete, saying the administrator had blocked that, so I looked up a way to fix it and I could do it through the Run... command thing. Now though, when I press ctrl alt delete, nothing happens at all, it doesn't even tell me the admin thing. I try to do the Run... thing again, and when I click on Run... it asks me if I want to create a shortcut for it on the desktop! I can't get to the Control Panel either. A few hours ago I was listening to music on winamp and the PC hasn't been off since, but now it says something like this when I try and play something: Bad DirectSound driver error code 80070057 (which I looked up, and found people asking but very little help). It won't play sound in youtube either, though it doesn't come up with an error code.

Oh yeah, AVG has been popping up frequently telling me I have this trojan here and this virus there. Now I don't know what the hell these things are, it doesn't come up saying "My Computer" and I think "ooh I shouldn't quarantine that", it says things like system32/dilu (that's completely made up from a vague memory, it hasn't done it for a couple of hours), so for all I know there's a virus on my system making AVG think perfectly harmless files are trojans and all this stuff is going wrong because I've been quarantining things I need. Or maybe they are all trojans.

Anyway, finally I gave up and decided I'd just have to reformat my hard drive. Problem is, I didn't install XP on this machine in the first place, my dad did it ages ago. So I don't know where the disk is, and haven't been able to ask him yet. I can't imagine he'd have thrown it away, but I went through all the CDs I could find and it wasn't there...even though I found boot up disks for older versions of windows so I'd have thought they'd be in the same place.

I don't know what to do if he doesn't know where it is. I didn't really want to have to buy another version, so I'm hoping you guys will be able to help me clean my PC without having to reformat. If anyone can give me a step by step guide which tries everything, and if that doesn't work I'll know I'll just have to buy XP again, I'd be grateful.

EDIT: Oh yeah, if you're linking to virus scanners and things, can you make sure they're free? If I can't fix it without paying for some scanner which might not even work, I'll just get XP again instead.
 

Jeffahn

Member
Image7.gif


...
 

livestOne

Member
Reboot in safe mode*

Use system restore


Turn on the computer while holding down F8. From the list pick open in safe mode
 

Mama Smurf

My penis is still intact.
Oh yeah, I tried the system restore, forgot to say. It didn't work. I then read somewhere that you should actually turn off system restore, as some viruses can hide in it somehow. I did that before trying any of the scanning, but I hope I didn't mess anything up by trying to do a system restore.

Thanks for the Kaspersky thing, I'll try it.

It even crossed my mind that the sites telling me how to get rid of BraveSentry might have been fakes too. I mean, if they're willing to go to the trouble of creating a programme to convince you you have viruses all over your system, I doubt a bunch of dummy sites would be beyond them. I mean, they'd know that eventually someone would come up with a way to get rid of it, so why not create sites saying that BraveSentry is indeed a problem, but then give fake a fake way to get rid of it, which just makes you think you have.

I'm probably just paranoid though.
 

rc213

Member
Check what is starting up when your pc boots up. Alot of trojans usually add an entry to that so when you delete infected files a .bat file can allow it to just replicate itself the next time you boot into windows.
 
Mama Smurf said:
Soon after, my toolbar has a little message thing pop-up telling me my computer's infected with a virus and it'll now download the latest virus killer. I think fair enough, i have after all just had these sites pop up, I probably have a virus.
...
 
Mama Smurf said:
It even crossed my mind that the sites telling me how to get rid of BraveSentry might have been fakes too. I mean, if they're willing to go to the trouble of creating a programme to convince you you have viruses all over your system, I doubt a bunch of dummy sites would be beyond them. I mean, they'd know that eventually someone would come up with a way to get rid of it, so why not create sites saying that BraveSentry is indeed a problem, but then give fake a fake way to get rid of it, which just makes you think you have.
Mama Smurf said:
Oh yeah, AVG has been popping up frequently telling me I have this trojan here and this virus there. Now I don't know what the hell these things are, it doesn't come up saying "My Computer" and I think "ooh I shouldn't quarantine that", it says things like system32/dilu (that's completely made up from a vague memory, it hasn't done it for a couple of hours), so for all I know there's a virus on my system making AVG think perfectly harmless files are trojans and all this stuff is going wrong because I've been quarantining things I need. Or maybe they are all trojans.
Were you using a Dreamcast to browse the Internet until last week?
 

Mama Smurf

My penis is still intact.
I don't understand the question, that's what BraveSentry does.

As for the toolbar thing, it wasn't like an internet pop up, it was like the little message that pops up telling you there's a new Windows update to download. Exactly like it. And it's not like I agreed to download something, it just did it and 5 minutes later I'd looked up BraveSentry to check it out.

Thanks for the help though. And by help, I mean being an ass.
 

SRG01

Member
Free anti-virus programs are very bad at quarantine and detection/removal of viruses. Moreover, I don't think many of them implement boot-order schemes.

Go download NOD32 and install it (not in safe mode, it messes it up). It should have a 30 day trial with it. That should get any on-load viruses since NOD32 has priority when it loads.

PS. You're being hit by multiple vectors. :(

edit: NOD32 also has the advantage of being able to run on low system resources and good virus heuristics.
 
It is odd that the system is still acting up considering that you seemed to run a good many programs that I trust.

And, of course, at least one you shouldn't have. Looking to a rogue pop-up for help is a bit like me dressing up like a security guard, jumping out from behind your bed, and shouting "Dood! They are steel ur sh*T! Let my freinz in so we cn help u!"

Spybot and AVG are the two I use. Are you updating these programs before you use them? Do you have a firewall outside of XP's own? Are you making sure that you are doing full scans? Is there another storage medium attached to your PC?
 

Mama Smurf

My penis is still intact.
I don't think I've explained the BraveSentry thing very well. The "pop up" was one of those little pale yellow bubbles that comes up from your toolbar when there are new updates to things. And I never chose to download it, it just told me it was doing and when I looked at my desktop there was a BraveSentry icon.

At most I'd have right clicked on it to make it go away quicker.

I'm going to try all the things you guys have suggested, but I'm losing hope. Shame my brother isn't around, he was always the computer guy.
 
Mama Smurf said:
that's what BraveSentry does.
...
Mama Smurf said:
I don't think I've explained the BraveSentry thing very well. The "pop up" was one of those little pale yellow bubbles that comes up from your toolbar when there are new updates to things.
Do you trust everything that looks real to you?

A simple google search on "bravesentry" is nothing but hits on how to remove it from your computer because it's a virus.
 

rc213

Member
Mama Smurf said:
I don't think I've explained the BraveSentry thing very well. The "pop up" was one of those little pale yellow bubbles that comes up from your toolbar when there are new updates to things. And I never chose to download it, it just told me it was doing and when I looked at my desktop there was a BraveSentry icon.

At most I'd have right clicked on it to make it go away quicker.

I'm going to try all the things you guys have suggested, but I'm losing hope. Shame my brother isn't around, he was always the computer guy.


Don't worry yourself too much about how it got on your pc. I've seen these things first hand and they quite tricky to detect when your not being careful. Start with Hijack This and post the log to their forums for better help analyzing your results.
 

Mama Smurf

My penis is still intact.
Liu Kang Baking A Pie said:
...
Do you trust everything that looks real to you?

A simple google search on "bravesentry" is nothing but hits on how to remove it from your computer because it's a virus.

How many times do I have to say this. I didn't choose to download it. It just said it was downloading (and it didn;'t say it was downloading bravesentry, just the latest anti-virus update) and there it was on my desktop. Nor did I open it, I looked up bravesentry (with a simple google search) when I saw it.

Thanks for the help guys, if I never return it's because the virus has continued its relentless attack, taken over my house and the doors no longer open.
 
Status
Not open for further replies.
Top Bottom